Principal Cyber Security Analyst @ Scottish Government
5 days ago
The devolved government for Scotland has a range of responsibilities that include: the economy, education, health, justice, rural affairs, housing, environment, equal opportunities, consumer advocacy and advice, transport and taxation.
Are you ready to take the lead in securing cloud environments for a vital public service? Join us as a Principal Cyber Security Analyst within the Digital Risk & Security branch of our Chief Digital Office, where your expertise will guide our commitment to protecting Social Security Scotland. If you are passionate about cloud security and have a keen interest in safeguarding critical information systems, apply now to join our talented team and take the next step in your career.
As the Principal Cyber Security Analyst, you will play a pivotal role in providing technical leadership across our security tooling within our cloud environment. Collaborating closely with cloud engineers and architects, you will oversee the development and implementation of robust cloud security architectures, ensuring compliance with industry best practices across multi-cloud landscapes. This is a key technical leadership position within Digital Risk & Security, focusing on applying proportional security measures to underpin our digital strategy.
Principal Cyber Security Analysts are responsible for protecting the confidentiality, integrity, and availability of information and information systems used by government and Partners Across Government.
At this role level, you will:
- Initiate and influence relationships with and between key stakeholders, in taking forward all aspects of cyber security, acting as a primary point of contact for senior stakeholders and influencers.
- Manage the assessment and response to cyber threats to maintain confidentiality, integrity, availability, accountability and relevant compliance.
- Operate as a focus for cyber security expertise for the organisation and the wider central government community, providing authoritative advice and guidance on the application and operation of all types of cyber security controls.
- Oversee the work of the cyber security function, including project and task definition and prioritisation, quality management and budgetary control, and management tasks such as recruitment and training.
Responsibilities
- Stakeholder Engagement: Initiate and cultivate relationships with key stakeholders, serving as the primary point of contact for all aspects of cyber security, ensuring comprehensive communication and collaboration.
- Security Control Development: Develop and enforce security controls within Infrastructure as Code (IaC) pipelines, such as Terraform and AWS CloudFormation, ensuring secure-by-design deployments. Embed security into CI/CD pipelines, integrating security testing (SAST, DAST, SCA) and automated compliance checks to enhance security without hindering development velocity.
- Cloud Security Monitoring: Lead initiatives to monitor, assess, and enhance our cloud security posture, leveraging automation to detect and remediate misconfigurations. Develop and operationalise cloud-native security monitoring solutions, integrating SIEM, SOAR, and threat intelligence to enhance detection and response capabilities.
- Cyber Security Expertise: Act as a focal point for cyber security expertise, offering authoritative advice and guidance on the application and operation of various cyber security controls across the organisation and the wider central government community.
- Incident Management: Champion policies and processes for incident management, investigation, and response. Proactively manage the assessment and response to cyber threats, ensuring the confidentiality, integrity, and availability of our information systems.
- Strategic Delivery: Deliver specific pieces of work resulting from the Cyber Security Strategy related to cyber business risk. Design and embed cloud security tooling capabilities to enable our digital roadmap.
- Risk Assessment and Management: Deliver comprehensive risk assessments for complex scenarios, integrating insights into the broader risk management process and aligning risk considerations with corporate governance frameworks.
- Policy Development: Develop cyber security policies, standards, and guidelines that reflect business, technological, and legal requirements, adhering to best practices and industry standards.
Essential Experience
- Experience in delivering technical leadership to teams and can develop and operationalise techniques in line with cloud security best practice, e.g. automating orchestration and configuration of cloud security tooling.
- Demonstrated ability to deliver balanced and cost-effective risk management decisions on situations with complex scope or significant risk and ensuring risk is embedded into corporate governance frameworks.
Technical / Professional Skills:
This role is aligned to Cyber Security Analyst Principal within the Digital, Data and Technology Profession. Please review the following to understand the skill expectations: Cyber security: operations - gov.scot.
We will assess you against the following technical skills during the selection process:
- Cyber security operations - Level: Expert
- Specific security technology and understanding - Level: Expert
- Incident management, incident investigation and response - Level: Expert
- Information risk assessment and risk management - Level: Expert
How to Apply
Apply online, providing a CV and Supporting Statement (of no more than 750 words) which provides evidence of how you meet the skills, experience and behaviours listed in the Success Profile above.
We will test your behaviours, technical skills and experience as part of the sift process, and if successful, you will be invited to an assessment and interview where we will test these again. Full details of the selection process will be made available to shortlisted candidates once the sift has been completed.
