Domain Abuse Operational Analyst in Oxford
Domain Abuse Operational Analyst

Domain Abuse Operational Analyst in Oxford

Oxford Full-Time 30000 - 40000 £ / year (est.) No home office possible
Nominet

At a Glance

  • Tasks: Investigate domain abuse reports and support cyber threat operations.
  • Company: Nominet, a leading domain name registry with a positive societal impact.
  • Benefits: Hybrid working, early finish Fridays, 30 days leave, and private medical insurance.
  • Other info: Dynamic team environment with opportunities for personal and professional growth.
  • Why this job: Join a mission to make .UK the safest domain and gain hands-on experience.
  • Qualifications: Knowledge of cyber threats and experience with ticketing systems.

The predicted salary is between 30000 - 40000 £ per year.

Location: Hybrid, with a minimum of 20% in the Oxford office per month

About Us

We’re Nominet – a world‑leading domain name registry operating at the heart of the UK internet. While we're best known for running .UK domains, our DNS expertise also underpins critical internet infrastructure that government services, including the NHS, rely on. As a public benefit company, our work has a positive impact on society. We’ve donated millions to projects that use technology to improve people’s lives and have committed to delivering £60m worth of support over the next three years.

The Role

The Domain Abuse Operational Analyst plays a vital role in Nominet’s mission to make .UK the safest country code top‑level domain (ccTLD) in the world. This role is focused on the day‑to‑day operational management of domain abuse reports, supporting investigations, and helping to ensure timely and effective mitigation of malicious activity. As a key member of the Domain Abuse team, you will be responsible for triaging abuse reports, conducting investigations, and supporting the continuous improvement of detection and response processes. Your work will directly contribute to the health and integrity of the .UK registry and help protect users from online harm. This is an ideal opportunity for someone with a strong interest in cyber threat operations and a desire to build hands‑on experience and develop their skills further.

What You’ll Be Doing

  • Investigating domain abuse reports using internal tools and open‑source intelligence (OSINT), escalating complex cases when needed
  • Supporting operational workflows and identifying ways to improve our tools, processes and automation
  • Assisting in the development and refinement of detection rules and identifying patterns in malicious activity
  • Liaising with registrars and other external stakeholders to help resolve abuse cases
  • Collaborating with internal teams (Security, Policy, Legal etc.) to support a coordinated abuse strategy
  • Maintaining accurate records and contributing to reporting, knowledge sharing and continuous improvement

About You

  • Working knowledge of common cyber threats (phishing, malware distribution, domain hijacking, and fraud)
  • Experience with ticketing and documentation systems to correctly record evidence, actions, and decisions.
  • Curious and analytical mindset with a strong interest in cyber threats and online safety
  • Understanding of using tools like WHOIS/RDAP and open‑source intelligence platforms
  • Strong communicator with the ability to summarise investigations clearly and accurately
  • Comfortable following standard operating procedures and suggesting improvements

Nice to have

  • Awareness of cyber threat intelligence (CTI) and its application in operational environments
  • Initial understanding and appreciation of regulatory considerations affecting domain abuse (for example, GDPR) and legal requirements around online safety
  • Understanding of DNS and domain infrastructure, and experience with relevant tools such as WHOIS/RDAP, passive DNS, among others.
  • Basic scripting or data analysis skills to support investigation or automation
  • Experience working with registrars, ISPs, or within DNS environments

What We Offer

  • Hybrid & Flexible Working
  • Early Finish Friday – Working week of 34 hours with full‑time pay. (Finish at midday on Friday)
  • 30 days of annual leave plus bank holidays, with the ability to purchase an additional 5 days.
  • Private Medical Insurance + Employee Assistance Programme
  • Pension Scheme (Matched to 7%)
  • Annual Bonus Scheme
  • Family Leave (Enhanced)
  • Electric vehicle scheme with on‑site charging points
  • Rewards platform with access to discounts at hundreds of shops, restaurants etc.
  • Flexible Benefits

Diversity Statement

We're passionate about creating a workplace where every individual is valued, respected, and empowered. Somewhere we can benefit from all forms of diversity and discover the true value in our differences. If there are any adjustments we could make to the recruitment and selection process to support you, please let us know.

