Associate Security Analyst
This is a long-term engagement until 31/03/2027, based in London on a hybrid model (around 60% on site), and would suit someone who already has strong SOC/incident response experience and is looking to take the next step in a critical national environment.
Why this role stands out
- Length & stability: Contract to March 2027, offering rare long-term security in the contracting market.
- Day rate: Up to £(Apply online only) (umbrella) inside IR35.
- Mission-critical work: Protects key government digital services and internal infrastructure.
- Career development: Mentor and line manage apprentice analysts, strengthening your leadership profile.
The role - Associate Security Analyst
As part of the Cyber Defence team, you will be central to detecting, investigating and responding to cyber threats and incidents affecting high-profile services.
- Triage and investigate security alerts and user reports.
- Analyse systems, files, network traffic and cloud environments to determine the nature and scope of incidents.
- Support and implement containment, eradication and recovery actions.
- Help coordinate incidents and contribute to post-incident reviews and lessons learned.
- Identify and support continuous improvements to incident investigation and response processes.
- Work closely with other Cyber Defence functions and contribute to playbooks, plans and knowledge base articles.
- Act as an escalation point and provide coaching and line management for apprentice security analysts.
- Participate in an out-of-hours on-call rota, as incidents can arise 24/7.
Key requirements
- Active SC (Security Check) clearance - STRONGLY PREFERED.
- 2-3+ years experience as a Cyber Security / Security Analyst.
- Hands-on experience with SIEM (Splunk preferred; Microsoft Sentinel or equivalent also considered).
- Experience with M365 security tooling (e.g. Microsoft Defender, Sentinel, KQL).
- Good understanding of threat actors' tools, techniques and procedures.
- Strong analytical, problem-solving and communication skills.
Nice to have
- Further experience with Splunk.
- Background working in an Agile environment.
- Exposure to cloud platforms such as AWS.
About our client
Our client's cyber and information security function safeguards crucial digital and information assets and enables the secure delivery of major citizen-facing services as well as internal government systems. You would be joining a team with a strong mandate, modern tooling, and a clear mission to improve the cyber resilience of core public services.