About . Registers of Scotland

United Kingdom

Inclusive Features


Job description

Title: Senior Cyber Secrity Analyst
Grade: SEO
Total remneration: £6,91 - £7,987
Pay Spplement:The base salary for this role is £5,43 - £59,156.This job qalifies for Digital, Data and Technology Annal Pay spplement % is inclded in the total remneration above.
Pension: 8.97% (RoS contribtion)
Annal leave: 38 days annal holiday, increasing to 4 days with length of service.
Dration: Permanent.
Working Pattern: 35 hors per week. We are a flexible employer and will consider a variety of working patterns on a case-by-case basis. For example, compressed hors, term-time working or part-time working.
Location: Hybrid working model. Contractal base either at Meadowbank Hose, Edinbrgh (EH8 7A), or St Vincent Plaza, Glasgow (G 5LD).
Department: Cyber Secrity
Directorate: Digital and Data and Technology Directorate
Role Reports to: IT Enablement Manager / Cyber Secrity Technical Prodct Manager
Closing date: 18th of October 6
Nmber of vacancies: 1 (In case that we will have more than 1 sccessfl candidate we will condct a bsiness and bdget review in order to validate a nd hire. Merit order will be followed.)

Registers of Scotland (RoS)Join an award-winning organisation recognised for its technology and innovation. Registers of Scotland is a world-leading pioneer in land and property registration. Or fll-stack teams design, architect, and bild all or registration prodcts in-hose. We work to create digital soltions for the people of Scotland. Yo will get an opportnity to nrtre yor creativity and develop with s throgh access to the latest data, software engineering and prodct delivery techniqes.

This job is for yo if yo want...
  • Work with prpose: working for the people of Scotland to set the bar for land and property registration worldwide.
  • Flexible and hybrid working: depending on the role and team reqirements, work when and where it's best for yo and yor stakeholders.
  • Benefits: enjoy pay progression, pension contribtions of p to 8.97%, p to a year's parental leave, and 38 days annal holiday, increasing to 4 days with length of service.
  • Investment in professional development: we invest in all or people so that they have the right skills to be prodctive and confident in their job.
  • Diversity and Inclsion: We are an 'Investor in People' and a 'Disability Confident' employer. We are inclsive, stronger together, and committed to ptting or people first.
  • Positive work cltre: RoS is an agile, digital organisation sing leading-edge technology.Colleages nderstand their role in achieving or strategy and have the atonomy to deliver.

  • To learn more abot RoS and what we offer visit or careers pages or watch this short video.

    Hear from or colleages abot their experience of working within or Digital, Data and Technology teams on or website.

    Or Tech stack
    Secrity Operations: Cortex XSIAM, Cortex XSOAR, Microsoft Defender, SIEM/XDR platforms, Incident Response, Detection Engineering, Threat Hnting, Threat Intelligence, Digital Forensics, Vlnerability Management and Ticket Management.
    Network & Clod Secrity: Firewalls, Network Threat Prevention, Network Traffic Analysis, Network Access Control (NAC), Clod Secrity Postre Management (CSPM) and Clod Secrity Technologies.
    Atomation & Engineering: SOAR, Playbook Development, Workflow Atomation, Secrity Analytics, KQL, PowerShell, Python and API Integrations.

    The RoleWe are seeking an experienced Senior Cyber Secrity Analyst to join Registers of Scotland (RoS) and help protect the organisation as we contine or digital transformation jorney.

    Working within or Cyber Secrity team, yo will play a key role in detecting, investigating, and responding to cyber threats and secrity incidents. Yo'll collaborate with colleages across secrity, IT operations, and development teams to strengthen or secrity capabilities, improve processes, and deliver effective secrity soltions. As a senior member of the team, yo'll also spport and mentor colleages while helping to shape a strong secrity cltre across the organisation.

    On a typical day yo will...
    Secrity Operations and Incident Response
  • Detect, triage, investigate, and respond to a wide range of cyber secrity events and incidents sing secrity monitoring and analysis tools.
  • Lead and spport incident response activities, ensring secrity incidents are investigated, contained, eradicated, and resolved in line with agreed procedres.
  • Condct detailed analysis of secrity alerts to determine impact, severity, and remediation reqirements.
  • Perform proactive threat hnting activities sing indicators of compromise (IoCs), threat intelligence, and emerging threat information from government, indstry, and trsted partners.
  • Spport the wider Secrity Operations fnction dring major incidents and contribte to post-incident reviews and lessons learned activities.
  • Monitor emerging cyber threats and vlnerabilities, assessing potential impacts on organisational services and systems.
  • Collaborate with infrastrctre, clod, network, and development teams to investigate and resolve complex secrity isses.
  • Contribte to the continos improvement of incident response processes, playbooks, and operational procedres.
  • Participate in ot-of-hors or major incident activities where reqired.

  • Secrity Engineering, Improvement and Atomation
  • Develop, tne, and optimise secrity monitoring soltions to improve detection accracy, redce false positives, and enhance operational effectiveness.
  • Identify opportnities to atomate rotine secrity activities, improving efficiency and response times across Secrity Operations.
  • Design and implement new secrity detections, se cases, and alerting mechanisms to address emerging threats.
  • Evalate existing secrity services, controls, and tooling, recommending improvements based on indstry best practice and organisational needs.
  • Spport the onboarding and integration of new platforms, services, and technologies into secrity monitoring capabilities.
  • Contribte to vlnerability management activities, helping identify, prioritise, and address secrity weaknesses.
  • Develop metrics, dashboards, and reporting to spport operational performance and informed decision making.
  • Work closely with projects and prodct teams to ensre secrity reqirements are considered throghot the delivery lifecycle.
  • Keep abreast of emerging technologies, indstry trends, and evolving cyber threats, applying this knowledge to improve organisational secrity.

  • Leadership, Collaboration and Professional Practice
  • Act as a sbject matter expert, providing advice and gidance on cyber secrity matters to technical and non-technical stakeholders.
  • Respond to secrity-related enqiries from colleages across Digital, Data and Technology and the wider bsiness.
  • Mentor and spport Cyber Secrity Analysts, promoting knowledge sharing, professional development, and continos learning.
  • Create, maintain, and review technical docmentation, inclding standard operating procedres, playbooks, investigation gides, and system configration docmentation.
  • Spport the development and adoption of secrity standards, policies, and operating procedres.
  • Bild effective working relationships with colleages, sppliers, and external partners to strengthen secrity collaboration.
  • Contribte to a cltre of continos improvement, innovation, and operational excellence within the Cyber Secrity team.
  • Commnicate complex technical information clearly and effectively to a range of adiences, ensring secrity risks and recommendations are nderstood and actionable.
  • Spport adit, compliance, and assrance activities by providing evidence, technical inpt, and sbject matter expertise where reqired.

  • Key Responsibilities
    Essential Criteria - Skills and Attribtes for Sccess
    Technical Experience: We will assess yo against the following Technical Experience dring the application and assessment process:
  • Demonstrable experience working in a Cyber Secrity Analyst, Secrity Operations, or Incident Response role, with responsibilities appropriate to a senior-level position.
  • Experience of detecting, triaging, investigating, and responding to cyber secrity events and incidents sing secrity monitoring and analysis tools.
  • Experience of developing, maintaining, and tning secrity detections and alerting capabilities to improve threat detection and redce false positives.
  • Experience of condcting secrity investigations, identifying root cases, and spporting the implementation of remediation and mitigation activities.
  • Experience of sing threat intelligence and indicators of compromise (IoCs) to ndertake threat hnting and spport proactive secrity investigations.
  • Experience of sing IT Service Management (ITSM) tools to manage secrity incidents, operational tasks, and service reqests.
  • Practical experience of working with secrity technologies sch as Secrity Information and Event Management (SIEM), Extended Detection and Response (XDR), Secrity Orchestration, Atomation and Response (SOAR), Next Generation Firewalls (NGFW), Web Application Firewalls (WAF), Network Access Control (NAC), Clod Secrity Postre Management (CSPM), or vlnerability management soltions.
  • Ability to explain the prpose and operation of technical secrity controls and provide expert advice and gidance to technical and non-technical stakeholders.
  • Experience of creating and maintaining technical docmentation, inclding standard operating procedres, playbooks, investigation gides, and technical standards.
  • Strong analytical and problem-solving skills, with the ability to assess risk, prioritise competing demands, and make informed decisions in a fast-paced operational environment.
  • Excellent commnication skills, with the ability to commnicate complex technical concepts clearly and effectively to a range of adiences, inclding senior stakeholders.
  • Experience of mentoring, spporting, or sharing knowledge with colleages to develop capability and promote a cltre of continos learning.
  • Relevant cyber secrity certifications, qalifications, or eqivalent professional experience demonstrating technical expertise and a commitment to contined professional development.

  • Behaviors
    At application stage, yo will be scored against the bolded Behaviors and against all Behaviors for the assessment:

    Working Together
  • Bild effective working relationships with colleages across cyber secrity, IT operations, development teams, and sppliers to spport the delivery of secre and resilient services.
  • Collaborate with technical and non-technical stakeholders dring secrity investigations and incidents, ensring information is shared effectively and appropriate actions are coordinated.
  • Foster a positive and inclsive team environment by sharing knowledge, spporting colleages, and contribting to the sccess of the wider Cyber Secrity team.

  • Developing Self and Others
  • Actively develop technical expertise and maintain awareness of emerging cyber threats, technologies, and indstry best practice to continally improve personal and team capability.
  • Spport the development of colleages throgh mentoring, coaching, and knowledge sharing, helping to bild confidence and capability across the Cyber Secrity team.
  • Encorage a cltre of continos learning by identifying development opportnities and promoting the sharing of lessons learned from incidents, projects, and operational activities.

  • Managing a Qality Service
  • Deliver high-qality secrity operations services by investigating and resolving secrity events and incidents in line with agreed processes, standards, and service expectations.
  • Identify opportnities to improve the effectiveness and efficiency of secrity tools, controls, and processes, implementing enhancements where appropriate.
  • Create and maintain clear, accrate, and p-to-date docmentation, ensring operational procedres and investigation gidance remain effective and accessible.

  • Making Effective Decisions
  • Analyse secrity events, threat intelligence, and operational data to assess risk, prioritise activity, and determine appropriate corses of action.
  • Make informed and evidence-based decisions dring secrity incidents, balancing risk, impact, and operational priorities to spport effective otcomes.
  • Evalate information from mltiple sorces to identify trends, vlnerabilities, and emerging threats, providing clear recommendations to spport decision making and risk management.

  • Stage one - Application ProcessTo apply, click on 'Apply now' and complete the online application form. Yo will need to sbmit:
  • A CV otlining yor career history and how yo meet the Technical Experience criteria (max 4 pages).
  • Yor responses to application qestions within or system and in the given box. These qestions will be related to the Technical Experience and 1 behavior of this role. The word limit is 4 words for each of yor responses.

  • Please note:
  • If we receive a high volme of applications, we may complete an initial sift on Technical Experience
  • We reserve the right to invite candidates to participate in a telephone interview prior to being frther assessed.
  • Applications that are not accompanied by CVs will not be scored or statements over 4 words will not be considered.
  • We strongly advise yo review or policy on responsible se of AI in the application process. RoS may contact yo for a pre-screening call to verify yor responses.
  • Applications and appointments are sbject to a strict merit-based assessment process, in line with the Civil Service Recritment Principles.

