
Senior Lead Security Operations Analyst
Job summary
Pleasenote: Applicants should review all aspects of this advert to ensure a thorough understanding. If reviewing via a screen reader, please note that the Job summary, Job description, Person specification and Things you need to know sections have been emphasisedAbout The Role
We are looking for an experienced and technically skilled Senior Lead Security Operations Analyst to play a key role in the continued development of Security Operations at Companies House.You will provide technical leadership within the Security Operations team, supporting analysts with complex investigations and helping to ensure security incidents are effectively identified, investigated, contained and escalated.
You will remain hands-on, using security monitoring and threat detection technologies including Microsoft Sentinel, Microsoft Defender and Amazon Web Services security tooling to investigate activity across our cloud and technology environments.
The role will also help drive improvements to our security monitoring capability, including developing and tuning detection rules, improving investigation and response processes, introducing automation and ensuring our monitoring continues to evolve alongside the threats facing Companies House.
We are looking for someone with:
- Strong security operations experience
- Excellent analytical and investigative skills
- The technical knowledge to lead complex investigations and support the development of others.
You should be comfortable working with large volumes of security and log data, making evidence-based decisions and communicating technical security issues clearly to both technical and non-technical colleagues.
This is an opportunity to take a senior technical role within an evolving Security Operations capability and directly influence how Companies House detects, investigates and responds to cyber security threats.
Technical Frameworks
This role aligns with the Government Security Profession Secure Development Framework and the Government Digital and Data (GDaD) DevOps Engineer Capability Framework. Candidates may find these useful when preparing examples for their personal statement and demonstrating relevant technical skills and experience.
- Government Security Profession: Secure Development Framework
Secure Development - UK Government Security - Beta - Government Digital and Data Profession: DevOps Engineer Capability Framework
https://ddat-capability-framework.service.gov.uk/role/development-operations-devops-engineer
Find out more about what a great place Companies House is to work
Job description
To be eligible for this role you also need to meet our Nationality requirements which are outlined below and also successful candidates must meet the security requirements for Security Clearance (SC) before they can be appointed. To gain (SC) clearance you will need to have been a UK resident for a minimum of 3 years out of the last 5 years. For more details, please refer to the ‘Things you need to know’ section below.As the Senior Lead Security Operations Specialist, you will be a senior technical leader within the Companies House Security Operations team, helping to protect our services, systems and information from cyber security threats.
You will combine hands-on technical expertise with leadership responsibility, leading complex security investigations, developing our monitoring and detection capabilities and providing technical guidance to the wider team. You will act as a senior escalation point and support the Head of Security Operations in developing the function.
You will be trusted to make operational security decisions, coordinate responses to significant incidents and engage with senior stakeholders when required.
Companies House operates across Microsoft Azure, Amazon Web Services and enterprise technology environments, with Microsoft Sentinel and Microsoft Defender forming key parts of our security monitoring and investigation capability.
Your key responsibilities will include:
- Leading security investigations and incident response – taking technical ownership of complex or high-impact incidents and coordinating investigation, containment, remediation and escalation.
- Providing technical leadership – acting as a senior escalation point for analysts, providing guidance on complex investigations and supporting effective decision making.
- Developing security monitoring and detection – creating, reviewing and tuning security detections to improve our ability to identify malicious and suspicious activity.
- Managing and improving Microsoft Sentinel and Microsoft Defender – using and developing our security technologies to investigate threats, improve detection coverage and maintain effective monitoring.
- Monitoring cloud environments – detecting and investigating security activity across Amazon Web Services and Microsoft Azure using cloud security services, logs and other security telemetry.
- Improving automation and processes – identifying opportunities to automate Security Operations activities and improve monitoring, investigation and response workflows.
- Developing incident response capability – improving investigation procedures, playbooks and escalation processes and supporting security exercises and readiness activities.
- Developing the team – mentoring analysts, sharing technical knowledge and supporting the development of investigative and technical capability.
