Skip to main content
AfterDuty

Senior Cyber Security Analyst - Cyber Threat Intelligence

Social Security Scotland · Glasgow, Scotland

Salary
£39,767 – £45,472Estimated
Type
Full-time
Posted
19 days ago

Overview

Your investigative mindset and intelligence analysis experience from policing directly apply to identifying and assessing cyber threats.

About this role

Details

GBP

Job grade

Higher Executive Officer

B2

Business area

SSS - Chief Digital Office

Type of role

Other

Working pattern

Full-time

Number of jobs available

1

Contents

  • Location
  • About the job
  • Benefits
  • Things you need to know
  • Apply and further information

About the job

Job summary

We are seeking an experienced and motivated*Senior Cyber Security Analyst specialising in Cyber Threat Intelligence (CTI)* to join the Digital Risk & Security branch within Digital Delivery & Change. This role plays a key part in identifying, analysing, and communicating cyber threats that could impact Social Security Scotland’s digital services, systems, and sensitive information.

As a senior member of the Security Operations function, you will support the delivery and continuous improvement of the organisation’s Cyber Threat Intelligence capability. You will work closely with security teams, technical specialists, and stakeholders to gather, assess, and share actionable threat intelligence that helps strengthen defensive measures, reduce cyber risk, and support informed decision-making across a cloud-first environment.

You will contribute to the operational delivery and development of key Cyber Threat Intelligence services, including:

  • Threat Intelligence Collection and Analysis
  • Threat Hunting and Threat Detection Support
  • Threat Actor and Campaign Tracking
  • Open-Source and Commercial Intelligence Monitoring
  • Indicators of Compromise (IoC) Management
  • Vulnerability and Threat Correlation
  • Strategic, Operational and Tactical Intelligence Reporting
  • Threat Intelligence Sharing and Collaboration
  • Emerging Threat and Risk Assessment
  • Intelligence Support for Incident Response and Security Operations

The role requires strong analytical, investigative, and problem-solving skills, with experience of threat intelligence methodologies, cyber threat landscapes, and industry-recognised frameworks such as MITRE ATT&CK. You will be responsible for assessing complex information from multiple intelligence sources, identifying patterns, and producing timely, actionable intelligence to support risk-based decision-making. The successful candidate will be confident working both independently and collaboratively, applying professional judgement to develop evidence-based assessments, recommendations, and decisions within their area of responsibility. You will take ownership of investigations and intelligence activities, demonstrating the initiative and confidence to act on findings where appropriate, while recognising when matters require escalation. You will also contribute to the continuous improvement of intelligence-led security practices and help ensure the organisation maintains an effective understanding of evolving cyber threats.

If you are passionate about cyber threat intelligence and want to play a key role in protecting critical public services and citizen data, we would welcome your application.

Cyber Security Analysts are responsible for protecting the confidentiality, integrity, and availability of information and information systems used by government and Partners Across Government.

  • Explains the purpose of and provides advice and guidance on the application and operation of elementary physical, procedural and technical security controls.
  • Performs security risk, vulnerability assessments, and business impact analysis for medium complexity information systems.
  • Investigates suspected attacks and manages security incidents including use of forensics where appropriate.
  • Maintains security administration processes and checks that all requests for support are dealt with according to agreed procedures.
  • Specifies requirements for environment, data, resources and tools. Interprets, executes and documents complex test scripts using agreed methods and standards.

Job description

Responsibilities

  • Gather, analyse and share cyber threat intelligence from a range of sources to identify cyber threats, vulnerabilities and emerging risks affecting the organisation.
  • Produce and deliver cyber threat reports, briefings and risk assessments for technical teams, senior leaders and key stakeholders, providing clear recommendations to improve cyber resilience.
  • Provide advice and guidance on cyber security controls, helping teams understand and apply security best practice.
  • Communicate cyber security risks and issues clearly to managers, stakeholders and colleagues across the organisation.
  • Investigate security incidents and breaches, using forensic techniques where appropriate, and support the implementation of corrective actions.
  • Carry out security risk assessments, vulnerability assessments and business impact analyses to help identify and manage cyber risks.
  • Develop security test cases based on identified risks, threats and common vulnerabilities.
  • Keep up to date with the latest cyber security threats, attack methods and industry developments.
  • Provide specialist cyber security advice and support, applying expertise to complex security challenges and projects.

