Skip to main content
AfterDuty

This job is no longer available.

See live cyber security & digital forensics jobs in London or register your CV below and we'll match you to the next one.

SOC Analyst

UK Government - Department for Business and Trade · London, Greater London

Salary
£39,377 – £41,494Estimated
Type
Full-time
Posted
10 days ago

Overview

Details London: £39,377 to £41,494 / National: £35,367 - £37,497 (including allowance). Your salary will be determined by your skills and capability as assessed at interview A Civil Service Pension with an employer contribution of 28.97% GBP Job grade Higher Executive…

About this role

Details

London: £39,377 to £41,494 / National: £35,367 - £37,497 (including allowance).

Your salary will be determined by your skills and capability as assessed at interview

A Civil Service Pension with an employer contribution of 28.97%

GBP

Job grade

Higher Executive Officer

Business area

DBT - CS - Digital, Data and Technology

Type of role

Information Technology

Knowledge and Information Management

Security

Working pattern

Flexible working, Full-time, Part-time

Number of jobs available

1

Contents

About the job

Benefits

Things you need to know

Apply and further information

About the job

Job summary

The Department for Business and Trade (DBT) has a clear mission - to grow the economy. Our role is to help businesses invest, grow and export to create jobs and opportunities right across the country. We do this in three ways.

Firstly, we help to build a strong, competitive business environment, where consumers are protected and companies rewarded for treating their employees properly.

Secondly, we open international markets and ensure resilient supply chains. This can be through Free Trade Agreements, trade facilitation and multilateral agreements.

Finally, we work in partnership with businesses every day, providing advance, finance and deal-making support to those looking to start up, invest, export and grow.

The Digital, Data and Technology (DDaT) directorate develops and operates tools and services to support us in this mission. The team have been nominated four times in a row for ‘Best Public Sector Employer’ at the Women in Tech awards and won the award in 2025!

Job description

We are looking for a capable and motivated SOC Analyst to join the Cyber Incident Detection and Response team and help strengthen our cyber defence capabilities.

In this role, you will play a key part in protecting the department’s systems and data. You will monitor, triage and investigate security alerts, identifying genuine threats and ensuring incidents are accurately assessed, documented and escalated where appropriate. You will also support incident response activities, working closely with Senior Analysts and wider technical teams to deliver effective and coordinated responses.

Alongside operational responsibilities, you will have dedicated time to focus on proactive work. This includes contributing to the improvement of detection rules, refining alerts, supporting threat hunting, and helping to develop repeatable processes and playbooks.

At this level, we are looking for someone who is curious, collaborative and able to use sound judgement in a fast-paced environment. You will manage your workload effectively, communicate clearly with a range of stakeholders, and take ownership of your work while contributing positively to the team.

We are committed to your development, offering protected learning time, access to training platforms, and opportunities to attend external courses and industry events such as SANS.

Main responsibilities

You will

Triage, investigate, and resolve security alerts and incidents in line with established processes, ensuring a timely and effective response.

Contribute to the development and refinement of incident response procedures, playbooks, and documentation.

Support the continuous improvement of logging, monitoring, and alerting capabilities to enhance threat visibility.

Provide support and advice to stakeholders and colleagues.

Maintain awareness of emerging threats, vulnerabilities, and trends to support effective detection and response.

Use time away from live operations to develop key SOC capabilities, including alert refinement, dashboard creation, and engagement across the wider Cyber team.

Person specification

It is essential that you have

  • Hands-on experience working in a professional Security Operations Centre (SOC), including direct involvement in responding to security alerts using a SIEM, conducting triage, and supporting incident investigations. (Lead Criteria)
  • Demonstrable operational experience managing cyber security incidents from initial triage through to resolution. (Lead Criteria)

Demonstrable experience investigating security events within cloud platforms (e.g. AWS, Azure).

Demonstrable experience contributing to proactive security activities, such as threat hunting or developing detection rules.

Experience analysing security data using a query language (e.g. KQL, SQL, SPL). Familiarity with KQL (Kusto Query Language) is particularly desirable.

Effective verbal and written communication skills, including the ability to collate and present information clearly and accurately.

