Back to search

Senior Cyber Security Analyst

Civil Service

Job Description

Job summary

We are seeking an experienced Senior Cyber Security Analyst to join Registers of Scotland (RoS) and help protect the organisation as we continue our digital transformation journey.

Working within our Cyber Security team, you will play a key role in detecting, investigating, and responding to cyber threats and security incidents. You'll collaborate with colleagues across security, IT operations, and development teams to strengthen our security capabilities, improve processes, and deliver effective security solutions. As a senior member of the team, you'll also support and mentor colleagues while helping to shape a strong security culture across the organisation.

Job description

Security Operations and Incident Response

  • Detect, triage, investigate, and respond to a wide range of cyber security events and incidents using security monitoring and analysis tools.
  • Lead and support incident response activities, ensuring security incidents are investigated, contained, eradicated, and resolved in line with agreed procedures.
  • Conduct detailed analysis of security alerts to determine impact, severity, and remediation requirements.
  • Perform proactive threat hunting activities using indicators of compromise (IoCs), threat intelligence, and emerging threat information from government, industry, and trusted partners.
  • Support the wider Security Operations function during major incidents and contribute to post-incident reviews and lessons learned activities.
  • Monitor emerging cyber threats and vulnerabilities, assessing potential impacts on organisational services and systems.
  • Collaborate with infrastructure, cloud, network, and development teams to investigate and resolve complex security issues.
  • Contribute to the continuous improvement of incident response processes, playbooks, and operational procedures.
  • Participate in out-of-hours or major incident activities where required.

Security Engineering, Improvement and Automation

  • Develop, tune, and optimise security monitoring solutions to improve detection accuracy, reduce false positives, and enhance operational effectiveness.
  • Identify opportunities to automate routine security activities, improving efficiency and response times across Security Operations.
  • Design and implement new security detections, use cases, and alerting mechanisms to address emerging threats.
  • Evaluate existing security services, controls, and tooling, recommending improvements based on industry best practice and organisational needs.
  • Support the onboarding and integration of new platforms, services, and technologies into security monitoring capabilities.
  • Contribute to vulnerability management activities, helping identify, prioritise, and address security weaknesses.
  • Develop metrics, dashboards, and reporting to support operational performance and informed decision making.
  • Work closely with projects and product teams to ensure security requirements are considered throughout the delivery lifecycle.
  • Keep abreast of emerging technologies, industry trends, and evolving cyber threats, applying this knowledge to improve organisational security.

Leadership, Collaboration and Professional Practice

  • Act as a subject matter expert, providing advice and guidance on cyber security matters to technical and non-technical stakeholders.
  • Respond to security-related enquiries from colleagues across Digital, Data and Technology and the wider business.
  • Mentor and support Cyber Security Analysts, promoting knowledge sharing, professional development, and continuous learning.
  • Create, maintain, and review technical documentation, including standard operating procedures, playbooks, investigation guides, and system configuration documentation.
  • Support the development and adoption of security standards, policies, and operating procedures.
  • Build effective working relationships with colleagues, suppliers, and external partners to strengthen security collaboration.
  • Contribute to a culture of continuous improvement, innovation, and operational excellence within the Cyber Security team.
  • Communicate complex technical information clearly and effectively to a range of audiences, ensuring security risks and recommendations are understood and actionable.
  • Support audit, compliance, and assurance activities by providing evidence, technical input, and subject matter expertise where required.

Person specification

Technical Experience:

We will assess you against the following Technical Experience during the application and assessment process:

  • Demonstrable experience working in a Cyber Security Analyst, Security Operations, or Incident Response role, with responsibilities appropriate to a senior-level position.
  • Experience of detecting, triaging, investigating, and responding to cyber security events and incidents using security monitoring and analysis tools.
  • Experience of developing, maintaining, and tuning security detections and alerting capabilities to improve threat detection and reduce false positives.
  • Experience of conducting security investigations, identifying root causes, and supporting the implementation of remediation and mitigation activities.
  • Experience of using threat intelligence and indicators of compromise (IoCs) to undertake threat hunting and support proactive security investigations.
  • Experience of using IT Service Management (ITSM) tools to manage security incidents, operational tasks, and service requests.
  • Practical experience of working with security technologies such as Security Information and Event Management (SIEM), Extended Detection and Response (XDR), Security Orchestration, Automation and Response (SOAR), Next Generation Firewalls (NGFW), Web Application Firewalls (WAF), Network Access Control (NAC), Cloud Security Posture Management (CSPM), or vulnerability management solutions.
  • Ability to explain the purpose and operation of technical security controls and provide expert advice and guidance to technical and non-technical stakeholders.
  • Experience of creating and maintaining technical documentation, including standard operating procedures, playbooks, investigation guides, and technical standards.
  • Strong analytical and problem-solving skills, with the ability to assess risk, prioritise competing demands, and make informed decisions in a fast-paced operational environment.
  • Excellent communication skills, with the ability to communicate complex technical concepts clearly and effectively to a range of audiences, including senior stakeholders.
  • Experience of mentoring, supporting, or sharing knowledge with colleagues to develop capability and promote a culture of continuous learning.
  • Relevant cyber security certifications, qualifications, or equivalent professional experience demonstrating technical expertise and a commitment to continued professional development.

Behaviours

At application stage, you will be scored against the bolded Behaviours and against all Behaviours for the assessment:

Working Together

  • Build effective working relationships with colleagues across cyber security, IT operations, development teams, and suppliers to support the delivery of secure and resilient services.
  • Collaborate with technical and non-technical stakeholders during security investigations and incidents, ensuring information is shared effectively and appropriate actions are ...

Yodel are hiring now

Working at Yodel, they promise to support you, develop you and give you all the tools you need to do a great job. They have a range of opportunities across the UK now - why not see if Yodel have the perfect role for you?

See Yodel jobs

Good luck with your application