- Supporting operational leadership – helping prioritise and coordinate Security Operations activity and providing operational leadership in the absence of the Head of Security Operations when required.
- Working across Companies House – collaborating with security, cloud, platform, infrastructure and software engineering teams to investigate security issues and improve monitoring and response.
- Advising senior stakeholders – communicating significant incidents, risks and technical findings clearly and providing evidence-based recommendations.
- Driving continuous improvement – keeping pace with emerging threats and technologies and using lessons from incidents and operational activity to continually improve our security capability.
This is a hands-on technical role with technical and operational leadership responsibility. You will remain actively involved in security monitoring, investigations, detection engineering and incident response while helping to develop the capability of the wider Security Operations team.
Please note- Companies House cannot offer Visa sponsorship to candidates through this campaign.
About the team
The Security Operations team sits within the wider Security function at Companies House and is responsible for monitoring, detecting, investigating and responding to cyber security threats across our technology and cloud environments.We are a collaborative and technically focused team made up of Security Operations analysts, senior specialists and threat intelligence capability, working closely with colleagues across security, cloud, platform and engineering teams as well as external security partners.
The team is continuing to develop and modernise its Security Operations capability, with a strong focus on Microsoft Sentinel and Microsoft Defender, alongside increasing security monitoring and response across Amazon Web Services. We are also investing in improved security telemetry, detection engineering, automation and threat intelligence to help us identify and respond to threats more effectively.
There is significant opportunity to influence how the capability develops. We encourage new ideas, continuous improvement and knowledge sharing, with team members given the opportunity to develop their technical skills, take ownership of meaningful work and contribute to the future direction of Security Operations at Companies House.
We have a supportive and collaborative culture where people are encouraged to challenge existing approaches, share knowledge and learn from each other. As a Senior Lead, you will play an important role in maintaining that culture and helping develop the technical capability of the wider team.
Where will you be working?
You will be aligned to either the Cardiff or Edinburgh office, where you will be expected to attend at least once a week. We are currently using a hybrid approach to the way we work which provides opportunities for you to be adaptable in the way you work so that you can achieve a healthy balance between your work and home life. Your manager will agree regular patterns of attendance with you; however, you may be required to make yourself available to attend the office more frequently when required to meet business needs.Person specification
What we’re looking forThe successful candidate will be an experienced cyber security professional with:
- Strong hands-on Security Operations expertise and the technical capability and judgement required to operate as a senior technical lead.
- Significant hands-on experience working within Security Operations, including investigating, triaging and responding to complex security alerts and incidents.
- Strong practical experience using Microsoft Sentinel, including security monitoring, log analysis, incident investigation, developing and tuning detection rules, and improving monitoring coverage.
- Strong experience working with Amazon Web Services, including investigating security activity using cloud security services and telemetry such as CloudTrail, GuardDuty and Identity and Access Management.
- Experience leading complex security investigations, coordinating containment and remediation activities, and making risk-based decisions during security incidents.
- Experience developing and improving Security Operations capabilities, including monitoring processes, incident response procedures, playbooks and automation.
- Advanced knowledge of Microsoft Sentinel, including Kusto Query Language, analytics rules, security investigations, log analysis and automation.
- Strong knowledge of Amazon Web Services security, including cloud logging, identity and access management, threat detection and the investigation of activity across cloud environments.
- Good working knowledge of Microsoft Defender security technologies and their use for threat detection, investigation and response.
- Strong analytical and diagnostic skills, with the ability to correlate security information from multiple data sources, identify malicious or suspicious activity and determine appropriate response actions.
- Practical knowledge of scripting and security automation using technologies such as PowerShell, Python, Terraform or equivalent tooling.
- Strong understanding of cyber threats, attacker techniques and security monitoring principles, with knowledge of relevant frameworks and good practice such as MITRE ATT&CK and the National Cyber Security Centre Cyber Assessment Framework.
