Rodeo
Get started

Ministry of Justice UK

Lead Cyber Detect and Respond Analyst (Ref: 20811)

London
£42.9k – £56.1k/yr
Posted about 20 hours ago
Sign up to applySee more jobs like this

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

Locations

East Midlands (England), East of England, London (region), North East England, North West England, Scotland, South East England, South West England, Wales, West Midlands (England), Yorkshire and the Humber


Job Summary

This is a Nationally based role.


Job Description

Lead Cyber Detect and Respond Analyst

  • Location: National*
  • Closing Date: 27th August 2026
  • Interviews: w/c 7th September 2026
  • Grade: SEO (MoJ candidates who are on a specialist grade, will be able to retain this grade on lateral transfer)
  • Salary:
    • National: £42,914 - £51,675 which may include an allowance up to £8,761.
    • London: £49,325 - £56,050 which may include an allowance up to £6,725.
  • Working pattern: Full-time, Flexible working
  • Contract Type: Permanent
  • Number of vacancies: 2
  • Vacancy number: 20811

We offer a hybrid working model, allowing for a balance between remote work and time spent in your local office. Office locations can be found ON THIS MAP.

Please note that unless you are an existing member of staff at Justice Digital, Data and Science, the only London location being recruited to is 10 South Colonnade, E14 4PU. We are no longer recruiting to 102 Petty France, SW1H 9AJ.


The Role

Please note this role requires you to pass Security Check clearance. Please click on the link for details.

We’re recruiting for a Lead Cyber Detect and Respond Analyst here at Justice Digital, Data and Science to be part of our warm and collaborative Digital Infrastructure and Security Operations (DISO) team.

This role aligns against Monitoring Lead from the Government Security Profession Framework.

The Lead Cyber Detect and Respond Analyst will lead the proactive monitoring, analysis, and response to security events and incidents, ensuring the effective detection and mitigation of cyber threats to the Ministry of Justice (MoJ). The lead analyst develops and refines detection and response procedures, mentors junior team members, and provides expert guidance during high-severity incidents.

Operating with a high degree of independence and technical authority, this role plays a critical part in strengthening the MoJ’s cyber resilience and advancing the maturity of SOC operations.

We recognise that people develop skills through a variety of professional, academic, and lived experiences.


Key Responsibilities

  • SOC actively monitor the hours between 8am - 6pm and provide on call coverage if needed outside of these hours. This is managed on a rota basis. Additional allowances are provided for on-call staff.
  • Lead the day-to-day coordination of security operations activities, ensuring investigations, incident response actions, and operational tasks are effectively assigned, tracked, and delivered.
  • Manage operational workload distribution across the team, balancing priorities, resolving resource conflicts, and maintaining visibility of deadlines and service commitments.
  • Oversee and maintain incident and investigation tracking processes, ensuring records are accurate, up to date, and provide clear operational oversight.
  • Act as one of the primary escalation points for complex security investigations, incidents, and operational issues, providing direction and support to analysts.
  • Mentor and coach analysts in investigative techniques, incident handling, and response processes to improve team capability and consistency.
  • Line Management/People Management responsibilities, requiring a strong people person who can build trusted relationships, motivate and support individuals, manage performance constructively, communicate effectively at all levels, and create a positive and collaborative team environment.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.


Benefits

You’ll receive a range of excellent benefits when you join our department, including:

  • A generous employer pension contribution of 28.97% through the Civil Service Pension Scheme.
  • 25 days of annual leave, (increasing to 30 days once you have reached 5 years of service), plus 8 bank holidays and a privilege day for the King’s birthday.
  • Flexible working arrangements including hybrid working, working part time or compressed hours. Designed to support a positive work–life balance.
  • Employees are allocated 10% of their working time for personal and professional development.
  • A £1k per person learning budget is in place to support all our people, with access to best-in-class conferences and seminars, accreditation with professional bodies, fully funded vocational programmes and e-learning platforms.
  • Compassionate maternity, adoption, and shared parental leave policies, with up to 26 weeks leave at full pay, 13 weeks with partial pay, and 13 weeks further leave. And maternity support/paternity leave at full pay for 2 weeks, too!

You can find more details of the Benefits we offer here. To help picture your life at MoJ Justice Digital, Data and Science please take a look at our blog.


