> Markdown version of [/jobs/ext/25679-lead-cyber-security-analyst](https://www.wearedevelopers.com/jobs/ext/25679-lead-cyber-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead Cyber Security Analyst - **Company:** Government Commercial Agency - **Location:** Birmingham, UK (Remote available) - **Experience:** Expert - **Salary:** £59,877.0 - £66,869.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Microsoft Azure, Network Analysis, Software as a Service, Cloud Computing, Cyber Security, Monitoring of Systems, Intrusion Detection and Prevention, Security Information and Event Management, Working Model 2D, Cloudwatch, Vulnerability Analysis - **Published:** May 16, 2026 - **Apply:** https://uk.indeed.com/viewjob?jk=b0388bc240ff27af ## About the Role Do you have experience in SaaS?, * A track record in cyber security leadership, strategy development and planning in large and complex organisations, with demonstrable technical security knowledge of modern security concepts, principles and technologies for Azure, AWS, and SaaS. * Experience using SIEM and Cloud provider monitoring tools such as AWS CloudWatch, CloudTrail and GuardDuty, Azure Defender for Cloud and Azure Sentinel for threat monitoring, alerting and response * Expert knowledge of typical threats and attack vectors with appropriate monitoring and remediation strategies. * experience using a variety of sources of information to identify, analyse and report on relevant threats and vulnerabilities. * Developed problem solving skills including addressing complex technical security and process challenges that ensure delivery at pace to an appropriate risk appetite. * Excellent communication and interpersonal skills, with the ability to effectively communicate complex security concepts to non-technical stakeholders, influence stakeholders and create easy to consume articles such as blogs, policies and presentations., * Delivering at Pace * Leadership * Making Effective Decisions * Changing and Improving Technical skills We'll assess you against these technical skills during the selection process: * understanding of security event analysis and remediation specific to AWS or Azure Cloud environments and workloads., Successful candidates must undergo a criminal record check. Successful candidates must meet the security requirements before they can be appointed. The level of security needed is security check . ## Description This role is being recruiting via Public Sector Resourcing, please ensure you contact them with any questions. Would you like to be a part of a digital transformation journey and be part of a growing team that is constantly evolving? Do you want to be involved in work that has a meaningful purpose? If yes, then this could be the role for you!, As the head of our new SecOps team, you will report to the Head of Service and Infrastructure within Digital Services. You’ll lead threat detection, response, and IT Health Checks while establishing security standards, policies, and automated monitoring processes. Working alongside product teams, you will leverage advanced SIEM and network analysis tools to mitigate vulnerabilities. You are responsible for resolving active issues and collaborating with Operations and Development to prevent future risks. This leadership role requires proactive communication with executives, ensuring our infrastructure remains resilient through continuous improvement of our security capabilities and response strategies., * lead monitoring, triaging, and investigation of security alerts on Azure and AWS platforms to identify security incidents * lead the SecOps team in the design, development and enablement of automated monitoring processes, advising on the latest SIEM (Security Information and Event Management) and network analysis tools, techniques and procedures to detect malicious activity, while communicating directly with leadership on the progress and status of monitoring * coordinate the triage and remediation of identified threats using a risk-based approach, working closely with service teams and developers to ensure that appropriate mitigation measures are implemented * produce regular reporting which delivers insights on security monitoring activities and the impact on cyber security risk * develop and update internal plans, processes, and knowledge base articles, and define requirements for improving and expanding our security tooling * support wider Cyber Defence activities, working closely with other teams within the Directorate and Information Security to proactively reduce cyber security threats and vulnerabilities, GCA operates a smarter working model that balances flexibility with collaboration. Successful candidates are expected to spend at least 26 days per quarter (approximately 2 days per week, pro-rata) at their contracted office, another GCA site, or off-site for meetings. For the remainder of the time, you may work from home or another suitable location that meets business needs., * UK nationals * nationals of the Republic of Ireland * nationals of Commonwealth countries who have the right to work in the UK * nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities with settled or pre-settled status under the European Union Settlement Scheme (EUSS) * nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities who have made a valid application for settled or pre-settled status under the European Union Settlement Scheme (EUSS) * individuals with limited leave to remain or indefinite leave to remain who were eligible to apply for EUSS on or before 31 December 2020 * Turkish nationals, and certain family members of Turkish nationals, who have accrued the right to work in the Civil Service ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Developer Tools for Microsoft Azure](https://www.wearedevelopers.com/videos/450-developer-tools-for-microsoft-azure) - [From Black Box to Glass Box : Bedrock AgentCore Observability](https://www.wearedevelopers.com/videos/2126-from-black-box-to-glass-box-bedrock-agentcore-observability) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [30 powerful AWS hacks in just 30 minutes: Boost your developer productivity](https://www.wearedevelopers.com/videos/1624-30-powerful-aws-hacks-in-just-30-minutes-boost-your-developer-productivity) - [Develop enterprise-ready applications for Microsoft Teams with Azure resources on modern web technologies](https://www.wearedevelopers.com/videos/187-develop-enterprise-ready-applications-for-microsoft-teams-with-azure-resources-on-modern-web-technologies) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Software Engineer Salary London](https://www.wearedevelopers.com/magazine/252-software-engineer-salary-london)