Skip to main content
AfterDuty

Security Analyst (Incident Response Lead)

CABINET OFFICE · London, Greater London

Salary
£57,204 – £74,822Estimated
Type
Full-time
Posted
4 days ago

Overview

Details National: £57,204 - £66,122 London: £62,988 - £74,822 Offers above the band minimum are subject to our assessment of your skills and experience as demonstrated at interview. Salaries over the band minimum will be paid as a non-pensionable allowance.

About this role

Details

National: £57,204 - £66,122 London: £62,988 - £74,822

Offers above the band minimum are subject to our assessment of your skills and experience as demonstrated at interview. Salaries over the band minimum will be paid as a non-pensionable allowance.

A Civil Service Pension with an employer contribution of 28.97%

GBP

Job grade

Business area

CO - Digital - Cyber Security

Type of role

Digital

Working pattern

Flexible working, Full-time, Part-time

Number of jobs available

1

Contents

About the job

Benefits

Things you need to know

Apply and further information

About the job

Job summary

The Cabinet Office supports the Prime Minister and ensures the effective running of government. It is also the corporate headquarters for government, in partnership with HM Treasury, and takes the lead in certain critical policy areas.

The Cyber Defence team delivers cyber threat intelligence, threat detection and incident response capabilities for the Cabinet Office, and is responsible for defending both internal IT infrastructure and citizen-facing services. As an Incident Response Lead, you’ll take a primary role in building and delivering these core capabilities, focusing on managing and responding to incidents.

IMPORTANT:**SECURITY VETTING

This role requires SC (Security Check) which will be conducted by the NSV (National Security vetting). You need to have been resident in the UK within the past five years in order to apply. Here is a short video why this is necessary.

Job description

As an Incident Response Lead, you will

Lead the investigation of security alerts to understand the nature and extent of possible cyber incidents

Lead the forensic analysis of systems, files, network traffic and cloud environments

Lead the technical response to cyber incidents by identifying and implementing (or coordinating the implementation of) containment, eradication and recovery actions

Support the wider coordination of cyber incidents

Review previous incidents to identify lessons and actions

Identify and deliver opportunities for continual improvement of the incident response capability

Work closely alongside other Cyber Defence functions, supporting the continual improvement of wider capabilities

Develop and update internal plans, playbooks and knowledge base articles

Act as an escalation point for, and provide coaching and mentoring to, security analysts

Be responsible for leadership and line management of security analysts

Cyber incidents can and do arise on a 24/7 basis. The team operates an out-of-hours on call rota, which you will be expected to join.

Person specification

Essential criteria

We’re interested in people who have

Significant experience investigating and responding to cyber incidents

Significant experience using security tools (e.g., EDR, SIEM) to support the investigation and response to cyber incidents

Experience managing and coordinating the response to cyber incidents

Experience coaching and mentoring junior staff

An in-depth understanding of the tools, techniques and procedures used by threat actors

Excellent analytical and problem-solving skills

Excellent verbal and written communication skills

Desirable criteria

It’s desirable, but not essential, that you have

Experience with Splunk

Experience working in an Agile environment

Experience with cloud environments such as AWS

Additional information

A minimum 60% of your working time should be spent at your principal workplace. Although requirements to attend other locations for official business will also count towards this level of attendance.

Behaviours

We'll assess you against these behaviours during the selection process:

  • Managing a Quality Service
  • Delivering at Pace
  • Making Effective Decisions
  • Working Together

We only ask for evidence of these behaviours on your application form:

Managing a Quality Service

Technical skills

We'll assess you against these technical skills during the selection process:

  • Applied Security Capability
  • Incident Management, Incident Investigation and Response
  • Information Risk Assessment and Risk Management
  • Intrusion Detection and Analysis
  • Protective Security
  • Threat Intelligence and Threat Assessment
  • Threat Understanding

We only ask for evidence of these technical skills on your application form:

Incident Management, Incident Investigation and Response

  • Intrusion Detection and Analysis
  • Threat Understanding

Benefits

Alongside your salary of £57,204, Cabinet Office contributes £16,571 towards you being a member of the Civil Service Defined Benefit Pension scheme. Find out what benefits a Civil Service Pension provides .

