Skip to main content
AfterDuty

Principal Cyber Security Analyst

The Scottish Government · Glasgow, Scotland

Type
Full-time
Posted
2 days ago

Overview

Your investigative background gives you a firm grip on incident response and threat management, and you understand the evidential standards needed for secure digital services. Leading security operations and incident investigations aligns with your experience commanding operations and managing risk under pressure. However, the deep technical expectations around system architecture and automation mean significant upskilling would be required.

About this role

Lead the cyber security agenda for a critical public service, protecting sensitive information while enabling digital transformation across Disclosure Scotland.

Disclosure Scotland is an executive agency of the Scottish Government, supporting safer recruitment and helping to protect vulnerable groups through trusted disclosure services. As Cyber Security Manager, you will join our Digital team at a pivotal point in our transformation journey, leading a specialist team whose mission is to enable secure, resilient, and accessible digital services that meet the needs of citizens, organisations, and government.

In this role, you will provide strategic leadership for cyber security across the organisation, working collaboratively with senior leaders, delivery teams, and external partners to embed security into our services, systems, and decision-making processes. Your primary objective will be to ensure that cyber security supports and enables organisational goals, protecting critical services and information while helping Disclosure Scotland deliver its vision for modern, innovative, and trusted public services.

Success profile

Success profiles are specific to each job and they include the mix of behaviours, experience and technical criteria (if applicable) that candidates will be assessed on.

Experience

  • *Lead criteria*- Experience of leading and developing cyber security teams, with the ability to design, implement and continuously improve Security Operations capabilities, including threat detection, automation, orchestration and the development of security processes and procedures to meet evolving business and threat requirements.
  • Experience of advising on organisational and technical responses to cyber security incidents, with responsibility for developing and driving incident investigation, response policies, processes and procedures.
  • Expert knowledge of system architectures, with the ability to assess and articulate the impact of vulnerabilities on existing and future systems, services and designs.

Experience of working in a multidisciplinary team environment, and delivering quality security objectives in a timely manner, among other competing digital priorities.

  • *Technical Skills:

This role is aligned to the *Cyber Security Analyst*role in the Digital, Data and Technology Profession.

These skills will be tested during the Technical Assessment if you are successful at sift stage. They will be not be assessed at application stage. Please review the following to understand the skill expectations Cyber Security Operations - Government Digital and Data Profession Capability Framework .

How to apply

Apply online, providing a CV and supporting statement (of no more than *1000*words) providing evidence of how you meet the behaviours, experience and technical skills listed in the Success Profile above. Both the CV and the supporting statement provided will be assessed against the criteria for the role.

Artificial Intelligence (AI) tools can be used to support your application, but all statements and examples provided must be truthful, factually accurate and taken directly from your own experience. Where plagiarism has been identified (presenting the ideas and experiences of others, or generated by artificial intelligence, and presented as your own) applications will be withdrawn and internal candidates may be subject to disciplinary action.

Please see our candidate guidance for more information on acceptable and unacceptable uses of AI in recruitment.

*Skilled Worker sponsorship is not available for this role. As a result, we are unable to appoint candidates who require Skilled Worker sponsorship now or in the future. Applicants must have an existing and ongoing right to work in the UK.

Candidates will have their applications assessed against all Experience criteria. In the event of a high volume of applications, candidates will have their applications initially assessed against the *Lead experience*criteria. Candidates who pass this initial sift will have their applications fully assessed against the listed criteria.

C andidates who are successful at sift stage will be invited to attend an Interview and Technical Assessment. The interview will further assess the Experience listed in the job advert and the Technical Assessment will evaluate the Technical Skills relevant to the role.

Candidates who pass the sift and are invited to the Interview and Technical Assessment stage will receive a Technical Assessment Candidate Pack, which will outline the skills to be assessed and the assessment methods to be used.

Following the application sift, there may be a telephone interview as part of the assessment process before the main interview.

Assessments are scheduled for w/c *14 September 2026*however this may be subject to change.

Recruitment Principles

As a government organisation, we adhere to the Civil Service Commission Recruitment Principles and we investigate any complaints received in relation to recruitment cases.

About us

Disclosure Scotland is an Executive Agency of the Scottish Government working on behalf of Scottish Ministers. You will be part of a trusted team delivering essential public protection services. Our mission is to safeguard people and support national priorities, including Children and Young People, Fair Work, Communities, Human Rights and the wider economy.

