Skip to main content
AfterDuty

Senior Security Analyst

Kocho · Cardiff, Wales

Type
Full-time
Posted
13 days ago

Overview

Your incident command and crisis management experience supports the escalation and bridge-running aspects of this role.

About this role

We are Kocho

Kocho recognise that technology on its own does not deliver change and offers technology adoption services alongside excellent technical consulting to enable our clients to achieve their business goals on their journey to Become Greater.

Our head office is in the heart of London’s West End and provides a comfortable working environment with flexible collaboration spaces that encourage our people to Become Greater with the aim to Do What’s Right.

Kocho is an equal opportunities employer. We make recruitment decisions based on qualifications, skill set and experiences. We consider all suitable candidates regardless of their age, sex, gender reassignment, race, religious beliefs, or lack thereof, marital status, disability or sexual orientation or any other protected characteristic. This is mindset aligns with our company values as we understand that we are Better Together.

Here is the role

Kocho operate exclusively in the Microsoft Stack. We are experts in everything Microsoft – Azure, Intune, KQL – you name it – it’s in the remit. We expect you to be experienced across the stack with familiarity of the Security Tooling, though you will largely be residing in the Unified Security Operations Platform (formerly Microsoft Defender XDR & Microsoft Sentinel).

In this role, you will be responsible for

  • Ensuring Incident SLAs are met by monitoring our “Work Queue”, which contains high-priority Incidents that must be acknowledged, supported by a Team of Analysts
  • Participate on the On-Call Rota (Second Line Escalations Out of Hours)
  • Respond to Incidents on a first-line basis where Capacity levels require your intervention
  • Be the ‘first responder’ to Escalations from the Analytical Team, before they reach Senior Levels
  • Escalate as required, with fully enriched notes and findings into Senior Team Members
  • Assist the Analytical Team Lead in taking ownership of Incident Escalations, Incident Response & Client Communications. You may be expected to run an Incident Bridge in the event that the Analytical Team Lead is unavailable.
  • Become a master of our Runbook documentation and maintaining an industry standard ‘Wiki’, containing both information and expand our ‘KQL Library’
  • Monitor and remediate our industry-leading Phishing & Email Management tool by responding to potential threats reported by our Users and our Clients
  • ‘Bridge’ relationships between Service Delivery, Engineering & our Architectural Team by feeding input into the Analytical Team Lead via regular cadences
  • Become a Subject Matter Expert in ‘Tuning’ Incidents – raise & review requests through our Azure DevOps Pipelines
  • Mentor our Analysts by being a Subject Matter Expert in KQL and all things Microsoft Security

This is what we need from you

  • A degree in Computer Science, Cyber Security or a related field or equivalent and demonstrable experience
  • Solid experience in an Analytical Role revolving around Microsoft Defender XDR & Microsoft Sentinel
  • Strong knowledge of security best practices, particularly UK based requirements
  • Very strong ability to query large data sets using KQL and understand how data is structured in Log Analytics
  • Very strong knowledge of the Microsoft Security Stack, particularly everything available in Microsoft Defender XDR
  • Very strong written & verbal communication skills – you will be expected to be contribute to high stakes situations with Clients

Would be great if you have

  • Proficiency in certain languages, standards and assemblies/tools such as Python, Bicep, ARM, JSON
  • Professional certifications such as AZ-900, SC-300, SC-900, Security+, Network+, A+
  • Experience in mentoring junior members of staff

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in Cardiff

Why this fits a police background

  • Incident command & response
  • Security operations
  • Training & coaching delivery
  • Team & shift leadership

What cyber security & digital forensics roles pay ex-police

Advertised UK ranges, editorial estimates reviewed July 2026

Digital forensics analyst£32,000–£45,000
DFIR consultant£45,000–£65,000
Senior forensics / IR specialist£60,000–£80,000
Threat-intelligence specialist£55,000–£80,000
Full cyber security & digital forensics salary guide →

More cyber security & digital forensics jobs for ex-police

  • Cyber Security Analyst L1

    Airbus · Cardiff

    Full-time

    Your incident command and high-pressure decision-making experience transfers directly to SOC triage and threat response.

    Posted 3 days ago

  • Cyber Security Analyst L1

    Airbus Protect · Cardiff

    Full-time

    Your incident response discipline and composure under pressure are directly applicable to SOC triage and monitoring.

    Posted 3 days ago

  • Full-time

    Your investigative mindset and evidence-handling discipline from policing transfer directly to digital forensics and incident response.

    Posted Yesterday

  • Contract

    Your investigative judgement and incident response experience from policing transfer directly to cybercrime analysis.

    Posted 2 days ago