
Senior Cyber Security Analyst
Job summary
We are seeking an experienced Senior Cyber Security Analyst to join Registers of Scotland (RoS) and help protect the organisation as we continue our digital transformation journey.
Working within our Cyber Security team, you will play a key role in detecting, investigating, and responding to cyber threats and security incidents. You'll collaborate with colleagues across security, IT operations, and development teams to strengthen our security capabilities, improve processes, and deliver effective security solutions. As a senior member of the team, you'll also support and mentor colleagues while helping to shape a strong security culture across the organisation.
Job description
Security Operations and Incident Response
- Detect, triage, investigate, and respond to a wide range of cyber security events and incidents using security monitoring and analysis tools.
- Lead and support incident response activities, ensuring security incidents are investigated, contained, eradicated, and resolved in line with agreed procedures.
- Conduct detailed analysis of security alerts to determine impact, severity, and remediation requirements.
- Perform proactive threat hunting activities using indicators of compromise (IoCs), threat intelligence, and emerging threat information from government, industry, and trusted partners.
- Support the wider Security Operations function during major incidents and contribute to post-incident reviews and lessons learned activities.
- Monitor emerging cyber threats and vulnerabilities, assessing potential impacts on organisational services and systems.
- Collaborate with infrastructure, cloud, network, and development teams to investigate and resolve complex security issues.
- Contribute to the continuous improvement of incident response processes, playbooks, and operational procedures.
- Participate in out-of-hours or major incident activities where required.
Security Engineering, Improvement and Automation
- Develop, tune, and optimise security monitoring solutions to improve detection accuracy, reduce false positives, and enhance operational effectiveness.
- Identify opportunities to automate routine security activities, improving efficiency and response times across Security Operations.
- Design and implement new security detections, use cases, and alerting mechanisms to address emerging threats.
- Evaluate existing security services, controls, and tooling, recommending improvements based on industry best practice and organisational needs.
- Support the onboarding and integration of new platforms, services, and technologies into security monitoring capabilities.
- Contribute to vulnerability management activities, helping identify, prioritise, and address security weaknesses.
- Develop metrics, dashboards, and reporting to support operational performance and informed decision making.
- Work closely with projects and product teams to ensure security requirements are considered throughout the delivery lifecycle.
- Keep abreast of emerging technologies, industry trends, and evolving cyber threats, applying this knowledge to improve organisational security.
Leadership, Collaboration and Professional Practice
- Act as a subject matter expert, providing advice and guidance on cyber security matters to technical and non-technical stakeholders.
- Respond to security-related enquiries from colleagues across Digital, Data and Technology and the wider business.
- Mentor and support Cyber Security Analysts, promoting knowledge sharing, professional development, and continuous learning.
- Create, maintain, and review technical documentation, including standard operating procedures, playbooks, investigation guides, and system configuration documentation.
- Support the development and adoption of security standards, policies, and operating procedures.
- Build effective working relationships with colleagues, suppliers, and external partners to strengthen security collaboration.
- Contribute to a culture of continuous improvement, innovation, and operational excellence within the Cyber Security team.
- Communicate complex technical information clearly and effectively to a range of audiences, ensuring security risks and recommendations are understood and actionable.
- Support audit, compliance, and assurance activities by providing evidence, technical input, and subject matter expertise where required.
Person specification
Technical Experience:
We will assess you against the following Technical Experience during the application and assessment process:
- Demonstrable experience working in a Cyber Security Analyst, Security Operations, or Incident Response role, with responsibilities appropriate to a senior-level position.
- Experience of detecting, triaging, investigating, and responding to cyber security events and incidents using security monitoring and analysis tools.
- Experience of developing, maintaining, and tuning security detections and alerting capabilities to improve threat detection and reduce false positives.
- Experience of conducting security investigations, identifying root causes, and supporting the implementation of remediation and mitigation activities.
- Experience of using threat intelligence and indicators of compromise (IoCs) to undertake threat hunting and support proactive security investigations.
- Experience of using IT Service Management (ITSM) tools to manage security incidents, operational tasks, and service requests.
- Practical experience of working with security technologies such as Security Information and Event Management (SIEM), Extended Detection and Response (XDR), Security Orchestration, Automation and Response (SOAR), Next Generation Firewalls (NGFW), Web Application Firewalls (WAF), Network Access Control (NAC), Cloud Security Posture Management (CSPM), or vulnerability management solutions.
- Ability to explain the purpose and operation of technical security controls and provide expert advice and guidance to technical and non-technical stakeholders.
- Experience of creating and maintaining technical documentation, including standard operating procedures, playbooks, investigation guides, and technical standards.
- Strong analytical and problem-solving skills, with the ability to assess risk, prioritise competing demands, and make informed decisions in a fast-paced operational environment.
- Excellent communication skills, with the ability to communicate complex technical concepts clearly and effectively to a range of audiences, including senior stakeholders.
- Experience of mentoring, supporting, or sharing knowledge with colleagues to develop capability and promote a culture of continuous learning.
- Relevant cyber security certifications, qualifications, or equivalent professional experience demonstrating technical expertise and a commitment to continued professional development.
Behaviours
At application stage, you will be scored against the bolded Behaviours and against all Behaviours for the assessment:
Working Together
- Build effective working relationships with colleagues across cyber security, IT operations, development teams, and suppliers to support the delivery of secure and resilient services.
- Collaborate with technical and non-technical stakeholders during security investigations and incidents, ensuring information is shared effectively and appropriate actions are coordinated.
- Foster a positive and inclusive team environment by sharing knowledge, supporting colleagues, and contributing to the success of the wider Cyber Security team.