- Leadership and Abilities Ability to provide technical leadership within Security Operations, lead complex investigations and provide authoritative guidance to analysts and other technical teams.
- Ability to mentor and develop others while communicating complex security incidents, risks and recommendations clearly to technical, non-technical and senior stakeholders
Behaviours
We'll assess you against these behaviours during the selection process:
- Making Effective Decisions
Technical skills
We'll assess you against these technical skills during the selection process:
- Cyber Security Operations, Intrusion Detection and Analysis and Incident Management, Incident Investigation and Response
- Leading complex cyber security investigations and incident response, including triage, containment, remediation and escalation.
- Hands-on experience using Microsoft Sentinel for security monitoring, investigation, detection development and tuning.
- Experience securing and monitoring Amazon Web Services environments, including investigating activity using relevant security logs and services.
- Developing and improving Security Operations capabilities, including detection engineering, automation, incident response processes and playbooks.
- Providing technical leadership within a Security Operations environment, including supporting complex decision-making and providing guidance to other analysts.
Benefits
Alongside your salary of £53,540, Companies House contributes £15,510 towards you being a member of the Civil Service Defined Benefit Pension scheme. Find out what benefits a Civil Service Pension provides (opens in a new window).We believe that our success is driven by the well-being and satisfaction of our team members at all levels of the organisation. At Companies House we’re committed to providing a comprehensive benefits package that goes beyond the ordinary, ensuring your career journey with us is not only fulfilling, but also rewarding. We pride ourselves on offering a quality work-life balance with our employee wellbeing being central to our working practices.
We offer a comprehensive range of benefits designed to support your wellbeing, professional development and financial security, including:
- Flexible working arrangements, with no core hours and working patterns available between 6am and 8pm.
- Hybrid working opportunities, helping you balance office collaboration with home working.
- 30 days annual leave, plus bank holidays, increasing with service.
- Civil Service Pension Scheme, with an average employer contribution of 28%.
- A strong commitment to learning, development and career progression.
- Access to wellbeing support, resources and initiatives that promote positive physical and mental health.
- A collaborative and inclusive working environment where colleagues are encouraged to bring their whole selves to work.
Head to Our benefits - Working for us - Recruitment (companieshouse.gov.uk) to find out more about the fantastic benefits package we have at Companies House.
Things you need to know
Artificial intelligence
Artificial intelligence can be a useful tool to support your application, however, all examples and statements provided must be truthful, factually accurate and taken directly from your own experience. Where plagiarism has been identified (presenting the ideas and experiences of others, or generated by artificial intelligence, as your own) applications may be withdrawn and internal candidates may be subject to disciplinary action. Please see our candidate guidance (opens in a new window) for more information on appropriate and inappropriate use.Selection process details
This vacancy is using Success Profiles (opens in a new window), and will assess your Behaviours, Experience and Technical skills.Additional details on security and vetting Successful candidates must meet the security requirements for Security Check (SC) before they can be appointed. Further information on the vetting process can be found at National security vetting: clearance levels - GOV.UK.
To be eligible for SC clearance, candidates must meet the vetting criteria and have been a resident in the UK for at least 3 out of the last 5 years. Failure to meet the residency requirements will result in your security clearance application being rejected.
Please review our vetting charter to understand what you can expect from the process - The vetting charter - GOV.UK
If you have questions regarding this or are unsure if you meet the eligibility criteria, please contact recruitmentch@companieshouse.gov.uk
What will the process look like?
Communications will be electronic via email therefore it is important that you check your Civil Service Jobs account regularly, as well as your spam/junk email folder.We welcome applications in Welsh / Rydym yn croesawi ceisiadau yn y Gymraeg.
Key Dates:(dates are indicative only and could be subject to change)
- Closing date: 28th September 2026.
- Sift/shortlist: 29th September 2026 onwards.
- Interviews: 14th October 2026 onwards.
