Skip to main content
AfterDuty

Lead Cyber Security Analyst - Identity and Access Management

Social Security Scotland · Glasgow, Scotland

Salary
£49,401 – £59,152Estimated
Type
Full-time
Posted
Yesterday

Overview

Your policing background equips you with strong incident management, risk assessment, and protective security instincts, which map to the incident response and security risk duties in the job description. However, the role is a senior technical IAM lead requiring specialist knowledge of identity governance, privileged access, and cloud authentication platforms that are not part of mainstream policing experience. Without significant formal retraining in identity technologies and security architecture, this is a poor direct fit despite the cyber security category.

About this role

Details

GBP

Job grade

Senior Executive Officer

B3

Business area

SSS - Chief Digital Office

Type of role

Other

Working pattern

Full-time

Number of jobs available

1

Contents

  • Location
  • About the job
  • Benefits
  • Things you need to know
  • Apply and further information

About the job

Job summary

We are seeking an experienced and motivated Lead Cyber Security Analyst specialising in Identity and Access Management (IAM) to join the Digital Risk & Security branch within Digital Delivery & Change. This role is responsible for leading the delivery and continuous improvement of IAM services that protect Social Security Scotland’s digital services, systems, and sensitive information.

As a technical lead within the Security Operations function, you will provide leadership and expertise across the organisation’s IAM capabilities, ensuring that access to systems, applications, and data is managed securely, appropriately, and in line with business and regulatory requirements. You will work closely with technical teams, service owners, and stakeholders to strengthen security controls, reduce risk, and support the adoption of modern identity security practices across a cloud-first environment.

You will lead the operational delivery and development of key IAM services, including:

  • Identity and Access Management (IAM)
  • Privileged Access Management (PAM)
  • Identity Governance and Administration (IGA)
  • Joiners, Movers and Leavers processes
  • Role-Based Access Controls (RBAC)
  • Authentication and Authorisation Services
  • Multi-Factor Authentication (MFA)
  • Access Reviews and Certification
  • Privileged Account Monitoring and Control

The role requires strong technical knowledge of identity technologies, access governance, and security best practices, alongside the ability to translate business requirements into effective security solutions. You will provide technical leadership, support the development of team capability, and drive continuous improvement to ensure IAM services remain effective, resilient, and aligned to organisational needs.

If you are passionate about identity security and want to play a key role in protecting critical public services and citizen data, we would welcome your application.

GDD Pay Supplement

This post is part of the Government Digital and Data (GDD) profession and currently attracts a £4,000 annual GDD pay supplement, which is paid monthly. Pay supplements are reviewed regularly.

Job description

Responsibilities

  • Leads the technical design and implementation of Identity and Access Management (IAM) strategy across the agency, including access governance, privileged access management, authentication, and user lifecycle processes.
  • Has oversight of security administration processes and checks that all requests for support are dealt with according to agreed procedures
  • Provides guidance in defining access rights and privileges across different applications and services across the Agency.
  • Contributes to the development of cyber security IAM policy, standards and guidelines appropriate to business, technology and legal requirements and in accordance with best professional and industry practice
  • Deliver specific pieces of work resulting from the Cyber Security Strategy, related to cyber business risk and information control/protection requirements
  • Champion incident management, incident investigation and response policy and/or incident management and investigation processes, procedures and systems
  • Performs security risk, vulnerability assessments, and business impact analysis for complex information systems or risk-based projects
  • Specifies requirements for environment, data, resources and tools. Interprets, executes and documents complex test scripts using agreed methods and standards
  • Maintains current knowledge of malware attacks, and other cyber security threats
  • Maintains knowledge of specific specialisms, provides detailed advice regarding their application and executes specialised tasks

Person specification

Success Profiles

We use an assessment framework called ‘Success Profiles’ which lists the elements we test and provides detailed descriptions of each. Find out more about the framework here.

For this post, the following Success Profile elements will be assessed:

Experience

  • Subject matter expertise in developing and operationalising cyber security capabilities, including the design and implementation of Identity and Access Management (IAM) controls, automation of identity lifecycle processes, integration of enterprise applications with identity platforms, enhancement of Privileged Access Management (PAM), and implementation of new IAM controls and processes to meet evolving security, compliance and business requirements.
  • Proven experience in incident management and investigation, including reporting, root cause analysis, and resolution, with the capability to provide informed guidance on incident response methodologies and best practice.

