Lead Cyber Security Analyst

Ofgem

Cardiff, Glasgow, Greater London

Hybrid

GBP 90,000 - 120,000

Full time

40 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Ofgem is seeking a Lead Cyber Security Analyst to drive monitoring, threat detection and incident response across its digital and security services. You will lead analytics, coordinate across security operations, threat intel and vulnerability management, and guide improvements in detection and response capabilities.

You will communicate risk and mitigation strategies to stakeholders, support resilience exercises, and contribute to continuous capability development in a fast-moving government

Qualifications

  • Experience in Security Operations and incident detection across complex environments.
  • Expertise in intrusion detection, threat intelligence and vulnerability management.
  • Experience with SIEM and monitoring platforms; ability to communicate risks clearly.
  • Certifications such as SANS, GIAC or CISSP preferred; SC clearance a plus.
  • Familiarity with government/regulatory environments and energy sector threats.

Responsibilities

  • Lead the monitoring and analysis of security events to identify threats and respond.
  • Develop and implement monitoring roadmap; enhance detection capabilities.
  • Oversee triage and investigation of security alerts using SIEM and tools.
  • Lead automated monitoring and detection process development.
  • Manage vulnerability assessment and remediation using risk-based prioritisation.
  • Leverage threat intelligence to inform security operations and controls.
  • Lead incident response activities including containment and recovery.
  • Provide expert security risk guidance to stakeholders.
  • Support resilience through preparedness exercises and continuous capability development.
  • Produce reporting on security posture and trends for senior stakeholders.

Skills

Security operations
Incident detection
Threat intelligence
Vulnerability management
Stakeholder communication

Tools

SIEM
Monitoring tools
Azure security tools
M365 security tools

Job description

Successful candidates may be based in any of our office locations – Cardiff, Glasgow or London. We especially welcome applicants from Cardiff and Glasgow. 1 day per week in the office (20%)

Job summary

Across government, cyber security is fundamental to protecting critical services, safeguarding sensitive data and maintaining public trust. As cyber threats continue to evolve in scale and sophistication, organisations must strengthen their ability to detect, analyse and respond to potential incidents in real time. Ofgem plays a vital role in the UK’s energy system, protecting consumers and enabling a more secure, fair and sustainable energy future, and effective cyber security operations are essential to ensuring resilience and continuity of services.

Ofgem is on a significant transformation journey. Within the Digital, Data and Security Services (DDSS) directorate, we are strengthening our cyber security capability to support a modern, digitally enabled organisation. This includes enhancing monitoring, threat intelligence and incident response processes to ensure that risks are identified early and managed effectively.

As a Lead Cyber Security Analyst, you will play a critical role in protecting Ofgem’s systems and services. You will lead the monitoring and analysis of security events, drive improvements to detection capabilities and support the effective investigation and response to incidents. You will work across security operations, threat intelligence and vulnerability management, ensuring that the organisation remains resilient against a dynamic threat landscape.

This is a technically demanding and high-impact role, requiring strong analytical capability, experience in security operations and the ability to lead activity across complex environments. You will act as both a subject matter expert and a leader, supporting the development of capability and driving continuous improvement across cyber security operations.

You will be responsible for:
  • Leading the monitoring and analysis of security events, ensuring threats are identified, investigated and responded to effectively.
  • Managing the development and implementation of the monitoring roadmap, enhancing detection capabilities across the organisation.
  • Overseeing the triage and investigation of security alerts using SIEM and other monitoring tools, ensuring appropriate escalation and response.
  • Leading the development of automated monitoring and detection processes, improving efficiency and accuracy of threat detection.
  • Managing vulnerability assessment and remediation activities, ensuring risks are prioritised and addressed using a risk-based approach.
  • Leveraging threat intelligence to inform security operations, identify risks and enhance preventative controls.
  • Leading incident response activities, including investigation, containment and recovery, and contributing to continuous improvement through lessons learned.
  • Providing expert advice to stakeholders on security risks, mitigations and best practice.
  • Supporting resilience through preparedness exercises, red teaming and continuous capability development.
  • Producing reporting and insight on security posture, risks and trends for senior stakeholders.
We are looking for:

A skilled and experienced cyber security professional who can operate effectively in a complex, fast-moving environment. You will bring strong technical expertise in security operations, along with the ability to lead and influence across teams.

You may come from a security operations, threat intelligence or cyber defence background, but you will demonstrate:

  • Experience working within a Security Operations environment
  • Strong experience in incident detection, analysis and response across complex systems
  • Expertise in intrusion detection, threat intelligence and vulnerability management
  • Experience working with security tools, including SIEM and monitoring platforms
  • The ability to communicate complex security issues clearly to technical and non-technical stakeholders

Relevant certifications such as SANS, GIAC or CISSP are expected (or willingness to achieve).

Experience working in government or regulated environments, and familiarity with threat landscapes relevant to energy or critical infrastructure, would be beneficial.

This is an opportunity to play a key role in safeguarding Ofgem’s digital environment. You will help ensure that systems and services are secure, resilient and capable of responding effectively to cyber threats, supporting the organisation’s mission at a time when cyber security has never been more critical.

Person specification
  • Demonstrable experience in analysing incidents across a complex environment. (Lead Criteria)
  • Experience in intrusion detection and analysis. (Lead Criteria)
  • Experience in a Security Operations environment.
  • Previous exposure to IT and network security and networking technologies and with system, security, and network monitoring tools.
  • Either holds, or can achieve, SC clearance.
  • SANS or GIAC Security Operations Modules or CISSP.
  • Sound awareness of the threat environment faced by government, regulatory departments and the energy industry.
  • Experience with M365 and Azure-related Security tooling.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Chief Information Security Officer
Chief Information Security Officer

SilverShoots • Cardiff, Glasgow, Greater London

Hybrid
GBP 130,000 - 180,000
Chief Information Security Officer
Chief Information Security Officer

Ofgem • Greater London

Hybrid
GBP 70,000 - 117,000
Cyber Strategy Technical Expert
Cyber Strategy Technical Expert

Ofgem • Glasgow

Hybrid
GBP 57,000 - 70,000
Hybrid working
Civil Service Pension
30 days annual leave
+4
Cyber Strategy Technical Expert
Cyber Strategy Technical Expert

Ofgem • Cardiff

Hybrid
GBP 57,000 - 70,000
Hybrid working
Civil Service pension
30 days annual leave after 2 years
+1
Regulatory Cyber Assurance Principal
Regulatory Cyber Assurance Principal

Ofgem • Glasgow, Cardiff, Greater London

Hybrid
GBP 60,000 - 67,000
Civil Service Pension
Hybrid working
Training and development opportunities
Principal Security Specialist
Principal Security Specialist

UK Regulators' Network • Glasgow

Hybrid
GBP 90,000 - 130,000
Professional development opportunities
Higher education funding (subject to/​
Hybrid working
Cyber Security Operations Lead
Cyber Security Operations Lead

Ofgem • Cardiff, Glasgow, Greater London

Hybrid
GBP 90,000 - 120,000
Cyber Strategy Technical Expert
Cyber Strategy Technical Expert

UK Regulators' Network • Glasgow

Hybrid
GBP 120,000 - 160,000
Principal Security Specialist
Principal Security Specialist

UKRN • Greater London, Glasgow, Cardiff

Hybrid
GBP 90,000 - 130,000
Professional development opportunities
Hybrid working arrangement
Cyber Security Analyst
Cyber Security Analyst

Vallum Associates • Greater London

On-site
GBP 60,000 - 80,000