Location: London / Hybrid β 60% office-based
Contract: Until 31 December 2026
Day Rate: Β£650βΒ£700 per day (Umbrella)
Clearance: Active SC clearance required
The Opportunity
We are seeking an Associate Security Analyst β Cyber Defence to join a high-profile government Cyber and Information Security function.
This is an excellent opportunity for an experienced cyber security professional to support the protection of critical digital services, infrastructure and information assets against cyber threats.
You will join a dedicated Cyber Defence team, supporting security alert triage, incident investigation, threat detection and cyber incident response.
Key Responsibilities
- Triage and investigate cyber security alerts and user-reported security incidents.
- Investigate systems, files, network traffic and cloud environments to identify potential threats.
- Use SIEM and EDR technologies to detect, investigate and respond to cyber threats.
- Support cyber incident response activities, including containment, eradication and recovery.
- Assist with the coordination and management of security incidents.
- Contribute to post-incident reviews, lessons learned and improvement actions.
- Develop and improve incident response processes, playbooks and security documentation.
- Work collaboratively with wider Cyber Defence and security functions.
- Act as an escalation point for apprentice and junior security analysts.
- Coach and mentor junior members of the team.
- Support line management responsibilities for apprentice security analysts.
- Participate in an out-of-hours cyber incident response/on-call rota.
Essential Skills & Experience
- Active SC security clearance.
- At least 2β3 years' experience as a Cyber Security Analyst or in a comparable security operations role.
- Proven experience investigating and responding to cyber security incidents.
- Practical experience with SIEM and EDR technologies.
- Hands-on experience with Splunk.
- Experience with Microsoft 365 security technologies, including:
- Microsoft Defender
- Microsoft Sentinel
- KQL
- Strong understanding of common cyber threat actor tactics, techniques and procedures (TTPs).
- Experience analysing alerts, identifying potential threats and assessing the scope and impact of incidents.
- Strong analytical and problem-solving skills.
- Excellent verbal and written communication skills.
- Experience working within a SOC, Cyber Defence or Security Operations environment.
Desirable Experience
- Advanced hands-on experience with Splunk.
- Experience working in an Agile environment.
- Experience with cloud security, particularly AWS.
- Experience creating or maintaining incident response playbooks and security documentation.
- Experience coaching, mentoring or supporting junior/apprentice security analysts.
- Experience contributing to continual improvement of security operations and incident response capabilities.
The Ideal Candidate
We are looking for an analytical, proactive and technically capable security professional with practical experience in cyber incident investigation and response.
You should be confident working with SIEM and EDR technologies, investigating security alerts, understanding attacker behaviour and communicating technical findings clearly to both technical and non-technical stakeholders.
Government Success Profiles
Candidates will be assessed against relevant experience, career history, achievements, technical/specialist skills and behaviours.
The key behaviours for this role are:
- Making Effective Decisions
- Changing and Improving
- Working Together
Apply Now
If you have active SC clearance, strong Cyber Security Analyst experience and hands-on expertise with Splunk, Microsoft Defender, Sentinel and KQL, we'd like to hear from you.
Apply now for this exciting Cyber Defence contract opportunity.