Learning and development tailored to your role.

An environment with flexible working options.

A culture encouraging inclusion and diversity.

A Civil Service Pension which provides an attractive pension, benefits for dependants and employer contributions of 28.97%.

A minimum of 25 days of paid annual leave, increasing by one day per year up to a maximum of 30.

Things you need to know

Artificial intelligence

Artificial intelligence can be a useful tool to support your application, however, all examples and statements provided must be truthful, factually accurate and taken directly from your own experience. Where plagiarism has been identified (presenting the ideas and experiences of others, or generated by artificial intelligence, as your own) applications may be withdrawn and internal candidates may be subject to disciplinary action. Please see our candidate guidance for more information on appropriate and inappropriate use.

Selection process details

This vacancy is using Success Profiles , and will assess your Behaviours, Experience and Technical skills.

Application process

As part of the application process, you will be asked to complete a CV, a behavioural statement and and a number of technical statements.

Further details around what this will entail are listed on the application form.

Should a large number of applications be received, an initial sift may be undertaken using the lead behaviour, Managing a Quality Service. Candidates who pass the initial sift may be progressed to a full sift, or progressed straight to assessment/interview.

Selection process

During the application process you will be assessed on experience behaviours and technical skills whilst during interview, you'll be assessed on behaviours and technical skills. The behaviours and technical skills are listed on this vacancy advert.

Expected timeline (subject to change)

Expected sift date – 08/09/2026

Expected interview date/s – 15/09/2025

Interview location - Your interview will either be conducted face to face or by video. You will be notified of the location if you are selected for interview.

Reasonable Adjustment

If a person with disabilities is put at a substantial disadvantage compared to a non-disabled person, we have a duty to make reasonable changes to our processes.

If you need a change to be made so that you can make your application, you should:

Contact Government Recruitment Service via cabinetofficerecruitment.grs@cabinetoffice.gov.uk as soon as possible before the closing date to discuss your needs.

Complete the ‘Assistance required’ section in the ‘Additional requirements’ page of your application form to tell us what changes or help you might need further on in the recruitment process. For instance, you may need wheelchair access at interview, or if you’re deaf, a Language Service Professional.

Further Information

If you are experiencing accessibility problems with any attachments on this advert, please contact the email address in the 'Contact point for applicants' section.

A reserve list may be held for a period of 12 months from which further appointments can be made.

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in London

Why this fits a police background — match score 90/100

  • Intelligence & OSINT
  • Incident command & response
  • Protection & firearms
  • Investigative casework
  • Risk & threat assessment

What cyber security & digital forensics roles pay ex-police

Advertised UK ranges, editorial estimates reviewed July 2026

Digital forensics analyst£32,000–£45,000
DFIR consultant£45,000–£65,000
Senior forensics / IR specialist£60,000–£80,000
Threat-intelligence specialist£55,000–£80,000
Full cyber security & digital forensics salary guide →

More cyber security & digital forensics jobs for ex-police

  • Operational Cyber Researcher

    BAE Systems · London

    Full-time

    BAE Systems Digital Intelligence is home to 4,500 digital, cyber and intelligence experts. We work collaboratively across 10 countries to collect, connect and understand complex data, so that governments, nation states, armed forces and commercial businesses can unlock digital advantage in the most…

    Posted 3 days ago

  • Full-time

    Atos is the Atos Group brand dedicated to AI-powered, secure, end-to-end digital services. Atos designs, develops, and operates critical digital environments that drive performance, resilience and sovereignty, helping public and private organizations worldwide retain control over their data and…

    Posted 4 days ago

  • Title: Senior Manager, Cybersecurity Governance, Risk & Compliance (GRC) KBR is seeking a Senior Manager, Cybersecurity Governance, Risk & Compliance (GRC) to lead cybersecurity governance, risk management, information assurance, and data protection activities across the United Kingdom.

    Posted 4 days ago

  • Basic information Business Line Technology & Transformation Job Type Permanent / FTC Date published 31-Jul-2026 Req # 24476 Job description Connect to your opportunity • Role: Cyber Security Manager • Roles available at multiple seniority levels roles available – suitable for applicants with…

    Posted 4 days ago