Senior Cyber Security Analyst
- Salary
- £60.3K–£71KGBP
- Hiring from
- United Kingdom
- Work type
- Hybrid
- Posted
- Oct 2, 2026
Title: Senior Cyber Security Analyst
Grade: SEO
Total remuneration: £60,291 – £70,987
Pay Supplement: The base salary for this role is £50,243 – £59,156. This job qualifies for Digital, Data and Technology Annual Pay supplement 20% is included in the total remuneration above.
Pension: 28.97% (RoS contribution)
Annual leave: 38 days annual holiday, increasing to 42 days with length of service.
Duration: Permanent.
Working Pattern: 35 hours per week. We are a flexible employer and will consider a variety of working patterns on a case-by-case basis. For example, compressed hours, term-time working or part-time working.
Location: Hybrid working model. Contractual base either at Meadowbank House, Edinburgh (EH8 7AU), or St Vincent Plaza, Glasgow (G2 5LD).
Department: Cyber Security
Directorate: Digital and Data and Technology Directorate
Role Reports to: IT Enablement Manager / Cyber Security Technical Product Manager
Closing date: 18th of October 2026
Number of vacancies: 1 (In case that we will have more than 1 successful candidate we will conduct a business and budget review in order to validate a 2nd hire. Merit order will be followed.)
Registers of Scotland (RoS)
Join an award-winning organisation recognised for its technology and innovation. Registers of Scotland is a world-leading pioneer in land and property registration. Our full-stack teams design, architect, and build all our registration products in-house. We work to create digital solutions for the people of Scotland. You will get an opportunity to nurture your creativity and develop with us through access to the latest data, software engineering and product delivery techniques.
This job is for you if you want…
- Work with purpose: working for the people of Scotland to set the bar for land and property registration worldwide.
- Flexible and hybrid working: depending on the role and team requirements, work when and where it’s best for you and your stakeholders.
- Benefits: enjoy pay progression, pension contributions of up to 28.97%, up to a year’s parental leave, and 38 days annual holiday, increasing to 42 days with length of service.
- Investment in professional development: we invest in all our people so that they have the right skills to be productive and confident in their job.
- Diversity and Inclusion: We are an ‘Investor in People’ and a ‘Disability Confident’ employer. We are inclusive, stronger together, and committed to putting our people first.
- Positive work culture: RoS is an agile, digital organisation using leading-edge technology. Colleagues understand their role in achieving our strategy and have the autonomy to deliver.
To learn more about RoS and what we offer visit our careers pages or watch this short video.
Hear from our colleagues about their experience of working within our Digital, Data and Technology teams on our website.
Our Tech stack
Security Operations: Cortex XSIAM, Cortex XSOAR, Microsoft Defender, SIEM/XDR platforms, Incident Response, Detection Engineering, Threat Hunting, Threat Intelligence, Digital Forensics, Vulnerability Management and Ticket Management.
Network & Cloud Security: Firewalls, Network Threat Prevention, Network Traffic Analysis, Network Access Control (NAC), Cloud Security Posture Management (CSPM) and Cloud Security Technologies.
Automation & Engineering: SOAR, Playbook Development, Workflow Automation, Security Analytics, KQL, PowerShell, Python and API Integrations.
The Role
We are seeking an experienced Senior Cyber Security Analyst to join Registers of Scotland (RoS) and help protect the organisation as we continue our digital transformation journey.
Working within our Cyber Security team, you will play a key role in detecting, investigating, and responding to cyber threats and security incidents. You'll collaborate with colleagues across security, IT operations, and development teams to strengthen our security capabilities, improve processes, and deliver effective security solutions. As a senior member of the team, you'll also support and mentor colleagues while helping to shape a strong security culture across the organisation.
On a typical day you will…
Security Operations and Incident Response
- Detect, triage, investigate, and respond to a wide range of cyber security events and incidents using security monitoring and analysis tools.
- Lead and support incident response activities, ensuring security incidents are investigated, contained, eradicated, and resolved in line with agreed procedures.
- Conduct detailed analysis of security alerts to determine impact, severity, and remediation requirements.
- Perform proactive threat hunting activities using indicators of compromise (IoCs), threat intelligence, and emerging threat information from government, industry, and trusted partners.
- Support the wider Security Operations function during major incidents and contribute to post-incident reviews and lessons learned activities.
- Monitor emerging cyber threats and vulnerabilities, assessing potential impacts on organisational services and systems.
- Collaborate with infrastructure, cloud, network, and development teams to investigate and resolve complex security issues.
- Contribute to the continuous improvement of incident response processes, playbooks, and operational procedures.
- Participate in out-of-hours or major incident activities where required.
Security Engineering, Improvement and Automation
- Develop, tune, and optimise security monitoring solutions to improve detection accuracy, reduce false positives, and enhance operational effectiveness.
- Identify opportunities to automate routine security activities, improving efficiency and response times across Security Operations.
- Design and implement new security detections, use cases, and alerting mechanisms to address emerging threats.
- Evaluate existing security services, controls, and tooling, recommending improvements based on industry best practice and organisational needs.
- Support the onboarding and integration of new platforms, services, and technologies into security monitoring capabilities.
- Contribute to vulnerability management activities, helping identify, prioritise, and address security weaknesses.
- Develop metrics, dashboards, and reporting to support operational performance and informed decision making.
- Work closely with projects and product teams to ensure security requirements are considered throughout the delivery lifecycle.
- Keep abreast of emerging technologies, industry trends, and evolving cyber threats, applying this knowledge to improve organisational security.
Leadership, Collaboration and Professional Practice
- Act as a subject matter expert, providing advice and guidance on cyber security matters to technical and non-technical stakeholders.
- Respond to security-related enquiries from colleagues across Digital, Data and Technology and the wider business.
- Mentor and support Cyber Security Analysts, promoting knowledge sharing, professional development, and continuous learning.
- Create, maintain, and review technical documentation, including standard operating procedures, playbooks, investigation guides, and system configuration documentation.
- Support the development and adoption of security standards, policies, and operating procedures.
- Build effective working relationships with colleagues, suppliers, and external partners to strengthen security collaboration.
- Contribute to a culture of continuous improvement, innovation, and operational excellence within the Cyber Security team.
- Communicate complex technical information clearly and effectively to a range of audiences, ensuring security risks and recommendations are understood and actionable.
- Support audit, compliance, and assurance activities by providing evidence, technical input, and subject matter expertise where required.
Key Responsibilities
Essential Criteria – Skills and Attributes for Success
Technical Experience: We will assess you against the following Technical Experience during the application and assessment process:
- Demonstrable experience working in a Cyber Security Analyst, Security Operations, or Incident Response role, with responsibilities appropriate to a senior-level position.
- Experience of detecting, triaging, investigating, and responding to cyber security events and incidents using security monitoring and analysis tools.
- Experience of developing, maintaining, and tuning security detections and alerting capabilities to improve threat detection and reduce false positives.
- Experience of conducting security investigations, identifying root causes, and supporting the implementation of remediation and mitigation activities.
- Experience of using threat intelligence and indicators of compromise (IoCs) to undertake threat hunting and support proactive security investigations.
- Experience of using IT Service Management (ITSM) tools to manage security incidents, operational tasks, and service requests.
- Practical experience of working with security technologies such as Security Information and Event Management (SIEM), Extended Detection and Response (XDR), Security Orchestration, Automation and Response (SOAR), Next Generation Firewalls (NGFW), Web Application Firewalls (WAF), Network Access Control (NAC), Cloud Security Posture Management (CSPM), or vulnerability management solutions.
- Ability to explain the purpose and operation of technical security controls and provide expert advice and guidance to technical and non-technical stakeholders.
- Experience of creating and maintaining technical documentation, including standard operating procedures, playbooks, investigation guides, and technical standards.
- Strong analytical and problem-solving skills, with the ability to assess risk, prioritise competing demands, and make informed decisions in a fast-paced operational environment.
- Excellent communication skills, with the ability to communicate complex technical concepts clearly and effectively to a range of audiences, including senior stakeholders.
- Experience of mentoring, supporting, or sharing knowledge with colleagues to develop capability and promote a culture of continuous learning.
- Relevant cyber security certifications, qualifications, or equivalent professional experience demonstrating technical expertise and a commitment to continued professional development.
Behaviours
At application stage, you will be scored against the bolded Behaviours and against all Behaviours for the assessment:
Working Together
- Build effective working relationships with colleagues across cyber security, IT operations, development teams, and suppliers to support the delivery of secure and resilient services.
- Collaborate with technical and non-technical stakeholders during security investigations and incidents, ensuring information is shared effectively and appropriate actions are coordinated.
- Foster a positive and inclusive team environment by sharing knowledge, supporting colleagues, and contributing to the success of the wider Cyber Security team.
Developing Self and Others
- Actively develop technical expertise and maintain awareness of emerging cyber threats, technologies, and industry best practice to continually improve personal and team capability.
- Support the development of colleagues through mentoring, coaching, and knowledge sharing, helping to build confidence and capability across the Cyber Security team.
- Encourage a culture of continuous learning by identifying development opportunities and promoting the sharing of lessons learned from incidents, projects, and operational activities.
