About this role
Details
National: £57,204 - £66,122 London: £62,988 - £74,822
Offers above the band minimum are subject to our assessment of your skills and experience as demonstrated at interview. Salaries over the band minimum will be paid as a non-pensionable allowance.
A Civil Service Pension with an employer contribution of 28.97%
GBP
Job grade
Business area
CO - Digital - Cyber Security
Type of role
Digital
Working pattern
Flexible working, Full-time, Part-time
Number of jobs available
1
Contents
•
About the job
•
Benefits
•
Things you need to know
•
Apply and further information
About the job
Job summary
The Cabinet Office supports the Prime Minister and ensures the effective running of government. It is also the corporate headquarters for government, in partnership with HM Treasury, and takes the lead in certain critical policy areas.
The Cyber Defence team delivers cyber threat intelligence, threat detection and incident response capabilities for the Cabinet Office, and is responsible for defending both internal IT infrastructure and citizen-facing services. As an Incident Response Lead, youll take a primary role in building and delivering these core capabilities, focusing on managing and responding to incidents.
IMPORTANT:**SECURITY VETTING
This role requires SC (Security Check) which will be conducted by the NSV (National Security vetting). You need to have been resident in the UK within the past five years in order to apply. Here is a short video why this is necessary.
Job description
As an Incident Response Lead, you will
•
Lead the investigation of security alerts to understand the nature and extent of possible cyber incidents
•
Lead the forensic analysis of systems, files, network traffic and cloud environments
•
Lead the technical response to cyber incidents by identifying and implementing (or coordinating the implementation of) containment, eradication and recovery actions
•
Support the wider coordination of cyber incidents
•
Review previous incidents to identify lessons and actions
•
Identify and deliver opportunities for continual improvement of the incident response capability
•
Work closely alongside other Cyber Defence functions, supporting the continual improvement of wider capabilities
•
Develop and update internal plans, playbooks and knowledge base articles
•
Act as an escalation point for, and provide coaching and mentoring to, security analysts
•
Be responsible for leadership and line management of security analysts
Cyber incidents can and do arise on a 24/7 basis. The team operates an out-of-hours on call rota, which you will be expected to join.
Person specification
Essential criteria
Were interested in people who have
•
Significant experience investigating and responding to cyber incidents
•
Significant experience using security tools (e.g., EDR, SIEM) to support the investigation and response to cyber incidents
•
Experience managing and coordinating the response to cyber incidents
•
Experience coaching and mentoring junior staff
•
An in-depth understanding of the tools, techniques and procedures used by threat actors
•
Excellent analytical and problem-solving skills
•
Excellent verbal and written communication skills
Desirable criteria
Its desirable, but not essential, that you have
•
Experience with Splunk
•
Experience working in an Agile environment
•
Experience with cloud environments such as AWS
Additional information
A minimum 60% of your working time should be spent at your principal workplace. Although requirements to attend other locations for official business will also count towards this level of attendance.
Behaviours
We'll assess you against these behaviours during the selection process:
- Managing a Quality Service
- Delivering at Pace
- Making Effective Decisions
- Working Together
We only ask for evidence of these behaviours on your application form:
•
Managing a Quality Service
Technical skills
We'll assess you against these technical skills during the selection process:
- Applied Security Capability
- Incident Management, Incident Investigation and Response
- Information Risk Assessment and Risk Management
- Intrusion Detection and Analysis
- Protective Security
- Threat Intelligence and Threat Assessment
- Threat Understanding
We only ask for evidence of these technical skills on your application form:
•
Incident Management, Incident Investigation and Response
- Intrusion Detection and Analysis
- Threat Understanding
Benefits
Alongside your salary of £57,204, Cabinet Office contributes £16,571 towards you being a member of the Civil Service Defined Benefit Pension scheme. Find out what benefits a Civil Service Pension provides .
•
Learning and development tailored to your role.
•
An environment with flexible working options.
•
A culture encouraging inclusion and diversity.
•
A Civil Service Pension which provides an attractive pension, benefits for dependants and employer contributions of 28.97%.
•
A minimum of 25 days of paid annual leave, increasing by one day per year up to a maximum of 30.
Things you need to know
Artificial intelligence
Artificial intelligence can be a useful tool to support your application, however, all examples and statements provided must be truthful, factually accurate and taken directly from your own experience. Where plagiarism has been identified (presenting the ideas and experiences of others, or generated by artificial intelligence, as your own) applications may be withdrawn and internal candidates may be subject to disciplinary action. Please see our candidate guidance for more information on appropriate and inappropriate use.
Selection process details
This vacancy is using Success Profiles , and will assess your Behaviours, Experience and Technical skills.
Application process
As part of the application process, you will be asked to complete a CV, a behavioural statement and and a number of technical statements.
Further details around what this will entail are listed on the application form.
Should a large number of applications be received, an initial sift may be undertaken using the lead behaviour, Managing a Quality Service. Candidates who pass the initial sift may be progressed to a full sift, or progressed straight to assessment/interview.
Selection process
During the application process you will be assessed on experience behaviours and technical skills whilst during interview, you'll be assessed on behaviours and technical skills. The behaviours and technical skills are listed on this vacancy advert.
Expected timeline (subject to change)
Expected sift date 08/09/2026
Expected interview date/s 15/09/2025
Interview location - Your interview will either be conducted face to face or by video. You will be notified of the location if you are selected for interview.
Reasonable Adjustment
If a person with disabilities is put at a substantial disadvantage compared to a non-disabled person, we have a duty to make reasonable changes to our processes.
If you need a change to be made so that you can make your application, you should:
Contact Government Recruitment Service via cabinetofficerecruitment.grs@cabinetoffice.gov.uk as soon as possible before the closing date to discuss your needs.
Complete the Assistance required section in the Additional requirements page of your application form to tell us what changes or help you might need further on in the recruitment process. For instance, you may need wheelchair access at interview, or if youre deaf, a Language Service Professional.
Further Information
If you are experiencing accessibility problems with any attachments on this advert, please contact the email address in the 'Contact point for applicants' section.
A reserve list may be held for a period of 12 months from which further appointments can be made.
About cyber security & digital forensics roles for ex-police
Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.
See all cyber security & digital forensics jobs in London →Why this fits a police background — match score 90/100
- Intelligence & OSINT
- Incident command & response
- Protection & firearms
- Investigative casework
- Risk & threat assessment
What cyber security & digital forensics roles pay ex-police
Advertised UK ranges, editorial estimates reviewed July 2026
| Digital forensics analyst | £32,000–£45,000 |
| DFIR consultant | £45,000–£65,000 |
| Senior forensics / IR specialist | £60,000–£80,000 |
| Threat-intelligence specialist | £55,000–£80,000 |