Our staff are part of the UK Civil Service , observing the Civil Service Code and working for Ministers and senior stakeholders to deliver vital public services which improve the lives of the people of Scotland.

We offer a supportive and inclusive working environment along with a wide range of employee benefits. Find out more about what we offer .

As part of the UK Civil Service, we uphold the Civil Service Nationality Rules .

Working pattern

Our standard hours are 35 hours per week and we offer a range of flexible working options depending on the needs of the role, including Flexi-leave. Scottish Government staff in hybrid-compatible roles will be expected to attend the office 2 days per week. If you have specific questions about the role you are applying for, please contact us.

Security checks

Successful candidates must complete the Baseline Personnel Security Standard (BPSS), before they can be appointed. BPSS is comprised of four main pre-employment checks – Identity, Right to work, Employment History and a Criminal Record check (unspent convictions).

You can find out more about BPSS on the UK Government website , or read about the different levels of security checks in our Candidate Guide .

Successful candidates must be willing to obtain Security Check (SC) clearance if necessary. You can find out more about SC clearance here: https://www.gov.uk/government/publications/united-kingdom-security-vetting-clearance-levels/national-security-vetting-clearance-levels#security-check-sc

Pay supplement

This post is part of the Government Digital and Data (GDD) profession and currently attracts a *£4000*annual GDD pay supplement, which is paid monthly – pay supplements are reviewed regularly.

Equality statement

We are committed to equality and inclusion and we aim to recruit a diverse workforce that reflects the population of our nation.

Find out more about our commitment to diversity and how we offer and support recruitment adjustments for anyone who needs them.

Further information

Find out more about our organisation, what we offer staff members and how to apply on our Careers Website .

Read our Candidate Guide for further information on our recruitment and application processes.

Responsibilities

  • Lead engagement with key stakeholders across Disclosure Scotland and the wider Scottish Government, acting as the primary point of contact for cyber security matters.
  • Provide expert cyber security advice and guidance, supporting the effective implementation and operation of security controls across the organisation.

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in Glasgow

Why this fits a police background

  • Evidence & case files
  • Investigative casework
  • Security operations
  • Safeguarding & public protection

What cyber security & digital forensics roles pay ex-police

Advertised UK ranges, editorial estimates reviewed July 2026

Digital forensics analyst£32,000–£45,000
DFIR consultant£45,000–£65,000
Senior forensics / IR specialist£60,000–£80,000
Threat-intelligence specialist£55,000–£80,000
Full cyber security & digital forensics salary guide →

More cyber security & digital forensics jobs for ex-police

  • Threat Analyst

    SCC · Birmingham

    Full-time

    Your background in intelligence analysis and threat assessment from policing maps directly to producing structured threat intelligence deliverables. You are used to researching hostile actors, evaluating sources, and writing concise briefings for different audiences, which is exactly what this role demands. Your incident response experience and disciplined approach to evidence and reporting would let you contribute from day one, while any gaps in specific tooling can be trained.

    Posted Today

  • Cyber Incident Responder

    CYFOR · Manchester

    Full-time

    £40,000 – £50,000Estimated

    Your experience investigating digital evidence and managing incidents in policing gives you a strong foundation for this role, particularly in forensic acquisition, log analysis, and producing evidential reports. The requirement for clear client communication and structured investigation aligns with your interview and case-file skills, though you would need to build specific technical knowledge of cloud environments and EDR tools.

    Posted Yesterday

  • Full-time

    This role focuses on information security management, risk assessment, and incident response — areas where your experience in operational policing, threat assessment, and managing critical incidents translates directly. Your background in following strict procedures, handling sensitive information, and coordinating multi-agency responses aligns well with the security governance and compliance aspects of the job. While the role requires specific technical cyber security knowledge, your investigative mindset and ability to work under pressure are strong foundations that employers in this sector

    Posted Yesterday

  • Full-time

    Your experience in policing has given you a strong foundation in risk assessment, threat identification, and incident management, which are directly applicable to IT risk management. You are used to working under pressure, making decisions based on incomplete information, and communicating complex risks to senior stakeholders. While you may need to develop specific technical knowledge of IT frameworks like ISO 31000 or NIST, your core skills in evaluating threats, implementing controls, and ensuring compliance are highly transferable to this role.

    Posted Yesterday