It is desirable that you have

Relevant or working towards cyber security certifications or qualifications.

Behaviours

We'll assess you against these behaviours during the selection process:

  • Making Effective Decisions
  • Working Together

Technical skills

We'll assess you against these technical skills during the selection process:

  • Intrusion Detection and Analysis
  • Threat Understanding
  • Cyber Security Operations
  • Threat intelligence and threat assessment
  • Forensics

Benefits

Alongside your salary of £35,367, Department for Business and Trade contributes £10,245 towards you being a member of the Civil Service Defined Benefit Pension scheme. Find out what benefits a Civil Service Pension provides .

Learning and development tailored to your role

An environment with flexible working options

A culture encouraging inclusion and diversity

A Civil Service pension with an employer contribution of 28.97%

Things you need to know

Artificial intelligence

Artificial intelligence can be a useful tool to support your application, however, all examples and statements provided must be truthful, factually accurate and taken directly from your own experience. Where plagiarism has been identified (presenting the ideas and experiences of others, or generated by artificial intelligence, as your own) applications may be withdrawn and internal candidates may be subject to disciplinary action. Please see our candidate guidance for more information on appropriate and inappropriate use.

Selection process details

This vacancy is using Success Profiles , and will assess your Behaviours, Experience and Technical skills.

As part of the application process you will be asked to upload a two-page CV and complete a 750 word personal statement outlining how you meet the essential skills and experience listed above. You can use bullet points and subheadings if you prefer.

Sift will be from week commencing 03.08.2026

Interviews will be from week commencing 24.08.2026

Please note these dates are indicative and may be subject to change.

If there is a high volume of applications, we will sift looking at the first two Lead Criteria only. Hands-on experience working in a professional Security Operations Centre (SOC), including direct involvement in responding to security alerts using a SIEM, conducting triage, and supporting incident investigations. (Lead Criteria) and Demonstrable operational experience managing cyber security incidents from initial triage through to resolution.

You may then be progressed to full sift or straight to interview.

At the interview stage for this role, you will be asked to demonstrate relevant Technical Skills and Behaviours from the Success Profiles framework, which are listed above. These are role specific and in line with the DDaT Capability Framework .

Offers will be made in merit order based on location preferences. If you pass the bar at interview but are not the highest scoring you will be held on a 12-month reserve list in case a role becomes available. If you are judged a near miss at interview, you may be offered a post at the grade below the one you applied for.

This role requires SC clearance.

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in London

Why this fits a police background — match score 90/100

  • Intelligence & OSINT
  • Incident command & response
  • Investigative casework
  • Risk & threat assessment
  • Security operations

What cyber security & digital forensics roles pay ex-police

Advertised UK ranges, editorial estimates reviewed July 2026

Digital forensics analyst£32,000–£45,000
DFIR consultant£45,000–£65,000
Senior forensics / IR specialist£60,000–£80,000
Threat-intelligence specialist£55,000–£80,000
Full cyber security & digital forensics salary guide →

More cyber security & digital forensics jobs for ex-police

  • Security Analyst

    Kubrick Group · London

    Full-time

    The opportunity Join us at the forefront of cyber defence, where you'll play a critical role in protecting our business from evolving threats. You'll proactively monitor, investigate and respond to security incidents using Microsoft Sentinel, Microsoft Defender and leading EDR technologies, working…

    Posted 2 days ago

  • Job details *Location:*London, Manchester *Capability:*Advisory *Experience Level:*Associate/Assistant Manager *Type:*Full Time *Business Area:*Cyber *Contract type:*Permanent Job description Cyber Response & Recovery Assistant Manager (Reactive DFIR) This role requires current SC or DV clearance,…

    Posted 2 days ago

  • IT Security Specialist

    Montu Group · London

    Full-time

    £55,000 – £60,000Estimated

    What is the job? Montu UK is entering an exciting new phase in its security journey: creating an independent, future-ready architecture for the UK and Europe.

    Posted 2 days ago

  • SOC Lead

    NCC Group · London

    Contract

    Description We are looking for a proactive SOC Analyst to monitor, detect, investigate, and respond to cyber security threats using the Splunk Enterprise Security toolset.

    Posted 2 days ago