Skip to main content
AfterDuty

Incident Response Analyst

HM Revenue & Customs · Bristol, South West England

Type
Contract
Posted
21 days ago

Overview

Your fraud investigation and evidence-handling skills from policing transfer directly to triaging identity-led fraud incidents.

About this role

Bristol Regional Centre - 3 Glass Wharf

Cardiff Regional Centre - Ty William Morgan

Edinburgh Regional Centre - Queen Elizabeth House

Leeds Regional Centre - Wellington Place

Salford - Trinity Bridge House

Telford - Plaza 1 and 2

Stratford Regional Centre - Westfield Avenue

Please note that due to workforce controls, Stratford is only available to existing HMRC staff in this location. HMRC staff based in Reading can also apply to move to Stratford in line with Migration path. HMRC staff based in 100PS can also apply to move to Stratford.

Job Summary

Discover a career in your hands at HMRC. Whether you're seeking purpose, growth, or a workplace that gives you a true sense of belonging, hear from some of our employees as they share their story about what it’s really like to work at HMRC.

Visit our YouTube channel to watch the full series and come and discover your potential.

Our team is rapidly growing as we invest in new technologies and capabilities, and we are in search of enthusiastic individuals who can help us in achieving our mission. We are continually improving the service we give to our customers and, in line with this, we are creating a new response and management team within the HMRC Fraud Prevention Centre.

The Fraud Prevention Centre (FPC) is a strategic capability within HMRC Security, designed to safeguard customers and the organisation against identity-related fraud and emerging threats. Its mission is built on three interconnected pillars: Protection, Detection, and Response, all underpinned by advanced threat intelligence and customer support. The Centre operates across multiple functional areas, including Proactive Protection, Customer Support & Response, and Strategy & Advisory, to deliver a holistic approach to fraud prevention.

Job Description

As an Incident Response Analyst, you will act as a key point of contact within the FPC Incident Response Team. You will assess, triage and analyse identity led fraud incidents, supporting effective response activities and helping to minimise the impact on business operations. Working collaboratively with colleagues and stakeholders, you will review existing weak processes, identify opportunities for improvement, and contribute to the development of effective incident response procedures and mitigations. Your work will support the timely restoration of services and the continuous improvement of fraud incident management across the FPC.

As an Incident Response Analyst, you will act as a key point of contact within the FPC Incident Response Team. You will assess, triage and analyse identity led fraud incidents, supporting effective response activities and helping to minimise the impact on business operations. Working collaboratively with colleagues and stakeholders, you will review existing weak processes, identify opportunities for improvement, and contribute to the development of effective incident response procedures and mitigations. Your work will support the timely restoration of services and the continuous improvement of fraud incident management across the FPC.

Person specification

  • Act as an FPC subject matter contributor for fraud incident management, working with colleagues and stakeholders to ensure effective incident response arrangements are in place and standards are adhered to.
  • Analyse and resolve detected fraud incidents, contributing to lessons learned activities and identifying opportunities for continuous improvement.
  • Support the day-to-day activities of the incident response team, reviewing incidents and contributing to response efforts, helping to prioritise and coordinate activities across the end-to-end fraud incident response cycle.
  • Contribute to the development of incident management capability across the FPC, working with SO Incident Response Analysts to promote best practice and consistent application of standards.
  • Support FPC SOs and G7s in producing reports and presentations for a variety of stakeholders, communicating technical information in an accessible and meaningful way.
  • Experience in developing, delivering and improving IT operations within a complex environment, particularly in incident management.
  • Support the capture, dissemination and maintenance of incident information within the incident register, ensuring records, processes and documentation remain accurate and up to date.
  • Provide regular updates on incidents and response activities to the G7 Incident Response Lead.
  • Contribute to the development and improvement of incident response plans, processes and capabilities, supporting effective information sharing across teams.
  • Work collaboratively with HMRC stakeholders, including incident response teams, to escalate findings and support the mitigation of fraud risks.
  • Review incidents, provide guidance to colleagues where appropriate, and support the development of FPC processes, standards and templates.
  • Maintain awareness of the current threat landscape, emerging fraud risks and developing industry practices.
  • Knowledge of fraud detection techniques, including behavioural analysis and anomaly detection and investigation and OSINT (Open Source Intelligence) methods.
  • Support the effectiveness and efficiency of FPC Incident Response Services through the identification of opportunities to improve processes, controls and ways of working.
  • Share knowledge and experience with colleagues across the FPC, helping to build confidence, capability and understanding of fraud incident management.