Stage 1–Sift
An initial sift of applications will be carried out to create a shortlist. This will be based on the evidence provided for the Experience Success Profile listed below.We’re committed to being diverse and inclusive, so please make your application anonymous by removing all identifying personal information (such as your name and age) from your personal statement. This also applies to your employment history, this means excluding names of schools, or any personal identifiers.
Experience
Your CV will be used to assess your suitability for the role alongside your 1000-word Personal statement.In your application form we’d like you to:
CV
- Tell us about your employment history that evidences working within a Security Operations background, including key responsibilities and achievements.
Personal statement
Tell us why you’re a great fit for this role by writing a 1000 word personal statement that highlights your relevant experience, skills, and motivations.
As part of the assessment process, we’ll be reviewing your statement for clear evidence of how you meet the criteria outlined below:
- Significant hands-on experience working within Security Operations, including investigating, triaging and responding to complex security alerts and incidents.
- Strong practical experience using Microsoft Sentinel, including security monitoring, log analysis, incident investigation, developing and tuning detection rules, and improving monitoring coverage.
- Strong experience working with Amazon Web Services, including investigating security activity using cloud security services and telemetry such as CloudTrail, GuardDuty and Identity and Access Management.
- Experience leading complex security investigations, coordinating containment and remediation activities, and making risk-based decisions during security incidents.
For guidance on how to structure your application please visit:About the application process , Civil Service Careers.
You can use examples from work, volunteering or other experiences. It is advisable to give clear examples for each criteria listed above, including the impact of your actions, ideally utilising the STAR technique (Situation, Task, Action, Result) with most detail on what you did and the outcome. Please use this link as guidance How to write your PS , Civil Service Careers.
Please note:
In the event of a high volume of applications, an initial sift may be conducted against the Lead Criteria:
Strong practical experience using Microsoft Sentinel, including security monitoring, log analysis, incident investigation, developing and tuning detection rules, and improving monitoring coverage.
If you pass the initial sift (lead criteria), you may either move on to a full sift (full personal statement) or go straight to interview, depending on number of applications received.
We may raise the score required at sift stage to progress to interview if we receive a high number of applications.
Stage 2 - Interviews
Companies House uses a blended interview technique, allowing us to find out more about you. We use the Success Profile framework and at interview we will use Success Profiles assessing the Behaviours and Technical skills listed in the advert. Successful candidates from the sift stage will be invited to a virtual interview, which will be conducted using Microsoft Teams.
As part of the interview process, candidates will be required to complete a presentation assessment. Candidates who are successfully invited to interview will be provided with the presentation topic and full instructions in advance, allowing sufficient time to prepare.
For this part of the assessment, candidates will be assessed against the following Technical element:
Cyber Security Operations, Intrusion Detection and Analysis and Incident Management, Incident Investigation and Response
Further information about the presentation requirements will be included within the interview invitation.
- In the event of a tie at interview, the Lead Criterion (shown in bold below) will be used to determine the final ranking of candidates with the same overall interview score. The Lead Criterion assesses one key technical requirement of the role:
Strong practical experience using Microsoft Sentinel, including security monitoring, log analysis, incident investigation, developing and tuning detection rules, and improving monitoring coverage.
If after the interview you are not found appointable at the advertised grade, you may be offered a lower grade role if you are considered to meet the skills, experience and behaviours for the lower level. The benchmark for appointing to the lower grade is set at the start of each campaign.
Stage 3- offer
Once all interviews have been completed, you will be notified of the outcome by email. Offers will be made in strict merit order to the highest scoring candidate first as outlined in the Civil Service Commissioners’ Recruitment Principles.Reserve list
This recruitment campaign will keep a reserve list for 12 months. If you meet the requirements for this role but aren't offered after passing the interview, you'll be placed on the reserve list. Subject to business need, if a suitable position opens up during this time, we will reach out to individuals in merit order. Successful applicants will be required to start on the date offered to align with the training schedule. Those who are unable to start on that date or are unavailable for certain parts of the training period will be placed on the reserve list for consideration in a future intake.