Information Session
We will be hosting an online Information Session on Thursday 3rd April at 1.30 – 2.30pm.
We will be talking about the Principal Cyber Security Analyst role and DRS Security Operations team.
Equality Statement
Social Security Scotland are committed to equality and inclusion, and we aim to recruit a diverse workforce that reflects the population of our nation.
-
security operations analyst
2 weeks ago
London, Greater London, United Kingdom LT Harper - Cyber Security Recruitment Full timeSecurity Operations Analyst / Engineer Remote (UK Based only) £35k - £45k A driven and growing managed security provider is looking for passionate people to join their team as a Security operations analyst / engineer. This is an excellent opportunity for broad exposure and development opportunities with opportunity to gain certs If you're looking for...
-
London, Greater London, United Kingdom Cyber UK Full timeCyber Operations purpose is to support safe care and build public trust by building NHS England's cyber resilience and enabling the wider health system to be cyber resilient, supporting Transformation Directorate's purpose of delivering the best care and outcomes for the NHS. The Cyber Operations sub-directorate consists of 4 operational areas:Cyber Security...
-
security operations analyst
6 days ago
London, Greater London, United Kingdom LT Harper - Cyber Security Recruitment Full timeInformation Security Recruitment Consultant at LT HarperSecurity Operations Analyst / EngineerRemote (UK Based only)A driven and growing managed security provider is looking for passionate people to join their team as a Security operations analyst / engineer.This is an excellent opportunity for broad exposure and development opportunities with opportunity to...
-
Cyber Security Analyst – Bicester
6 days ago
London, Greater London, United Kingdom Cyber UK Full timeWe have an exciting opportunity to work in an evolving and busy Information Security and Governance team, working closely with our Digital Colleagues. This role plays an important part in supporting front line NHS staff such as Paramedics, 999 and 111 call takers, Patient transport services, as well as to our corporate enablers such as finance, estates and...
-
Principal Security Analyst
2 days ago
London, Greater London, United Kingdom Cyderes Full timePrincipal Security Analyst - SecOps (Chronicle)Cyderes (Cyber Defense and Response) is a pure-play, full life-cycle cybersecurity services provider with award-winning managed security services, identity and access management, and professional services designed to manage the cybersecurity risks of enterprise clients. We specialize in multi-technology, complex...
-
Cyber Incident Response Analyst
3 weeks ago
London, Greater London, United Kingdom Iceberg Cyber Security Full timeJob Description Cyber Security Manager | Financial Services | HybridDo you want to be a driving force in my client's IR, threat-hunting capabilitiesAbout the Role:As a Cyber Security Manager, you will be responsible for monitoring, analyzing, and improving the security posture of the organization. You will drive the maturity of security monitoring, incident...
-
Principal Security Analyst
6 days ago
London, Greater London, United Kingdom Cyderes co Full timeCyderes (Cyber Defense and Response) is a pure-play, full life-cycle cybersecurity services provider with award-winning managed security services, identity and access management, and professional services designed to manage the cybersecurity risks of enterprise clients. We specialize in multi-technology, complex environments with the speed and agility needed...
-
Senior Cyber Security Analyst
6 days ago
London, Greater London, United Kingdom Nhs Scotland Full timeFlexible Location: Based throughout Scotland, NES is a remote friendly employer supporting office and hybrid working. We're happy to talk about how you want to work.Work Pattern: Fixed Term, Full Time, 37 hours per weekFixed-term or Secondment: Until 31 March 2026For NHS applicants, an NHS secondment will be offered in the first instance. For non-NHS...
-
Cyber Security Analyst
3 weeks ago
London, Greater London, United Kingdom TN United Kingdom Full timeCyber Security Analyst - Hedge Fund, LondonClient:Client ServerLocation:London, United KingdomJob Category:OtherEU work permit required:YesJob Reference:b349e6129a94Job Views:97Posted:11.03.2025Expiry Date:25.04.2025Job Description:Cyber Security Analyst (Splunk SOC AWS) London / WFH to £65kAre you a bright, ambitious Cyber Security Analyst with a strong...
-
Cyber Security Analyst
7 days ago
London, Greater London, United Kingdom TN United Kingdom Full timeSocial network you want to login/join with:Cyber Security Analyst - Hedge Fund, LondonClient:Client ServerLocation:London, United KingdomJob Category:OtherEU work permit required:YesJob Reference:b349e6129a94Job Views:102Posted:14.03.2025Expiry Date:28.04.2025Job Description:Cyber Security Analyst (Splunk SOC AWS) London / WFH to £65kAre you a bright,...
