Security Analyst (Incident Response Lead)
Cabinet Office · GB
Security Analyst (Incident Response Lead) at Cabinet Office, based in GB, paying £57,204 - £74,822 per annum. This is a permanent role.
- Salary
- £57,204 - £74,822 per annum
- Location
- GB
- Contract
- Permanent
- Posted
- 4 days ago
- Closes
- 30 Aug 2026
- Sector
- Security Officer
About 32% above the going rate for security officer
Reference 29495770da79f525cbecebb3fe534cd4b543b863
About the role
Job summary
The Cabinet Office supports the Prime Minister and ensures the effective running of government. It is also the corporate headquarters for government, in partnership with HM Treasury, and takes the lead in certain critical policy areas.
The Cyber Defence team delivers cyber threat intelligence, threat detection and incident response capabilities for the Cabinet Office, and is responsible for defending both internal IT infrastructure and citizen-facing services. As an Incident Response Lead, you’ll take a primary role in building and delivering these core capabilities, focusing on managing and responding to incidents.
IMPORTANT: SECURITY VETTING
This role requires SC (Security Check) which will be conducted by the NSV (National Security vetting). You need to have been resident in the UK within the past five years in order to apply. Here is a short video why this is necessary.
Job description
As an Incident Response Lead, you will:
- Lead the investigation of security alerts to understand the nature and extent of possible cyber incidents
- Lead the forensic analysis of systems, files, network traffic and cloud environments
- Lead the technical response to cyber incidents by identifying and implementing (or coordinating the implementation of) containment, eradication and recovery actions
- Support the wider coordination of cyber incidents
- Review previous incidents to identify lessons and actions
- Identify and deliver opportunities for continual improvement of the incident response capability
- Work closely alongside other Cyber Defence functions, supporting the continual improvement of wider capabilities
- Develop and update internal plans, playbooks and knowledge base articles
- Act as an escalation point for, and provide coaching and mentoring to, security analysts
- Be responsible for leadership and line management of security analysts
Cyber incidents can and do arise on a 24/7 basis. The team operates an out-of-hours on call rota, which you will be expected to join.
Person specification
Essential criteria
We’re interested in people who have:
- Significant experience investigating and responding to cyber incidents
- Significant experience using security tools (e.g., EDR, SIEM) to support the investigation and response to cyber incidents
- Experience managing and coordinating the response to cyber incidents
- Experience coaching and mentoring junior staff
- An in-depth understanding of the tools, techniques and procedures used by threat actors
- Excellent analytical and problem-solving skills
- Excellent verbal and written communication skills
Desirable criteria
It’s desirable, but not essential, that you have:
- Experience with Splunk
- Experience working in an Agile environment
- Experience with cloud environments such as AWS
Additional information:
A minimum 60% of your working time should be spent at your principal workplace. Although requirements to attend other locations for official business will also count towards this level of attendance.
Behaviours
We'll assess you against these behaviours during the selection process:
- Managing a Quality Service
- Delivering at Pace
- Making Effective Decisions
- Working Together
We only ask for evidence of these behaviours on your application form:
- Managing a Quality Service
Technical skills
We'll assess you against these technical skills during the selection process:
- Applied Security Capability
- Incident Management, Incident Investigation and Response
- Information Risk Assessment and Risk Management
- Intrusion Detection and Analysis
- Protective Security
- Threat Intelligence and Threat Assessment
- Threat Understanding
We only ask for evidence of these technical skills on your application form:
- Incident Management, Incident Investigation and Response
- Intrusion Detection and Analysis
- Threat Understanding
Benefits
Alongside your salary of £57,204, Cabinet Office contributes £16,571 towards you being a member of the Civil Service Defined Benefit Pension scheme. Find out what benefits a Civil Service Pension provides (opens in a new window).- Learning and development tailored to your role.
- An environment with flexible working options.
- A culture encouraging inclusion and diversity.
- A Civil Service Pension which provides an attractive pension, benefits for dependants and employer contributions of 28.97%.
- A minimum of 25 days of paid annual leave, increasing by one day per year up to a maximum of 30.
Things you need to know
Artificial intelligence
Artificial intelligence can be a useful tool to support your application, however, all examples and statements provided must be truthful, factually accurate and taken directly from your own experience. Where plagiarism has been identified (presenting the ideas and experiences of others, or generated by artificial intelligence, as your own) applications may be withdrawn and internal candidates may be subject to disciplinary action. Please see our candidate guidance (opens in a new window) for more information on appropriate and inappropriate use.Selection process details
This vacancy is using Success Profiles (opens in a new window), and will assess your Behaviours, Experience and Technical skills.Application process
As part of the application process, you will be asked to complete a CV, a behavioural statement and and a number of technical statements.
Further details around what this will entail are listed on the application form.
Should a large number of applications be received, an initial sift may be undertaken using the lead behaviour, Managing a Quality Service. Candidates who pass the initial sift may be progressed to a full sift, or progressed straight to assessment/interview.
Selection process
During the application process you will be assessed on experience behaviours and technical skills whilst during interview, you'll be assessed on behaviours and technical skills. The behaviours and technical skills are listed on this vacancy advert.
Expected timeline (subject to change)
Expected sift date – 08/09/2026
Expected interview date/s – 15/09/2025
Interview location - Your interview will either be conducted face to face or by video. You will be notified of the location if you are selected for interview.
Reasonable Adjustment
If a person with disabilities is put at a substantial disadvantage compared to a non-disabled person, we have a duty to make reasonable changes to our processes.
If you need a change to be made so that you can make your application, you should:
C
Reference: 29495770da79f525cbecebb3fe534cd4b543b863 · Posted 4 days ago · Closes 30 Aug 2026 · Listed via Cabinet Office
Apply for this job
This role is listed via Cabinet Office. Applications are handled on the employer's site.
Apply on employer siteOpens the employer's website in a new tab.
Safe applying: a genuine employer will never ask you to pay for a DBS check, training or equipment, or move you onto WhatsApp before you are hired. If this listing does, report it and do not pay anything.