Cyber Investigations Manager in Glasgow

Cyber Investigations Manager in Glasgow

Glasgow Full-Time 63000 - 77000 £ / year (est.) Home office (partial)
S

At a Glance

  • Tasks: Lead cyber investigations to protect vital Scottish Government information and services.
  • Company: Join the Scottish Government's Cyber Security Unit, a leader in public service protection.
  • Benefits: Enjoy a 35-hour work week, flexible hybrid options, and strong pension benefits.
  • Other info: Dynamic role with opportunities for professional growth and a supportive work environment.
  • Why this job: Make a real impact on public services while tackling exciting cyber challenges.
  • Qualifications: Expertise in cyber security operations and incident management required.

The predicted salary is between 63000 - 77000 £ per year.

Lead cyber investigations that help protect critical Scottish Government information and services. The Cyber Investigation Manager role sits within the Cyber Security Unit (CSU) and is responsible for protecting the confidentiality, integrity and availability of Scottish Government information and information systems. You will join a highly skilled cyber team working across a large and complex technology landscape, helping to strengthen resilience against evolving cyber threats.

This role offers the opportunity to take lead on significant cyber investigation, incident response and security improvement activity that has a direct impact on public services used across Scotland. You will work with a wide range of technical and business stakeholders, shape how incidents are investigated and managed, and help drive improvements to cyber security capability. Alongside interesting technical challenges, Scottish Government offers a 35-hour working week, flexible hybrid working, strong pension benefits and the opportunity to make a meaningful public impact while maintaining a healthy work-life balance.

Please note: This role is based at Saughton House, Edinburgh only, and not Glasgow as may be displayed above.

Responsibilities

  • Champion incident management, incident investigation and response policy and/or incident management and investigation processes, procedures and systems.
  • Produce and facilitate cyber security exercising for customers to ensure a robust and effective incident management and technical response capability.
  • Lead on Data Loss Prevention (DLP) projects to reduce the capability of data leaks of government information through official tools.
  • Deliver specific pieces of work resulting from the Cyber Security Strategy, related to cyber business risk and information control/protection requirements.
  • Contribute to the development of cyber security policy, standards, and guidelines appropriate to business, technology and legal requirements.
  • Maintain current knowledge of malware attacks, and other cyber security threats.
  • Maintain knowledge of specific specialisms, provide detailed advice regarding their application, and execute specialised tasks.
  • Explain the purpose of, and provide advice and guidance on, the application and operation of elementary physical, procedural and technical security controls.

Qualifications

Experience: You are a subject matter expert in developing and operationalising techniques for Cyber Security operations, e.g. detecting anomalous activity, automating orchestration and configuration of IT or have experience in identifying the need for, and implementing, new security operating procedures and practices to meet changing requirements. You have experience of managing incidents, reporting on and bringing investigations to a successful conclusion which allows you to advise on response best practice. You have experience of delivering or reviewing risk assessments using appropriate risk assessment methods for common scenarios such as enterprise IT systems and have a good understanding how assessed risks are addressed. You have advanced knowledge of system architectures in order to articulate the impact of vulnerabilities on existing and future designs and systems.

Behaviours: Making Effective Decisions (Level 3), Communicating and Influencing (Level 3)

Technical Skills: This role is aligned to the Lead Cyber Security Analyst job role within the Cyber Security and Information Assurance job family.

  • Cyber security operations Expert
  • Incident management, incident investigation and response Expert
  • Information risk assessment and risk management Practitioner
  • Penetration testing Practitioner
  • Specific security technology and understanding Practitioner

How to apply: Apply online, providing a CV and Supporting Statement (of no more than 750 words) which provides evidence of how you meet each of the 4 Experience criteria listed in the Success Profile above. Candidates will have their applications assessed against all Experience criteria.

Artificial Intelligence (AI) tools can be used to support your application, but all statements and examples provided must be truthful, factually accurate and taken directly from your own experience. Where plagiarism has been identified (presenting the ideas and experiences of others, or generated by artificial intelligence, and presented as your own) applications will be withdrawn and internal candidates may be subject to disciplinary action.

If invited for further assessment, this will consist of an interview and Government Cyber Profession Technical assessment where the behaviours, experiences and technical skills outlined in the Success Profile will be assessed.

The sift is scheduled for w/c Monday 14th September. Interviews and Technical assessments are scheduled for w/c Monday 5th October, however these may be subject to change.

Security checks

This role requires National Security Vetting (NSV) at Developed Vetting (DV) level. Appointment to the post will be subject to successfully obtaining and maintaining DV clearance. To support the vetting process, candidates will normally need to have lived in the UK for a sufficient period to allow the necessary checks to be carried out. In most cases, this means having been resident in the UK for at least the previous five years.

About us

The Scottish Government is the devolved government for Scotland. We have responsibility for a wide range of key policy areas including: education, health, the economy, justice, housing and transport. We offer rewarding careers and employ people across Scotland in a wide range of professions and roles.

We offer a supportive and inclusive working environment along with a wide range of employee benefits.

Working pattern: Our standard hours are 35 hours per week and we offer a range of flexible working options depending on the needs of the role, including Flexi-leave. Scottish Government staff in hybrid-compatible roles should aim to work in-person 40% of the time, either in an office or other agreed work location.

If you have specific questions about the role you are applying for, please contact Digitalcareers@gov.scot.

Equality Statement

We are committed to equality and inclusion, and we aim to recruit a diverse workforce that reflects the population of our nation.

Further information: Find out more about our organisation, what we offer staff members and how to apply on our Careers Website. Read our Candidate Guide for further information on our recruitment and application processes.

Apply before: 13/09/2026 (23:59). This role is open to internal candidates and Common Citizenship organisations only.

Cyber Investigations Manager in Glasgow employer: Scottish Government

The Scottish Government is an exceptional employer, offering a supportive and inclusive work environment where employees can make a meaningful impact on public services across Scotland. With a focus on employee well-being, the role of Cyber Investigations Manager provides a flexible hybrid working model, a strong pension scheme, and opportunities for professional growth within a highly skilled cyber team dedicated to enhancing national security. Located in Edinburgh, this position not only presents interesting technical challenges but also allows you to contribute directly to the safety and resilience of critical government information systems.

S

Contact Details:

Scottish Government Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Cyber Investigations Manager in Glasgow

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Scottish Government, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through Scottish Government

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Scottish Government. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Cyber Investigations Manager in Glasgow

Cyber Security Operations
Incident Management
Incident Investigation
Incident Response
Data Loss Prevention (DLP)
Risk Assessment
Risk Management

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Scottish Government insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Scottish Government that you’re committed to staying ahead in the game.

How to prepare for a job interview at Scottish Government

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at Scottish Government to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Scottish Government.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.