-
Cyber Security Analyst
3 weeks ago
London, Greater London, United Kingdom Zone IT Solutions Full timeZone IT Solutions is seeking a talented Cyber Security Analyst to join our team. As a Cyber Security Analyst, you will play a key role in ensuring the security and integrity of our organization's data and systems.Responsibilities:Monitor, detect, and respond to cyber threats and security incidents.Conduct vulnerability assessments and penetration testing to...
-
Principal Cyber Security Consultant
7 days ago
London, Greater London, United Kingdom FSP Consulting Services Limited Full timeRole OverviewWe have an exciting opportunity for a Principal Cyber Security Consultant to join our Governance, Risk and Compliance practice. As a Principal Consultant, you will work with senior client stakeholders to help them develop and deliver effective cyber security strategy and programmes alongside supporting the growth and development of our GRC...
-
Cyber Security Analyst
6 days ago
London, Greater London, United Kingdom Elliot Marsh Ltd. Full timeOur Client is in search of a skilled Cyber Security Analyst to protect our computer systems and networks from information breaches and cyber-attacks. The ideal candidate will have a keen understanding of the latest security principles, techniques, and protocols to ensure the integrity, confidentiality, and availability of data.Key Responsibilities:Monitor...
-
Cyber Security Analyst
2 days ago
London, Greater London, United Kingdom Locke & Mccloud Full timeCyber Security Analyst - Kent/Hybrid - £45,000-£55,000We're pleased to be working with a specialist Cyber Services company that delivers security operations support to a diverse range of clients. They're expanding their SOC team and are in search of a confident Cyber Security Analyst to lead threat investigations, tune detection logic, and contribute to...
-
Cyber Security Analyst
2 days ago
London, Greater London, United Kingdom Locke & Mccloud Full timeCyber Security Analyst - London/Hybrid - £45,000-£55,000We're thrilled to be supporting a mission-driven GreenTech company that's using innovation to drive sustainability across industries. As they continue to grow, they're bolstering their cyber defences and seeking a dedicated Cyber Security Analyst to help manage risks, handle incidents, and protect key...
-
Senior Cyber Security
7 days ago
London, Greater London, United Kingdom UK Power Networks Full time80422 - Senior Cyber Security (GRC) AnalystThis Senior Cyber Security (GRC) Analyst will report to the Cyber Security Governance, Risk & Compliance Manager and will work within the Information Systems directorate based in either our London or Crawley office. You will be a permanent employee.You will attract a salary of up to £75,000.00 and a bonus of 7.5%....
-
Cyber Security analyst
6 days ago
London, Greater London, United Kingdom Vector Resourcing Ltd. Full timeWe are searching for a Cyber Security Analyst who will be responsible for the research, design, development, implementation, documentation, and management of all aspects of Cyber Security. This role involves ensuring the organisation's Cyber Security remains secure from internal and external threats while proactively identifying and mitigating...
-
Cyber Security Analyst
6 days ago
London, Greater London, United Kingdom Halr Tech Group Full timeCybersecurity AnalystLocation: Remote / Hybrid / On-siteJob Type: Full-TimeAbout the RoleAs a Cybersecurity Analyst, you will be responsible for monitoring, detecting, and responding to cyber threats. You will analyze security incidents, conduct risk assessments, and implement security measures to protect sensitive data and infrastructure.Key...
-
Cyber Security Analyst
2 days ago
London, Greater London, United Kingdom Locke and McCloud Full timeJoin a Growing Team as an IT Security AnalystHybrid Working | 2 Days Onsite Weekly | £43,517–£55,517 + Up to 15% Bonus | Flexibility & OwnershipAre you ready to step into a pivotal role where your expertise shapes the future of cyber security? We're on the lookout for a proactive IT Security Analyst to join a dynamic organisation undergoing rapid growth...
-
Cyber Security Project Manager
1 day ago
London, Greater London, United Kingdom Cyber UK Full timeCyber Security Project Manager – Contract / Project Planning / Agile / Stakeholder Management – London/Hybrid – £650pd Outside IR35Our client, a global media organisation, is in the market for a highly skilled and motivated Cyber Security Project Manager to join the business until at least the end of the year.In this role, you will be responsible for...