Developing Self and Others
- Actively develop technical expertise and maintain awareness of emerging cyber threats, technologies, and industry best practice to continually improve personal and team capability.
- Support the development of colleagues through mentoring, coaching, and knowledge sharing, helping to build confidence and capability across the Cyber Security team.
- Encourage a culture of continuous learning by identifying development opportunities and promoting the sharing of lessons learned from incidents, projects, and operational activities.
Managing a Quality Service
- Deliver high-quality security operations services by investigating and resolving security events and incidents in line with agreed processes, standards, and service expectations.
- Identify opportunities to improve the effectiveness and efficiency of security tools, controls, and processes, implementing enhancements where appropriate.
- Create and maintain clear, accurate, and up-to-date documentation, ensuring operational procedures and investigation guidance remain effective and accessible.
Making Effective Decisions
- Analyse security events, threat intelligence, and operational data to assess risk, prioritise activity, and determine appropriate courses of action.
- Make informed and evidence-based decisions during security incidents, balancing risk, impact, and operational priorities to support effective outcomes.
- Evaluate information from multiple sources to identify trends, vulnerabilities, and emerging threats, providing clear recommendations to support decision making and risk management.
Behaviours
We'll assess you against these behaviours during the selection process:
- Working Together
- Developing Self and Others
- Managing a Quality Service
- Making Effective Decisions
Benefits
Alongside your salary of £60,291, Registers of Scotland contributes £17,466 towards you being a member of the Civil Service Defined Benefit Pension scheme. Find out what benefits a Civil Service Pension provides (opens in a new window).- Learning and development tailored to your role
- An environment with flexible working options
- A culture encouraging inclusion and diversity
- A Civil Service pension with an employer contribution of 28.97%
Things you need to know
Artificial intelligence
Artificial intelligence can be a useful tool to support your application, however, all examples and statements provided must be truthful, factually accurate and taken directly from your own experience. Where plagiarism has been identified (presenting the ideas and experiences of others, or generated by artificial intelligence, as your own) applications may be withdrawn and internal candidates may be subject to disciplinary action. Please see our candidate guidance (opens in a new window) for more information on appropriate and inappropriate use.Selection process details
This vacancy is using Success Profiles (opens in a new window), and will assess your Behaviours and Experience.Stage one - Application Process
To apply, click on 'Apply now' and complete the online application form.
You will need to submit:
- A CV outlining your career history and how you meet the Technical Experience criteria (max 4 pages).
- Your responses to application questions within our system and in the given box. These questions will be related to the Technical Experience and 1 behaviour of this role. The word limit is 400 words for each of your responses.
Please note:
- If we receive a high volume of applications, we may complete an initial sift on Technical Experience
- We reserve the right to invite candidates to participate in a telephone interview prior to being further assessed.
- Applications that are not accompanied by CVs will not be scored or statements over 400 words will not be considered.
- We strongly advise you review our policy on responsible use of AI in the application process. RoS may contact you for a pre-screening call to verify your responses.
- Applications and appointments are subject to a strict merit-based assessment process, in line with the Civil Service Recruitment Principles.
Stage two – assessment
If successful at application stage, you will be invited to an in-person interview which will include the following:
- Behaviour based interview, we will assess all the advertised behaviours.
- Hackerrank discussion, we will issue a Hackerrank task in advance and we will ask you some questions regarding that.
Behaviour based interview questions will be given to candidates 15 minutes before the start of the interview to allow candidates to prepare in advance.
Guidance on Interview Notes
- You are welcome to bring notes with you to the interview
- Notes can be either handwritten or typed
- Notes should consist of brief prompts, such as key words or bullet points, to help you structure your responses rather than complete answers
- The interview is a conversation, and we are interested in hearing about your experiences in your own words
Feedback will only be provided if you attend an interview or assessment.
Security
Successful candidates must undergo a standard (or equivalent) criminal record check.People working with government assets must complete baseline personnel security standard (opens in new window) checks.Nationality requirements
This job is broadly open to the following groups:
- UK nationals
- nationals of the Republic of Ireland
- nationals of Commonwealth countries who have the right to work in the UK
- nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities with settled or pre-settled status under the European Union Settlement Scheme (EUSS) (opens in a new window)
- nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities who have made a valid application for settled or pre-settled status under the European Union Settlement Scheme (EUSS)
- individuals with limited leave to remain or indefinite leave to remain who were eligible to apply for EUSS on or before 31 December 2020
- Turkish nationals, and certain family members of Turkish nationals, who have accrued the right to work in the Civil Service
Working for the Civil Service
The Civil Service Code (opens in a new window) sets out the standards of behaviour expected of civil servants.We recruit by merit on the basis of fair and open competition, as outlined in the Civil Service Commission's recruitment principles (opens in a new window).The Civil Service embraces diversity and promotes equal opportunities. As such, we run a Disability Confident Scheme (DCS) for candidates with disabilities who meet the minimum selection criteria.
Diversity and Inclusion
The Civil Service is committed to attract, retain and invest in talent wherever it is found. To learn more please see theCivil Service People Plan (opens in a new window) and the Civil Service Diversity and Inclusion Strategy (opens in a new window).Apply and further information
Once this job has closed, the job advert will no longer be available. You may want to save a copy for your records.Contact point for applicants
Job contact :
- Name : talent@ros.gov.uk
- Email : talent@ros.gov.uk
Recruitment team
- Email : talent@ros.gov.uk
Further information
For further information relating to RoS, including:Additional details on pay & benefits
The Civil Service Code
Complaints process
Use of AI in the application/recruitment process,
Please view our additional information page online.
Share this page
Salary range
- £60,291 - £70,987 per year