Person specification

Success Profiles

We use an assessment framework called ‘Success Profiles’ which lists the elements we test and provides detailed descriptions of each. Find out more about the framework here.

For this post, the following Success Profile elements will be assessed:

Experience

  • Experience of delivering or reviewing cyber security risk assessments for enterprise IT systems using recognised methodologies, incorporating threat intelligence from a range of sources to assess emerging threats, vulnerabilities and organisational risk.
  • Experience of conducting and developing security investigations, threat hunting activities or vulnerability assessments across enterprise environments, selecting and applying appropriate tools, techniques and methodologies to identify vulnerabilities, malicious activity and indicators of compromise.

Behaviours

  • Seeing the Bigger Picture - Level 3
  • Communicating and Influencing - Level 3

You can find out more about Success Profiles Behaviours here.

Technical / Professional Skills

This role is aligned to Senior Cyber Security Analyst within the Government Digital and Data Profession.

These skills will be tested during the Technical Assessment if you are successful at sift stage. They will not be assessed at application stage. Please review the following to understand the skill expectations Cyber security: operations - gov.scot.

Benefits

Annual Leave - You will receive 25 days annual leave on joining us. This will increase to 30 days after four full years of service. You will also have 11.5 public and privilege days of leave every year. We also offer Flexi-time. Any extra hours you've worked can be taken as leave when suitable.

A Civil Service Pension - This job comes with a Civil Service pension. New joiners to the Civil Service will join a career average pension scheme as standard. Read more here - www.civilservicepensionscheme.org.uk.

Healthy work life balance - We can offer the possibility of full-time, part-time, term-time, and job shares. We also encourage flexible working.

Discounts - You can enjoy a vast range of retail, travel and lifestyle discounts through our benefit scheme.

Personal support for you - Our Employee Assistance Programme gives you confidential, independent information and guidance 24/7.

Volunteering special leave - Up to six days paid special leave a year for volunteering. We support our staff to help causes important to them.

Great locations - Our bright and modern offices in the heart of Dundee and Glasgow have been designed with staff in mind. Both locations are ideal for public transport.

Things you need to know

Artificial intelligence

Artificial intelligence can be a useful tool to support your application, however, all examples and statements provided must be truthful, factually accurate and taken directly from your own experience.

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in Glasgow

Why this fits a police background — match score 65/100

  • Intelligence & OSINT
  • Incident command & response
  • Investigative casework
  • Risk & threat assessment
  • Security operations

What cyber security & digital forensics roles pay ex-police

Advertised UK ranges, editorial estimates reviewed July 2026

Digital forensics analyst£32,000–£45,000
DFIR consultant£45,000–£65,000
Senior forensics / IR specialist£60,000–£80,000
Threat-intelligence specialist£55,000–£80,000
Full cyber security & digital forensics salary guide →

More cyber security & digital forensics jobs for ex-police

  • Information Security Officer

    Police Scotland · Glasgow

    Contract

    Police Scotland is seeking an experienced Information Security professional to join our Information Security and Records Management team with a specialist focus on Data Loss Prevention (DLP).x This is an exciting opportunity for an individual with strong Information Security, Governance, Risk and…

    Posted 8 days ago

  • Full-time

    Your digital forensics and evidence-handling discipline from policing maps directly onto this insider risk investigation role.

    Posted 14 days ago

  • Full-time

    Your incident command and evidence-handling skills directly apply to coordinating cyber incident response and maintaining chain-of-custody.

    Posted 20 days ago

  • Cyber Security Analyst

    The Scottish Government · Glasgow

    Full-time

    £62,111 – £77,439Estimated

    Your experience managing incidents, assessing threats, and leading multi-agency responses in policing directly translates to leading cyber incident management and risk assessments. The role's emphasis on stakeholder engagement and policy development mirrors the collaborative and procedural work you did in command or investigation roles. While deep technical cyber expertise may require upskilling, your operational discipline and strategic thinking make you a strong candidate for this managerial position.

    Posted 22 days ago