This post is being advertised Externally.
Incomplete and/or late submissions will not be accepted or considered. Feedback will only be provided if you attend an interview or assessment.
If you require a reasonable adjustment at any stage of the recruitment process, or if you'd like to discuss any person-centred adjustments then please let the recruitment team know viarecruitmentch@companieshouse.gov.uk
We Celebrate Diversity
As an equal opportunity employer, we celebrate diversity, being committed to ensuring we’re representative of the citizens we serve and creating an inclusive environment. Everyone in Companies House brings something different, and so will you. To fulfil our commitment to recruiting and attracting diverse talent we welcome applications from underrepresented groups. We also welcome applications from Welsh speakers.
We are proud to be a disability confident leader. Our recruitment process is fully inclusive and we can make adjustments as needed through our process. These could include having an interview buddy, extra time at interviews/assessments and receiving interview questions in advance, to name a few.
If you require any reasonable adjustments at application stage, or if you'd like to discuss any person-centred adjustments, please contact us by emailing recruitmentCH@companieshouse.gov.uk.
Read our 'Applying under the Disability Confidence Scheme (DCS)' guide to find out how to successfully complete an application under the Disability Confidence Scheme (DCS).
Pre-Employment Checking
In line with Government guidance, successfully appointed candidates will need to provide documents for our Right to Work checks.
From June 2026, applicants who are successful at interview will be, as part of pre-employment screening, subject to a check on the Internal Fraud Database (IFD). Your personal details (name, National Insurance number, and date of birth) will be checked against the Civil Service Resourcing Extract IFD.
This check will provide information about employees who have been dismissed for fraud or dishonesty offences. This check also applies to employees who resign or otherwise leave before being dismissed for fraud or dishonesty had their employment continued.
If your details appear on this database, you will not be offered employment unless you can demonstrate exceptional circumstances. Companies House, acting on behalf of the vacancy holder, will inform you if your application is refused for this reason.
Please note: You are not eligible to apply for a role within the Civil Service if the application is made within a 5 year period following a dismissal for carrying out internal fraud against government.
Feedback will only be provided if you attend an interview or assessment.
Security
Successful candidates must undergo a basic (or equivalent) criminal record check.Successful candidates must meet the security requirements before they can be appointed. The level of security needed is security check (opens in a new window).See our vetting charter (opens in a new window).People working with government assets must complete baseline personnel security standard (opens in new window) checks.
Nationality requirements
This job is broadly open to the following groups:
- UK nationals
- nationals of the Republic of Ireland
- nationals of Commonwealth countries who have the right to work in the UK
- nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities with settled or pre-settled status under the European Union Settlement Scheme (EUSS) (opens in a new window)
- nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities who have made a valid application for settled or pre-settled status under the European Union Settlement Scheme (EUSS)
- individuals with limited leave to remain or indefinite leave to remain who were eligible to apply for EUSS on or before 31 December 2020
- Turkish nationals, and certain family members of Turkish nationals, who have accrued the right to work in the Civil Service
Working for the Civil Service
The Civil Service Code (opens in a new window) sets out the standards of behaviour expected of civil servants.We recruit by merit on the basis of fair and open competition, as outlined in the Civil Service Commission's recruitment principles (opens in a new window).The Civil Service embraces diversity and promotes equal opportunities. As such, we run a Disability Confident Scheme (DCS) for candidates with disabilities who meet the minimum selection criteria.The Civil Service also offers a Redeployment Interview Scheme to civil servants who are at risk of redundancy, and who meet the minimum requirements for the advertised vacancy.
Diversity and Inclusion
The Civil Service is committed to attract, retain and invest in talent wherever it is found. To learn more please see theCivil Service People Plan (opens in a new window) and the Civil Service Diversity and Inclusion Strategy (opens in a new window).Apply and further information
This vacancy is part of the Great PSalary range
- £53,540 - £68,250 per year