An application made for this job — a tailored resume and cover letter that speak straight to the posting.
Companies House is seeking a Senior Lead Security Operations Analyst to shape and evolve our security monitoring and incident response capabilities. You will lead complex investigations, provide technical guidance, and drive improvements across Microsoft Sentinel, Defender and AWS environments.
You will balance hands-on monitoring with leadership responsibilities, mentoring analysts and coordinating across security, cloud and engineering teams to protect services and data.
D0.33, Queen Elizabeth House, 1 Sibbald Walk, Edinburgh, EH8 8FT
Crown Way, Cardiff, CF14 3UZ
D0.33, Queen Elizabeth House, 1 Sibbald Walk, Edinburgh, EH8 8FT
Job summary
We are looking for an experienced and technically skilled Senior Lead Security Operations Analyst to play a key role in the continued development of Security Operations at Companies House.
You will provide technical leadership within the Security Operations team, supporting analysts with complex investigations and helping to ensure security incidents are effectively identified, investigated, contained and escalated.
You will remain hands-on, using security monitoring and threat detection technologies including Microsoft Sentinel, Microsoft Defender and Amazon Web Services security tooling to investigate activity across our cloud and technology environments.
The role will also help drive improvements to our security monitoring capability, including developing and tuning detection rules, improving investigation and response processes, introducing automation and ensuring our monitoring continues to evolve alongside the threats facing Companies House.
You should be comfortable working with large volumes of security and log data, making evidence-based decisions and communicating technical security issues clearly to both technical and non-technical colleagues.
This is an opportunity to take a senior technical role within an evolving Security Operations capability and directly influence how Companies House detects, investigates and responds to cyber security threats.
This role aligns with the Government Security Profession Secure Development Framework and the Government Digital and Data (GDaD) DevOps Engineer Capability Framework. Candidates may find these useful when preparing examples for their personal statement and demonstrating relevant technical skills and experience.
To be eligible for this role you also need to meet our Nationality requirements which are outlined below and also successful candidates must meet the security requirements for Security Clearance (SC) before they can be appointed. To gain (SC) clearance you will need to have been a UK resident for a minimum of 3 years out of the last 5 years. For more details, please refer to the ‘Things you need to know’ section below.
As the Senior Lead Security Operations Specialist, you will be a senior technical leader within the Companies House Security Operations team, helping to protect our services, systems and information from cyber security threats.
You will combine hands‑on technical expertise with leadership responsibility, leading complex security investigations, developing our monitoring and detection capabilities and providing technical guidance to the wider team. You will act as a senior escalation point and support the Head of Security Operations in developing the function.
You will be trusted to make operational security decisions, coordinate responses to significant incidents and engage with senior stakeholders when required.
Companies House operates across Microsoft Azure, Amazon Web Services and enterprise technology environments, with Microsoft Sentinel and Microsoft Defender forming key parts of our security monitoring and investigation capability.
This is a hands‑on technical role with technical and operational leadership responsibility. You will remain actively involved in security monitoring, investigations, detection engineering and incident response while helping to develop the capability of the wider Security Operations team.
Companies House cannot offer Visa sponsorship to candidates through this campaign.
The Security Operations team sits within the wider Security function at Companies House and is responsible for monitoring, detecting, investigating and responding to cyber security threats across our technology and cloud environments.
We are a collaborative and technically focused team made up of Security Operations analysts, senior specialists and threat intelligence capability, working closely with colleagues across security, cloud, platform and engineering teams as well as external security partners.
The team is continuing to develop and modernise its Security Operations capability, with a strong focus on Microsoft Sentinel and Microsoft Defender, alongside increasing security monitoring and response across Amazon Web Services. We are also investing in improved security telemetry, detection engineering, automation and threat intelligence to help us identify and respond to threats more effectively.
There is significant opportunity to influence how the capability develops. We encourage new ideas, continuous improvement and knowledge sharing, with team members given the opportunity to develop their technical skills, take ownership of meaningful work and contribute to the future direction of Security Operations at Companies House.
We have a supportive and collaborative culture where people are encouraged to challenge existing approaches, share knowledge and learn from each other. As a Senior Lead, you will play an important role in maintaining that culture and helping develop the technical capability of the wider team.
You will be aligned to either the Cardiff or Edinburgh office, where you will be expected to attend at least once a week. We are currently using a hybrid approach to the way we work which provides opportunities for you to be adaptable in the way you work so that you can achieve a healthy balance between your work and home life. Your manager will agree regular patterns of attendance with you; however, you may be required to make yourself available to attend the office more frequently when required to meet business needs.
The successful candidate will be an experienced cyber security professional with: