> Markdown version of [/jobs/ext/3240842-senior-cyber-analyst-e2](https://www.wearedevelopers.com/jobs/ext/3240842-senior-cyber-analyst-e2). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Cyber Analyst E2 - **Company:** Nationwide - **Location:** Swindon, UK (Remote available) - **Experience:** Expert - **Salary:** £35,087.0 - **Contract:** Temporary contract - **Skills:** Cyber Security, Cybercrime - **Published:** September 5, 2026 - **Apply:** https://www.adzuna.co.uk/jobs/details/5870756153 ## About the Role You will have experience in the following: * CompTIA Cyber Security Analyst+ / Microsoft SC-200 / SANS SEC501 - SANS Advanced Security Essentials - Enterprise Defender or similar Defensive Security/Incident Response qualifications * Proven experience of working within a cyber security operations role, preferably in a complex IT environment * Hands on, practical experience of security monitoring platforms, threat hunting and incident response * Ability to build good working relationships with both technical and business stakeholders, gaining their respect and trust based on your knowledge and professionalism * Display a clear ability to communicate cyber concepts to a range of stakeholders and to articulate the possible risks of an attack and the recommended response * Experience in writing or following security incident response playbooks * The ability to act as a technical escalation point for junior colleagues, coaching and mentoring to enable skillset development Our customer first behaviours put customers and members at the heart of how we work together. They are the set of behaviours that every colleague needs to display, in every role: * Feel what customers feel - We step into our customers' shoes, using their feedback and insights to empathise with them and to understand their needs, so that every decision we make starts and finishes with our customers in mind * Say it straight - We are brave in speaking out and saying what we think - we're honest and direct with good intent, openly sharing diverse perspectives to reach the best conclusions and using language everyone can understand * Push for better - We don't settle for mediocrity, we challenge the status quo, taking responsibility for continuous improvement and personal development * Get it done - We prioritise what will have the greatest impact, we are decisive, and we take accountability for delivering brilliant customer outcomes You can strengthen your application by showing how our customer first behaviours resonate with you, and where you may have already demonstrated these ## Description As part of the GSOC (Group Security Operations Centre), you will be focused on minimising or avoiding impact to our services from cyber-attacks through early detection and, where necessary, urgent response. You'll be responsible for ensuring cyber security alerts are investigated in line with playbooks throughout the cyber incident lifecycle. This includes initial triage, detailing investigative steps to support findings, taking appropriate response actions or escalation as necessary. This role sits within the Detect & Respond sub-team of the Group Security Operations Centre, under the Cyber Security tower in Security & Resilience. We are happy to consider flexible working approaches to help you perform at your best. At Nationwide we offer hybrid working wherever possible. More rewarding relationships are supported through our hybrid approach, bringing colleagues together across our UK wide estate, whilst also supporting generous access to home working. We value our time in the office to solve problems, to learn, and to feel connected. For this role, you'll be based at your nearest regional office or hub. We value time spent together to connect with colleagues for collaboration so there will be a regular requirement to attend our Swindon site approximately once per quarter. If you are based at an office location, you'll be expected to meet our hybrid working requirement of at least two days a week, or 40% of your working time if part-time, in the office. If your application is successful, your hiring manager will provide further details on how this works. Nationwide is committed to the redeployment of our employees impacted by change, as such applications for redeployment candidates will be prioritised in this recruitment process. If you're a colleague on long-term absence (for example, on parental leave) or a temporary worker, please use your personal email address to submit an application. Responsibilities What you'll be doing Part of your role will be to act as a point of experience and escalation for more junior analysts, to guide and drive thinking around appropriate and timely response actions and ensure that, when action is required, it is appropriate and taken sufficiently rapidly. Your role will often require close collaboration with other parts of the business, to help identify, enable, and drive the right response actions, predominantly but not only, with technical teams across the business. The GSOC defends the whole of Nationwide's estate, both Member-facing and support capabilities. You'll help mature our internal processes, developing or defining appropriate detection, response and containment capabilities and contributing to the GSOC Strategy. You will help shape our future technology direction, suggesting and assisting with innovative ways to combat contemporary cyber threats, so we remain fit to find and confront malicious activity. And, inevitably as a regulated business, there will be a need to support assurance activities and assessments, driving actions and providing evidence for audits, compliance reviews and meeting regulatory commitments., The hiring manager for this role is Gary Smith, and the main recruitment contact is Nathan Richens. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Building Security Champions](https://www.wearedevelopers.com/videos/360-building-security-champions) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Jobs in Tech: The State of the European Market](https://www.wearedevelopers.com/magazine/575-jobs-in-tech-the-state-of-the-european-market) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)