Person Specification

Essential

  • Experience working in a Security Operations Centre (SOC) or similar cyber security role.
  • Previous experience leading, coordinating, or supervising.
  • Working understanding of cybersecurity operations, threat detection methodologies, and incident response processes.
  • Strong experience in analysing and correlating logs (e.g., SIEM, XDR/EDR, cloud, network).
  • Excellent analytical and critical thinking skills, with the ability to make sound decisions under pressure.
  • Strong communication skills, capable of presenting findings to technical and non-technical stakeholders.
  • Strong people skills with experience mentoring and developing junior analysts, building confidence and capability within the team while contributing to SOC process and detection improvements.
  • Demonstrated ability to work collaboratively across teams and with external partners.

Willingness to be assessed against the requirements for SC clearance

We welcome the unique contribution diverse applicants bring and do not discriminate based on culture, ethnicity, race, nationality or national origin, age, sex, gender identity or expression, religion or belief, disability status, sexual orientation, educational or social background or any other factor.

Our values are Purpose, Humanity Openness and Together. Find out more here about how we celebrate diversity and an inclusive culture in our workplace.

The Civil Service is committed to attract, retain and invest in talent wherever it is found. To learn more please see the Civil Service People Plan and the Civil Service D&I Strategy.

Justice Digital, Data and Science (Ministry of Justice) was named Best Employer of the Year at the Women in Tech Excellence Awards 2025.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

Salary Information

Base salary for this role is from

  • London: £49,325 - £53,081
  • National: £42,914 - £46,182

New entrants to the Civil Service joining the MoJ are expected to start at the minimum of the pay band.

Existing Civil Servants moving on a level transfer will retain their current base salary or move to the minimum of the pay band for the role, whichever is higher.

Existing Civil Servants who are promoted will either move to the bottom of the new grade’s pay band or receive a 10% uplift, whichever provides the greater increase.

Candidates may also be eligible for a non‑pensionable Government Digital & Data Allowance of up to £6,725 per year (London) or £8,761 (National). This is a temporary allowance, reviewed annually and may be retained, amended, or withdrawn.

The final offer will reflect the skills and experience you demonstrate during the assessment process.

In Justice Digital, Data and Science, we recruit using a combination of the Success Profiles and Government Security Profession Frameworks. We shall assess a combination of your Experience, Technical skills and Behaviours during the assessment process.


Stage 1 - Application And Sift

To apply for this position, you must submit the following as part of your application (please amend accordingly):

  • A CV detailing your career history (including any relevant qualifications). Your CV will be assessed against the essential criteria outlined within the Person Specification of this advert.
  • A Personal Statement (no more than 750 words) which should outline your experience and skills, giving clear examples of work undertaken. It should specifically address the following 5 criteria listed below, using a separate paragraph for each.
    • Experience working in a Security Operations Centre (SOC) or similar cyber security role.
    • Previous experience leading, coordinating, or supervising.
    • Working understanding of cybersecurity operations, threat detection methodologies, and incident response processes.
    • Excellent analytical and critical thinking skills, with the ability to make sound decisions under pressure.
    • Strong communication skills, capable of presenting findings to technical and non-technical stakeholders.

A diverse sift panel will review the information in your CV and Personal Statement to assess the sift criteria specified above. We operate an anonymous shortlisting process. Please ensure your CV and Personal Statement do not include your name or any other identifying details.

Should We Receive a High Volume Of Applications, a Pre-sift Based On The Following Criteria Will Be Conducted Before The Sift:

  • Experience working in a Security Operations Centre (SOC) or similar cyber security role.
  • Working understanding of cybersecurity operations, threat detection methodologies, and incident response processes.
  • Excellent analytical and critical thinking skills, with the ability to make sound decisions under pressure.

Please access the following link for guidance on how to apply - Application Guidance


Stage 2 - Interviews

Successful candidates who meet the required standard will then be invited to a panel interview held via Microsoft Teams. At interview stage, you will be assessed

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Skills

Security Operations Centre (SOC)
Threat Detection
Incident Response
SIEM
XDR
EDR
Log Analysis
Cybersecurity Operations
People Management
Mentoring
Critical Thinking
Stakeholder Communication
Cyber Resilience
Security Monitoring
Technical Leadership
Incident Handling

Location

London, England, United Kingdom

Sign up to applySee more jobs like this