Security Operations Centre (SOC) - Cyber Security Analyst
Ministry of Defence · Corsham, England
Security Operations Centre (SOC) - Cyber Security Analyst at Ministry of Defence, based in Corsham, England, paying £30,740 per annum. This is a permanent role.
- Salary
- £30,740 per annum
- Location
- Corsham, England
- Contract
- Permanent
- Posted
- 3 weeks ago
- Closes
- 6 May 2027
- Sector
- Security Officer
39% below the typical rate for security officer
Reference 1a3df62c031dfe2361eff5a4bdf5e72fdde2c737
About the role
Job summary
Important Information
Please note that these posts are open to sole UK nationals only. Candidates who hold dual nationality, a student visa or right‑to‑reside status are not eligible to apply. If you are unsure about your eligibility, please contact us prior to submitting an application.
About Us
Cyber & Specialist Operations Command (CSOC) develops and operates specialist capabilities to defend the UK across all domains, keeping the nation secure at home and strong abroad. In response to an increasingly contested cyber environment, CSOC has established the Defence Cyber and Electromagnetic Force (DCEMF).
DCEMF brings together military expertise, Defence cyber professionals and industry partners to strengthen digital defence capabilities, anticipate emerging threats and protect UK military networks from persistent and sophisticated cyber attacks.
We operate at the forefront of data science, automation and cyber security at scale. Our work extends beyond the battlefield, supporting humanitarian operations and driving digital innovation that delivers real‑world impact.
▶ Watch to find out more about what we do.
Passionate about using your skills to make a critical difference? Your next career move could be here.
Job description
Cyber Security Analyst (Security Operations Centre)
The Global Operations and Security Control Centre (GOSCC) delivers a coordinated and coherent approach to cyber defence across Defence. Within GOSCC, the Security Operations Centres (SOCs) provide 24/7/365 defensive monitoring and incident response, underpinning MOD Defensive Cyber Operations and enabling freedom of action in cyberspace.
As a Cyber Security Analyst within the SOC, you will play a critical role in protecting the MOD’s digital enterprise. Working in a fast‑paced operational environment, you will monitor, detect, analyse and respond to cyber security incidents, ensuring the confidentiality, integrity and availability of Defence information systems.
You will use a range of protective monitoring platforms, SIEM tooling and network analysis capabilities to identify malicious activity and emerging threats. Drawing on multiple data sources, you will conduct detailed security log analysis, event correlation and threat intelligence assessment to proactively identify risks to MOD networks and systems.
Your role will involve researching, analysing and correlating data across a wide variety of sources to identify indications and warnings of potential compromise. You will validate intrusion detection system (IDS) alerts against network traffic using packet analysis tools, ensuring alerts are timely, accurate and actionable.
You will support and, where required, lead incident response activity, including containment, investigation, technical analysis and reporting. This includes contributing to major incident response efforts and supporting lessons learned to strengthen Defence cyber resilience.
In addition, you will contribute to the development and enhancement of SOC monitoring capabilities by supporting the design and implementation of automated monitoring and detection processes. You will work with the latest SIEM and network analysis tools, techniques and procedures to continuously improve detection coverage and operational effectiveness.
The role also includes providing operational guidance, advice and support to colleagues within the SOC, including coaching and mentoring team members to maintain high professional standards and effective team performance.
This post offers an opportunity to operate at the heart of Defence cyber operations, directly contributing to the protection of critical systems and information in an increasingly contested cyber domain.
Person specification
Please ensure that your CV and application clearly demonstrate how you meet the essential criteria below.
Essential Criteria
You will be expected to demonstrate:
- Knowledge and understanding of core cyber security principles, methodologies and frameworks (for example, MITRE ATT&CK), and how these apply to current cyber threats.
- Experience of, or a clear understanding of, networking fundamentals and security concepts.
- Familiarity with cyber security technologies and tooling, such as firewalls, endpoint protection, SIEM platforms, and/or other security monitoring tools.
You will also need to demonstrate:
- A strong analytical mindset, with the ability to approach complex problems in a structured and methodical way.
- Excellent communication skills, both written and verbal.
- The ability to prioritise and manage your own workload with minimal supervision.
- The ability to communicate technical information clearly to non‑technical audiences and produce concise, accurate reports for senior stakeholders.
Desirable Attributes
- A strong interest in cyber security, with a commitment to developing skills in security monitoring, incident response and the use of SIEM tooling.
- Willingness to learn and contribute to continuous network and security monitoring in an operational environment.
Training and Development
If not already held, you will have the opportunity to gain the following (or equivalent) certifications while in post:
- GIAC Certified Detection Analyst (GCDA)
- GIAC Continuous Monitoring (GMON)
- GIAC Cloud Threat Detection (GCTD)
If you are not already a member of a relevant professional body, support will be available to assist you in joining one.
Additional Information
You will be a key member of a small (approximately 5‑person) team operating a 24/7/365 shift-based working pattern.
- Shifts include both days and nights and are rostered in blocks of four and five, with equivalent rest periods.
- All shifts have mandatory start and finish times; further details will be provided at interview.
- The role attracts a regular shift allowance and weekend premiums.
- A Digital Skills Allowance (DSA) of up to £9,000 per annum may be payable, dependent on competence, and paid in staged increments.
The normal place of work is MOD Corsham, Wiltshire. Some hybrid working may be possible following successful completion of the probation period. There may be occasional UK travel for meetings, training or operational reasons.
This role requires a high level of security clearance. Applicants must normally have been resident in the UK for at least the last 10 years.
Please note: This vacancy is open to sole UK nationals only. Applicants who hold dual nationality, a student visa or right to reside status are not eligible. If you are unsure about your eligibility, please contact us prior to applying.
Behaviours
We'll assess you against these behaviours during the selection process:
- Changing and Improving
- Making Effective Decisions
Technical skills
We'll assess you against these technical skills during the selection process:
- Cyber Security Operations
- Intrusion Detection and Analysis
- Threat Understanding
Benefits
Alongside your salary of £30,740, Ministry of Defence contributes £8,905 towards you being a member of the Civil Service Defined Benefit Pension scheme. Find out what benefits a Civil Service PReference: 1a3df62c031dfe2361eff5a4bdf5e72fdde2c737 · Posted 3 weeks ago · Closes 6 May 2027 · Listed via Ministry of Defence
Apply for this job
This role is listed via Ministry of Defence. Applications are handled on the employer's site.
Apply on employer siteOpens the employer's website in a new tab.
Safe applying: a genuine employer will never ask you to pay for a DBS check, training or equipment, or move you onto WhatsApp before you are hired. If this listing does, report it and do not pay anything.