Essential Criteria

  • To have, or be willing to achieve CISMP
  • Knowledge of fraud detection techniques, including behavioural analysis and anomaly detection and investigation and OSINT (Open Source Intelligence) methods.
  • Data analysis skills and experience with large data sets, with proficiency scripting complex queries in analysis environments.
  • Solid technical understanding of web and API services (e.g. cookies, IP addresses, authentication processes) and threats to those services from cybercrime actors and tools.
  • Experience using Security Information and Event Management (SIEM) platforms, preferably in a security operations setting.
  • A sound understanding of Identity, Verification and Authentication principles

Desirable Criteria

  • A degree in Data Analysis, Data Science, Information Security, Cyber Security, or other Cyber qualifications eg SANS, or at least previous experience in a relevant cyber role.
  • Active use of at least one of the following: Python, SQL, KQL, SPL

The successful candidate may be required to apply for Developed Vetting (DV) clearance level once in post but must already hold or be willing to obtain Security Check (SC) clearance level before starting the role

Further Location Information

Please ensure that you only apply for a location that you are willing and able to work from, as we will only make one offer of employment. Any additional notes included in a ‘Further Location Preferences (optional)’ field within the application form, will not be considered. Please be aware that you cannot change your location preference after submitting your application.

Office closures

For more information on where you might be working, review this information on our locations.

If your location preference is for one of the following sites, it’s important to note that these are not long-term sites for HMRC and we will require you to move to a new building in the future, subject to our location strategy and the applicable employee policies at that time.

These Sites Are

  • Telford Plaza, Telford - moving to Parkside Court, Telford
  • Trinity Bridge House, Salford - moving to an alternative office in Manchester/ Salford

You will be given more information about what this means at the job offer stage.

Leeds Locations

Moves Adjustment Payment will be available for this role, provided the successful applicant is a current HMRC colleague in Bradford and meets the eligibility requirements outlined in the HMRC’s Moves Adjustment Payment guidance.

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in Bristol

Why this fits a police background — match score 75/100

  • Financial crime & fraud
  • Intelligence & OSINT
  • Incident command & response
  • Investigative casework
  • Digital forensics & cybercrime

What cyber security & digital forensics roles pay ex-police

Advertised UK ranges, editorial estimates reviewed July 2026

Digital forensics analyst£32,000–£45,000
DFIR consultant£45,000–£65,000
Senior forensics / IR specialist£60,000–£80,000
Threat-intelligence specialist£55,000–£80,000
Full cyber security & digital forensics salary guide →

More cyber security & digital forensics jobs for ex-police

  • Your incident command and calm analytical approach under pressure directly translate to leading cyber incident response.

    Posted 3 days ago

  • Full-time

    Your incident command and multi-agency coordination experience directly applies to managing cyber incident response and preparedness.

    Posted 6 days ago

  • Information Security Analyst

    REX Cyber Security · Bristol

    Full-time

    Information Security Analyst 📍 Bristol | Hybrid Working | £45,000 - £55,000 We’re working with a leading professional services company in Bristol that is looking to appoint an Information Security Analyst to join its established security function.

    Posted 8 days ago

  • Junior Cyber Security Analyst

    Executive Jet Support Ltd · Bristol

    Full-time

    Your incident response and investigative discipline transfer directly to triaging and escalating security threats.

    Posted 12 days ago