Senior Lead Security Operations Analyst
Companies House · Cardiff, Wales
Senior Lead Security Operations Analyst at Companies House, based in Cardiff, Wales, paying £53,540 - £68,250 per annum. This is a permanent role.
- Salary
- £53,540 - £68,250 per annum
- Location
- Cardiff, Wales
- Contract
- Permanent
- Posted
- 10 hours ago
- Closes
- 29 Sep 2026
- Sector
- Security Officer
About 16% above the going rate for security officer
Reference b3b8776a76d77b9a162a74433f16e72eb114689c
About the role
Job summary
Pleasenote: Applicants should review all aspects of this advert to ensure a thorough understanding. If reviewing via a screen reader, please note that the Job summary, Job description, Person specification and Things you need to know sections have been emphasisedAbout The Role
We are looking for an experienced and technically skilled Senior Lead Security Operations Analyst to play a key role in the continued development of Security Operations at Companies House.You will provide technical leadership within the Security Operations team, supporting analysts with complex investigations and helping to ensure security incidents are effectively identified, investigated, contained and escalated.
You will remain hands-on, using security monitoring and threat detection technologies including Microsoft Sentinel, Microsoft Defender and Amazon Web Services security tooling to investigate activity across our cloud and technology environments.
The role will also help drive improvements to our security monitoring capability, including developing and tuning detection rules, improving investigation and response processes, introducing automation and ensuring our monitoring continues to evolve alongside the threats facing Companies House.
We are looking for someone with:
- Strong security operations experience
- Excellent analytical and investigative skills
- The technical knowledge to lead complex investigations and support the development of others.
You should be comfortable working with large volumes of security and log data, making evidence-based decisions and communicating technical security issues clearly to both technical and non-technical colleagues.
This is an opportunity to take a senior technical role within an evolving Security Operations capability and directly influence how Companies House detects, investigates and responds to cyber security threats.
Technical Frameworks
This role aligns with the Government Security Profession Secure Development Framework and the Government Digital and Data (GDaD) DevOps Engineer Capability Framework. Candidates may find these useful when preparing examples for their personal statement and demonstrating relevant technical skills and experience.
- Government Security Profession: Secure Development Framework
Secure Development - UK Government Security - Beta - Government Digital and Data Profession: DevOps Engineer Capability Framework
https://ddat-capability-framework.service.gov.uk/role/development-operations-devops-engineer
Find out more about what a great place Companies House is to work
Job description
To be eligible for this role you also need to meet our Nationality requirements which are outlined below and also successful candidates must meet the security requirements for Security Clearance (SC) before they can be appointed. To gain (SC) clearance you will need to have been a UK resident for a minimum of 3 years out of the last 5 years. For more details, please refer to the ‘Things you need to know’ section below.As the Senior Lead Security Operations Specialist, you will be a senior technical leader within the Companies House Security Operations team, helping to protect our services, systems and information from cyber security threats.
You will combine hands-on technical expertise with leadership responsibility, leading complex security investigations, developing our monitoring and detection capabilities and providing technical guidance to the wider team. You will act as a senior escalation point and support the Head of Security Operations in developing the function.
You will be trusted to make operational security decisions, coordinate responses to significant incidents and engage with senior stakeholders when required.
Companies House operates across Microsoft Azure, Amazon Web Services and enterprise technology environments, with Microsoft Sentinel and Microsoft Defender forming key parts of our security monitoring and investigation capability.
Your key responsibilities will include:
- Leading security investigations and incident response – taking technical ownership of complex or high-impact incidents and coordinating investigation, containment, remediation and escalation.
- Providing technical leadership – acting as a senior escalation point for analysts, providing guidance on complex investigations and supporting effective decision making.
- Developing security monitoring and detection – creating, reviewing and tuning security detections to improve our ability to identify malicious and suspicious activity.
- Managing and improving Microsoft Sentinel and Microsoft Defender – using and developing our security technologies to investigate threats, improve detection coverage and maintain effective monitoring.
- Monitoring cloud environments – detecting and investigating security activity across Amazon Web Services and Microsoft Azure using cloud security services, logs and other security telemetry.
- Improving automation and processes – identifying opportunities to automate Security Operations activities and improve monitoring, investigation and response workflows.
- Developing incident response capability – improving investigation procedures, playbooks and escalation processes and supporting security exercises and readiness activities.
- Developing the team – mentoring analysts, sharing technical knowledge and supporting the development of investigative and technical capability.
- Supporting operational leadership – helping prioritise and coordinate Security Operations activity and providing operational leadership in the absence of the Head of Security Operations when required.
- Working across Companies House – collaborating with security, cloud, platform, infrastructure and software engineering teams to investigate security issues and improve monitoring and response.
- Advising senior stakeholders – communicating significant incidents, risks and technical findings clearly and providing evidence-based recommendations.
- Driving continuous improvement – keeping pace with emerging threats and technologies and using lessons from incidents and operational activity to continually improve our security capability.
This is a hands-on technical role with technical and operational leadership responsibility. You will remain actively involved in security monitoring, investigations, detection engineering and incident response while helping to develop the capability of the wider Security Operations team.
Please note- Companies House cannot offer Visa sponsorship to candidates through this campaign.
About the team
The Security Operations team sits within the wider Security function at Companies House and is responsible for monitoring, detecting, investigating and responding to cyber security threats across our technology and cloud envirReference: b3b8776a76d77b9a162a74433f16e72eb114689c · Posted 10 hours ago · Closes 29 Sep 2026 · Listed via Companies House
Apply for this job
This role is listed via Companies House. Applications are handled on the employer's site.
Apply on employer siteOpens the employer's website in a new tab.
Safe applying: a genuine employer will never ask you to pay for a DBS check, training or equipment, or move you onto WhatsApp before you are hired. If this listing does, report it and do not pay anything.