> Markdown version of [/jobs/ext/1909351-security-analyst-incident-response-lead](https://www.wearedevelopers.com/jobs/ext/1909351-security-analyst-incident-response-lead). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Analyst (Incident Response Lead) - **Company:** Cabinet Office - **Location:** London, UK - **Experience:** Expert - **Salary:** £57,204.0 - £74,822.0 - **Contract:** Permanent contract - **Skills:** Agile Methodology, Amazon Web Services, Computer Networks, Databases, Intrusion Detection and Prevention, Security Information and Event Management, Cloud Platform System, Cyber Threat Analysis, SC Clearance, Information Technology, Splunk - **Published:** August 4, 2026 - **Apply:** https://uk.indeed.com/viewjob?jk=60bf44bed9ef7332 ## About the Role We’re interested in people who have: * Significant experience investigating and responding to cyber incidents * Significant experience using security tools (e.g., EDR, SIEM) to support the investigation and response to cyber incidents * Experience managing and coordinating the response to cyber incidents * Experience coaching and mentoring junior staff * An in-depth understanding of the tools, techniques and procedures used by threat actors * Excellent analytical and problem-solving skills * Excellent verbal and written communication skills Desirable criteria It’s desirable, but not essential, that you have: * Experience with Splunk * Experience working in an Agile environment * Experience with cloud environments such as AWS, * Incident Management, Incident Investigation and Response * Information Risk Assessment and Risk Management * Intrusion Detection and Analysis * Protective Security * Threat Intelligence and Threat Assessment * Threat Understanding, This vacancy is using Success Profiles , and will assess your Behaviours, Experience and Technical skills. ## Description The Cabinet Office supports the Prime Minister and ensures the effective running of government. It is also the corporate headquarters for government, in partnership with HM Treasury, and takes the lead in certain critical policy areas. The Cyber Defence team delivers cyber threat intelligence, threat detection and incident response capabilities for the Cabinet Office, and is responsible for defending both internal IT infrastructure and citizen-facing services. As an Incident Response Lead, you’ll take a primary role in building and delivering these core capabilities, focusing on managing and responding to incidents., As an Incident Response Lead, you will: * Lead the investigation of security alerts to understand the nature and extent of possible cyber incidents * Lead the forensic analysis of systems, files, network traffic and cloud environments * Lead the technical response to cyber incidents by identifying and implementing (or coordinating the implementation of) containment, eradication and recovery actions * Support the wider coordination of cyber incidents * Review previous incidents to identify lessons and actions * Identify and deliver opportunities for continual improvement of the incident response capability * Work closely alongside other Cyber Defence functions, supporting the continual improvement of wider capabilities * Develop and update internal plans, playbooks and knowledge base articles * Act as an escalation point for, and provide coaching and mentoring to, security analysts * Be responsible for leadership and line management of security analysts, We'll assess you against these behaviours during the selection process: * Managing a Quality Service * Delivering at Pace * Making Effective Decisions * Working Together, If a person with disabilities is put at a substantial disadvantage compared to a non-disabled person, we have a duty to make reasonable changes to our processes., If you are experiencing accessibility problems with any attachments on this advert, please contact the email address in the 'Contact point for applicants' section. A reserve list may be held for a period of 12 months from which further appointments can be made. Any move to Cabinet Office from another employer will mean you can no longer access childcare vouchers. This includes moves between government departments. You may however be eligible for other government schemes, including Tax Free Childcare; for further information visit the Childcare Choices website. If successful and transferring from another Government Department a criminal record check may be carried out. In order to process applications without delay, we will be sending a Criminal Record Check to Disclosure and Barring Service on your behalf. However, we recognise in exceptional circumstances some candidates will want to send their completed forms direct. If you will be doing this, please advise Government Recruitment Service of your intention by emailing Pre-EmploymentChecks.grs@cabinetoffice.gov.uk stating the job reference number in the subject heading. Please note that this role requires SC clearance, which would normally need 5 years of UK residency in the past 5 years. This is not an absolute requirement, but supplementary checks may be needed where individuals have not lived in the UK for that period. This may mean your security clearance (and therefore your appointment) will take longer or, in some cases, not be possible. For further information on National Security Vetting please visit the Demystifying Vetting website. New entrants are expected to join on the minimum of the pay band. Applicants who are successful at interview will be, as part of pre-employment screening, subject to a check on the Internal Fraud Database (IFD). This check will provide information about employees who have been dismissed for fraud or dishonesty offences. This check also applies to employees who resign or otherwise leave before being dismissed for fraud or dishonesty had their employment continued. Any applicant’s details held on the IFD will be refused employment. A candidate is not eligible to apply for a role within the Civil Service if the application is made within a 5 year period following a dismissal for carrying out internal fraud against government. Please note terms and conditions are attached. Please take time to read the document to determine how these may affect you. Feedback Feedback will only be provided if you attend an interview or assessment. Security Successful candidates must undergo a criminal record check. Successful candidates must meet the security requirements before they can be appointed. The level of security needed is security check . See our vetting charter . People working with government assets must complete baseline personnel security standard (opens in new window) checks., * UK nationals * nationals of the Republic of Ireland * nationals of Commonwealth countries who have the right to work in the UK * nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities with settled or pre-settled status under the European Union Settlement Scheme (EUSS) * nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities who have made a valid application for settled or pre-settled status under the European Union Settlement Scheme (EUSS) * individuals with limited leave to remain or indefinite leave to remain who were eligible to apply for EUSS on or before 31 December 2020 * Turkish nationals, and certain family members of Turkish nationals, who have accrued the right to work in the Civil Service ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Kubernetes and Microservices with Multi-Model Databases](https://www.wearedevelopers.com/videos/382-kubernetes-and-microservices-with-multi-model-databases) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Fault Tolerance and Consistency at Scale: Harnessing the Power of Distributed SQL Databases](https://www.wearedevelopers.com/videos/1146-fault-tolerance-and-consistency-at-scale-harnessing-the-power-of-distributed-sql-databases) - [Branch your database like your code: How schema changes and pull requests go hand in hand](https://www.wearedevelopers.com/videos/350-branch-your-database-like-your-code-how-schema-changes-and-pull-requests-go-hand-in-hand) ## Related Articles - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)