  • Stage two - assessmentIf sccessfl at application stage, yo will be invited to an in-person interview which will inclde the following:
  • Behavior based interview, we will assess all the advertised behaviors.
  • Hackerrank discssion, we will isse a Hackerrank task in advance and we will ask yo some qestions regarding that.

  • Behavior based interview qestions will be given to candidates 15 mintes before the start of the interviewto allow candidates to prepare in advance.

    Gidance on Interview Notes
  • Yo are welcome to bring notes with yo to the interview
  • Notes can be either handwritten or typed
  • Notes shold consist of brief prompts, sch as key words or bllet points, to help yo strctre yor responses rather than complete answers
  • The interview is a conversation, and we are interested in hearing abot yor experiences in yor own words

  • Information on Sccess Profiles

    For frther information on sccess profiles, visit orSccess Profiles.

    Feedback
    Feedback will only be provided if yo progress to interview stage.

    Reserve ListIn the event that frther posts are reqired, a reserve list of sccessfl candidates will be kept for p to 1 months.

    Nationality and immigration statsIn general, only nationals from the following contries (and associations of contries) are eligible for employment in the Civil Service: the nited Kingdom, the Repblic of Ireland, and the Commonwealth. E nationals (with settled or pre-settled stats), certain EEA nationals, Swiss and Trkish nationals are also eligible for employment. Detailed provisions on determining eligibility on the gronds of nationality and, where relevant, immigration stats can be reviewed here.

    SecritySccessfl candidates mst ndergo a Level 1 Disclosre check.
    Individals working with government assets mst completebaseline personnel secrity standardchecks.

    Diversity and inclsionAs a prod member of the Disability Confident Scheme, we welcome applications from disabled candidates.We'renot as diverse aswe'dlike yet, andwe'reworking on it. We especially welcome applications from nderrepresented grops - people who are disabled, minoritised ethnic grops, and yonger people (16-4 years of age).To learn more,please seeorEDI strategy.

    As part of the application process,we wold like to invite yo toplease complete or diversity monitoring form. This information is not shared with recritment panelsbt will allow s to frther improve or processes to increase diversity.

    Reasonable adjstmentsWe want everyone to have the chance to perform at their best. If yo need any adjstments (for example, extra time, a hearing loop, materials in large font)inany part of or recritment process, please get in [email protected] will discss adjstments individally with anycandidates who reqest these.

    Find ot more abot reasonable adjstments onthis page.

    DDaT spplementThis post is part of the Digital, Data and Technology profession (DDAT) and attracts a pay spplement. The DDaT allowance is applied to the role and not yo as an individal. Therefore, in ftre, if yo move to a role that does not attract this allowance, the allowance wold be withdrawn. Similarly, if yo move to a different role which attracts a DDaT allowance, the amont of that allowance wold be driven by that role's Job Family alignment to the DDaT Pay Framework.

    The allowance is based on market benchmarking data and will be reviewed biennially. Following sch review, the allowance may be increased, decreased or withdrawn where salary benchmarking data indicates this is appropriate

    Frther informationFor frther information relating to RoS, inclding:
  • Additional details on pay & benefits
  • The Civil Service Code
  • Complaints process
  • se of AI in the application/recritment process,

  • Please view or additional information page online.

    If yo have any qestions, please contact [email protected]
    Industry
    Other
    Job Sector
    Information Technology
    Job Position
    Cyber Security Analyst
    Address
    United Kingdom
    Post date
    Closing date
    Reference Number
    1.1102104802637E+19

    Related Jobs

    Senior Cyber Security Analyst

    Cyber Security Analyst
    Cwmbran NP44 3HR, UK

    posted 1 week ago

    Senior Cyber Security Analyst

    Cyber Security Analyst
    St Jame's Ct, Beckett St, Harehills, Leeds LS9 7TF, UK

    posted 11 hours ago

    . Registers of Scotland false