At a Glance
- Tasks: Lead the defence against complex cyber threats and respond to high-severity incidents.
- Company: Join the Met Office, a certified Great Place to Work with a focus on environmental impact.
- Benefits: Enjoy a competitive salary, generous annual leave, and a fantastic pension scheme.
- Why this job: Make a real difference while working with cutting-edge technology in a supportive environment.
- Qualifications: Degree in Cyber Security or IT, with extensive incident response experience.
- Other info: Flexible hybrid working options and excellent career development opportunities.
The predicted salary is between 55000 - 66000 £ per year.
We’re looking for an exceptional Security Operations Centre Incident Responder / Senior Analyst – Level 3 to help us make a difference to our planet. The job may be suitable for hybrid working, which is where an employee works part of the week in the office and part of the week from home. This is a voluntary, non-contractual arrangement and the location advertised will be your contractual place of work. Our opportunity is full time, 37 hours per week. Our people are at the heart of what we do, and we’ll do our best to agree a working pattern that works for everyone.
World changing work: From science to technology, from meteorology to management, and from planning to communication, our expertise helps us stand out as the authority on weather accuracy and climate prediction. We help individuals, industries and government to make better decisions to stay safe and thrive.
Your world of expertise: As our Security Operations Centre Incident Responder / Senior Analyst – Level 3 you won’t just respond to alerts, you’ll lead the defence of the organisation at the highest technical level. You will be the final escalation point for complex cyber threats, trusted to investigate sophisticated attacks, uncover hidden adversary behaviour, and drive rapid, effective response. From identity-based attacks and advanced persistent threats to insider risks, you’ll be working on the incidents that truly matter.
- Act as the final escalation point for complex, high-severity, and major security incidents.
- Lead end-to-end incident response activities including triage, containment, eradication, and recovery.
- Perform advanced threat analysis, including malware analysis and attacker techniques.
- Conduct digital forensics across endpoints, networks, and cloud environments.
- Lead threat hunting activities using intelligence, hypotheses, and behavioural analytics.
We operate an on‑call roster in Technology to provide 24/7/365 support to respond to operational service requirements. This post may be part of an on‑call roster and the postholder would be required to participate in an on‑call roster where in operation.
Essential Criteria, skills and experience:
- An extensive knowledge of Cyber Security Incident response principles and practices within a Security Operations Centre environment.
- Degree in Cyber Security, Information Technology, or equivalent experience.
- Ideally with advanced industry certifications such as: GIAC Certified Incident Handler (GCIH) & or GIAC Certified Forensic Analyst (GCFA).
- Strong understanding of network security, including packet analysis and intrusion detection including NDR tooling, and advanced knowledge of SIEM platforms (e.g., Microsoft Sentinel) along with deep expertise with EDR technologies (e.g., Microsoft Defender for Endpoint).
- Deep knowledge of operating systems (Windows, Linux) and system internals along with cloud security (Azure, AWS,) and hybrid environments.
- Experience with digital forensics and incident response (DFIR) tools and methodologies, and experience with scripting and automation (PowerShell, Python).
- Provide technical leadership and mentoring to Level 1 and Level 2 analysts.
How to apply: If you share our values, we’d love to hear from you! Click apply to begin your application. Please complete your career history and provide evidence against each of the essential criteria in the supporting statement questionnaire. We recommend candidates use the CARL method (Context, Action, Result and Learning) for presenting evidence of experience and skills. Closing date 15/03/2026 at 23:59 with first stage interviews commencing from 23/03/2026.
We understand that great minds don’t always think alike and as an equal opportunities employer we welcome applications from those with all protected characteristics. We recruit on merit, fairness, and open competition in line with the Civil Service Code.
We require Security clearance, for which you need to have resided in the UK for at least 3 of the last 5 years to be eligible, 2 of these years must be immediately preceding the point of your application. You will need to achieve full security clearance within your first 6 months with us.
Security Operations Centre Incident Responder / Senior Analyst – Level 3 in Exeter employer: Met Office
Contact Detail:
Met Office Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Security Operations Centre Incident Responder / Senior Analyst – Level 3 in Exeter
✨Tip Number 1
Network like a pro! Reach out to folks in the industry, attend meetups, and connect on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Tip Number 2
Prepare for interviews by practising common questions and scenarios related to incident response. Use the STAR method (Situation, Task, Action, Result) to structure your answers and showcase your skills effectively.
✨Tip Number 3
Showcase your expertise! Bring examples of your past work, especially those that highlight your experience with complex cyber threats and incident response. This will help you stand out as a candidate who can lead the defence.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen. Plus, we love seeing candidates who are genuinely interested in joining our mission at the Met Office.
We think you need these skills to ace Security Operations Centre Incident Responder / Senior Analyst – Level 3 in Exeter
Some tips for your application 🫡
Show Your Expertise: When you're writing your application, make sure to highlight your extensive knowledge of Cyber Security Incident response principles. Use specific examples from your experience that demonstrate your skills in handling complex incidents.
Use the CARL Method: We recommend using the CARL method (Context, Action, Result, Learning) to structure your supporting statement. This helps us see not just what you did, but how you approached challenges and what you learned from them.
Tailor Your Application: Make sure your application reflects the job description closely. Highlight your experience with SIEM platforms, EDR technologies, and digital forensics. We want to see how your background aligns with our needs!
Apply Through Our Website: Don’t forget to apply through our website! It’s the best way to ensure your application gets to us directly. Plus, it makes the whole process smoother for everyone involved.
How to prepare for a job interview at Met Office
✨Know Your Stuff
Make sure you brush up on your knowledge of Cyber Security Incident response principles and practices. Be ready to discuss your experience with advanced threat analysis, malware analysis, and digital forensics. The more specific examples you can provide, the better!
✨Showcase Your Leadership Skills
As a Senior Analyst, you'll be expected to lead incident response activities. Prepare to share instances where you've acted as a technical lead during major incidents. Highlight how you liaised with senior stakeholders and maintained confidentiality.
✨Familiarise Yourself with Tools
Get comfortable with the tools mentioned in the job description, like SIEM platforms and EDR technologies. If you have experience with Microsoft Sentinel or Defender for Endpoint, be ready to discuss how you've used these tools in past roles.
✨Practice the CARL Method
When discussing your experiences, use the CARL method (Context, Action, Result, Learning) to structure your answers. This will help you clearly convey your skills and how they align with the role, making it easier for the interviewers to see your fit for the position.