Security Statement

Nominet is committed to the safeguarding and welfare of the internet and expects all employees and volunteers to share this commitment by participating in the relevant security and screening processes. All roles working for Nominet will be subject to a Baseline Personnel Security Standard (BPSS) check. Some roles due to the nature of their work, will require additional security clearance.

Domain Abuse Operational Analyst in Oxford employer: Nominet

Nominet is an exceptional employer that prioritises the well-being and development of its employees while making a positive impact on society through its work in internet safety. With a hybrid working model, generous benefits including an early finish on Fridays, and a commitment to diversity and employee growth, Nominet fosters a collaborative and innovative work culture that empowers individuals to thrive in their roles. Joining Nominet means being part of a mission-driven team dedicated to protecting users from online harm and contributing to the integrity of the .UK domain.
Nominet

Contact Detail:

Nominet Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Domain Abuse Operational Analyst in Oxford

✨Tip Number 1

Get to know the company inside out! Research Nominet's mission, values, and recent projects. This will not only help you tailor your conversations but also show that you're genuinely interested in being part of their team.

✨Tip Number 2

Network like a pro! Connect with current employees on LinkedIn or attend industry events. A friendly chat can sometimes lead to insider tips or even a referral, which can give you a leg up in the hiring process.

✨Tip Number 3

Prepare for the interview by practising common questions related to cyber threats and domain abuse. Think about how your skills align with the role and be ready to share examples of your analytical mindset in action.

✨Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re serious about joining Nominet and contributing to making .UK the safest ccTLD.

We think you need these skills to ace Domain Abuse Operational Analyst in Oxford

Investigative Skills
Knowledge of Cyber Threats
Open-Source Intelligence (OSINT)
Analytical Mindset
Communication Skills
Ticketing and Documentation Systems
Standard Operating Procedures
Cyber Threat Intelligence (CTI)
Regulatory Awareness (GDPR)
Understanding of DNS and Domain Infrastructure
WHOIS/RDAP Tools
Basic Scripting Skills
Data Analysis Skills
Collaboration Skills

Some tips for your application 🫡

Tailor Your Application: Make sure to customise your CV and cover letter for the Domain Abuse Operational Analyst role. Highlight your experience with cyber threats and any relevant tools you've used, like WHOIS or OSINT. We want to see how your skills align with our mission!

Show Your Curiosity: We love candidates who are curious and analytical! In your application, share examples of how you've investigated issues or improved processes in the past. This will show us your passion for online safety and cyber threat operations.

Be Clear and Concise: When summarising your experiences, keep it clear and to the point. Use bullet points where possible to make it easy for us to read. Remember, we’re looking for strong communicators who can present their findings effectively!

Apply Through Our Website: Don’t forget to submit your application through our website! It’s the best way for us to receive your details and ensures you’re considered for the role. Plus, it shows you’re keen on joining our team at Nominet!

How to prepare for a job interview at Nominet

✨Know Your Cyber Threats

Make sure you brush up on common cyber threats like phishing, malware distribution, and domain hijacking. Being able to discuss these topics confidently will show your genuine interest in the role and help you stand out.

✨Familiarise Yourself with Tools

Get comfortable with tools like WHOIS/RDAP and open-source intelligence platforms. If you can demonstrate your understanding of these tools during the interview, it’ll show that you’re ready to hit the ground running.

✨Prepare for Scenario Questions

Think about how you would handle specific domain abuse scenarios. Prepare examples from your past experiences where you’ve successfully triaged reports or improved processes. This will highlight your analytical mindset and problem-solving skills.

✨Communicate Clearly

Practice summarising complex information clearly and accurately. The ability to communicate findings effectively is crucial in this role, so be ready to showcase your communication skills during the interview.

Domain Abuse Operational Analyst in Oxford
Nominet
Location: Oxford

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

>