Security Analyst; Incident Response Lead
Listed on 2026-02-23
-
IT/Tech
Cybersecurity
Overview
Employer: Government Recruitment Service
Location: Bristol
Pay: £57,204 to £74,822 per year, National: £57,204 - £66,122 London: £62,988 - £74,822. Offers above the band minimum are subject to our assessment of your skills and experience as demonstrated aries over the band minimum will be paid as a non-pensionable allowance.
Contract Type: Permanent
Hours: Full time
Disability Confident: Yes
Closing Date: 07/03/2026
About this jobThe Cabinet Office supports the Prime Minister and ensures the effective running of government. It is also the corporate headquarters for government, in partnership with HM Treasury, and takes the lead in certain critical policy areas.
The Cyber Defence team delivers cyber threat intelligence, threat detection and incident response capabilities for the Cabinet Office, and is responsible for defending both internal IT infrastructure and citizen-facing services.
As an Incident Response Lead, you’ll take a primary role in building and delivering these core capabilities, focusing on managing and responding to incidents.
Security vetting: This role requires SC (Security Check) which will be conducted by the NSV (National Security vetting). You need to have been resident in the UK within the past five years in order to apply.
A short video explaining the necessity:
Video explanation available on request.
- Lead the investigation of security alerts to understand the nature and extent of possible cyber incidents
- Lead the forensic analysis of systems, files, network traffic and cloud environments
- Lead the technical response to cyber incidents by identifying and implementing containment, eradication and recovery actions (or coordinating the implementation)
- Support the wider coordination of cyber incidents
- Review previous incidents to identify lessons and actions
- Identify and deliver opportunities for continual improvement of the incident response capability
- Work closely alongside other Cyber Defence functions, supporting the continual improvement of wider capabilities
- Develop and update internal plans, playbooks and knowledge base articles
- Act as an escalation point for, and provide coaching and mentoring to, security analysts
- Be responsible for leadership and line management of security analysts
- Note:
Cyber incidents can and do arise on a 24/7 basis - The team operates an out-of-hours on call rota, which you will be expected to join
Proud member of the Disability Confident employer scheme
Jobs are provided by the Find a Job Service from the Department for Work and Pensions (DWP).
#J-18808-Ljbffr(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).