Managing a Quality Service
- Deliver high-quality security operations services by investigating and resolving security events and incidents in line with agreed processes, standards, and service expectations.
- Identify opportunities to improve the effectiveness and efficiency of security tools, controls, and processes, implementing enhancements where appropriate.
- Create and maintain clear, accurate, and up-to-date documentation, ensuring operational procedures and investigation guidance remain effective and accessible.
Making Effective Decisions
- Analyse security events, threat intelligence, and operational data to assess risk, prioritise activity, and determine appropriate courses of action.
- Make informed and evidence-based decisions during security incidents, balancing risk, impact, and operational priorities to support effective outcomes.
- Evaluate information from multiple sources to identify trends, vulnerabilities, and emerging threats, providing clear recommendations to support decision making and risk management.
Stage one - Application Process
To apply, click on 'Apply now' and complete the online application form. You will need to submit:
- A CV outlining your career history and how you meet the Technical Experience criteria (max 4 pages).
- Your responses to application questions within our system and in the given box. These questions will be related to the Technical Experience and 1 behaviour of this role. The word limit is 400 words for each of your responses.
Please note:
- If we receive a high volume of applications, we may complete an initial sift on Technical Experience
- We reserve the right to invite candidates to participate in a telephone interview prior to being further assessed.
- Applications that are not accompanied by CVs will not be scored or statements over 400 words will not be considered.
- We strongly advise you review our policy on responsible use of AI in the application process. RoS may contact you for a pre-screening call to verify your responses.
- Applications and appointments are subject to a strict merit-based assessment process, in line with the Civil Service Recruitment Principles.
Stage two – assessment
If successful at application stage, you will be invited to an in-person interview which will include the following:
- Behaviour based interview, we will assess all the advertised behaviours.
- Hackerrank discussion, we will issue a Hackerrank task in advance and we will ask you some questions regarding that.
Behaviour based interview questions will be given to candidates 15 minutes before the start of the interview to allow candidates to prepare in advance.
Guidance on Interview Notes
- You are welcome to bring notes with you to the interview
- Notes can be either handwritten or typed
- Notes should consist of brief prompts, such as key words or bullet points, to help you structure your responses rather than complete answers
- The interview is a conversation, and we are interested in hearing about your experiences in your own words
Information on Success Profiles
For further information on success profiles, visit our Success Profiles.
Feedback
Feedback will only be provided if you progress to interview stage.
Reserve List
In the event that further posts are required, a reserve list of successful candidates will be kept for up to 12 months.
Nationality and immigration status
In general, only nationals from the following countries (and associations of countries) are eligible for employment in the Civil Service: the United Kingdom, the Republic of Ireland, and the Commonwealth. EU nationals (with settled or pre-settled status), certain EEA nationals, Swiss and Turkish nationals are also eligible for employment. Detailed provisions on determining eligibility on the grounds of nationality and, where relevant, immigration status can be reviewed here.
Security
Successful candidates must undergo a Level 1 Disclosure check.
Individuals working with government assets must complete baseline personnel security standard checks.
Diversity and inclusion
As a proud member of the Disability Confident Scheme, we welcome applications from disabled candidates. We’re not as diverse as we’d like yet, and we’re working on it. We especially welcome applications from underrepresented groups – people who are disabled, minoritised ethnic groups, and younger people (16-24 years of age). To learn more, please see our EDI strategy.
As part of the application process, we would like to invite you to please complete our diversity monitoring form. This information is not shared with recruitment panels but will allow us to further improve our processes to increase diversity.
Reasonable adjustments
We want everyone to have the chance to perform at their best. If you need any adjustments (for example, extra time, a hearing loop, materials in large font) in any part of our recruitment process, please get in touch via talent@ros.gov.uk. We will discuss adjustments individually with any candidates who request these.
Find out more about reasonable adjustments on this page .
DDaT supplement
This post is part of the Digital, Data and Technology profession (DDAT) and attracts a pay supplement. The DDaT allowance is applied to the role and not you as an individual. Therefore, in future, if you move to a role that does not attract this allowance, the allowance would be withdrawn. Similarly, if you move to a different role which attracts a DDaT allowance, the amount of that allowance would be driven by that role's Job Family alignment to the DDaT Pay Framework.
The allowance is based on market benchmarking data and will be reviewed biennially. Following such review, the allowance may be increased, decreased or withdrawn where salary benchmarking data indicates this is appropriate
Further information
For further information relating to RoS, including:
- Additional details on pay & benefits
- The Civil Service Code
- Complaints process
- Use of AI in the application/recruitment process,
Please view our additional information page online.
If you have any questions, please contact talent@ros.gov.uk