Behaviours:*

  • Changing and Improving (Level 4)
  • Leadership (Level 4)

You can find out more about Success Profiles Behaviours here:

Technical / Professional Skills

This role is aligned to Lead Cyber Security Analyst within the Government Digital and Data Profession.

These skills will be tested during the Technical Assessment if you are successful at sift stage. They will not be not be assessed at application stage. Please review the following to understand the skill expectations:

Benefits

Annual Leave - You will receive 25 days annual leave on joining us. This will increase to 30 days after four full years of service. You will also have 11.5 public and privilege days of leave every year. We also offer Flexi-time. Any extra hours you've worked can be taken as leave when suitable.

A Civil Service Pension - This job comes with a Civil Service pension. New joiners to the Civil Service will join a career average pension scheme as standard. Read more here - www.civilservicepensionscheme.org.uk.

Healthy work life balance - We can offer the possibility of full-time, part-time, term-time, and job shares. We also encourage flexible working.

Discounts - You can enjoy a vast range of retail, travel and lifestyle discounts through our benefit scheme.

Personal support for you - Our Employee Assistance Programme gives you confidential, independent information and guidance 24/7.

Volunteering special leave - Up to six days paid special leave a year for volunteering. We support our staff to help causes important to them.

Great locations - Our bright and modern offices in the heart of Dundee and Glasgow have been designed with staff in mind. Both locations are ideal for public transport.

Things you need to know

Artificial intelligence

Artificial intelligence can be a useful tool to support your application, however, all examples and statements provided must be truthful, factually accurate and taken directly from your own experience. Where plagiarism has been identified (presenting the ideas and experiences of others, or generated by artificial intelligence, as your own) applications may be withdrawn and internal candidates may be subject to disciplinary action. Please see our candidate guidance for more information on appropriate and inappropriate use.

Selection process details

Expected Timeline**(subject to change)

Sift - week commencing 17th August 2026

Interview – week commencing 7th September 2026

Feedback will only be provided if you attend an interview or assessment.

Security

Successful candidates must undergo a criminal record check.

People working with government assets must complete baseline personnel security standard (opens in new window) checks.

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in Glasgow

Why this fits a police background

  • Incident command & response
  • Investigative casework
  • Working to legislation & regulation
  • Security operations

What cyber security & digital forensics roles pay ex-police

Advertised UK ranges, editorial estimates reviewed July 2026

Digital forensics analyst£32,000–£45,000
DFIR consultant£45,000–£65,000
Senior forensics / IR specialist£60,000–£80,000
Threat-intelligence specialist£55,000–£80,000
Full cyber security & digital forensics salary guide →

More cyber security & digital forensics jobs for ex-police

  • Threat Analyst

    SCC · Birmingham

    Full-time

    Your background in intelligence analysis and threat assessment from policing maps directly to producing structured threat intelligence deliverables. You are used to researching hostile actors, evaluating sources, and writing concise briefings for different audiences, which is exactly what this role demands. Your incident response experience and disciplined approach to evidence and reporting would let you contribute from day one, while any gaps in specific tooling can be trained.

    Posted Today

  • Cyber Incident Responder

    CYFOR · Manchester

    Full-time

    £40,000 – £50,000Estimated

    Your experience investigating digital evidence and managing incidents in policing gives you a strong foundation for this role, particularly in forensic acquisition, log analysis, and producing evidential reports. The requirement for clear client communication and structured investigation aligns with your interview and case-file skills, though you would need to build specific technical knowledge of cloud environments and EDR tools.

    Posted Yesterday

  • Full-time

    This role focuses on information security management, risk assessment, and incident response — areas where your experience in operational policing, threat assessment, and managing critical incidents translates directly. Your background in following strict procedures, handling sensitive information, and coordinating multi-agency responses aligns well with the security governance and compliance aspects of the job. While the role requires specific technical cyber security knowledge, your investigative mindset and ability to work under pressure are strong foundations that employers in this sector

    Posted Yesterday

  • Full-time

    Your experience in policing has given you a strong foundation in risk assessment, threat identification, and incident management, which are directly applicable to IT risk management. You are used to working under pressure, making decisions based on incomplete information, and communicating complex risks to senior stakeholders. While you may need to develop specific technical knowledge of IT frameworks like ISO 31000 or NIST, your core skills in evaluating threats, implementing controls, and ensuring compliance are highly transferable to this role.

    Posted Yesterday