Rodeo
Get started

Social Security Scotland

Lead Cyber Security Analyst - Identity and Access Management

Glasgow
£49.4k – £59.2k/yr
Posted about 18 hours ago
Sign up to applySee more jobs like this

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

Lead Cyber Security Analyst - Identity and Access Management (IAM)

We are seeking an experienced and motivated Lead Cyber Security Analyst specialising in Identity and Access Management (IAM) to join the Digital Risk & Security branch within Digital Delivery & Change. This role is responsible for leading the delivery and continuous improvement of IAM services that protect Social Security Scotland’s digital services, systems, and sensitive information.

As a technical lead within the Security Operations function, you will provide leadership and expertise across the organisation’s IAM capabilities, ensuring that access to systems, applications, and data is managed securely, appropriately, and in line with business and regulatory requirements. You will work closely with technical teams, service owners, and stakeholders to strengthen security controls, reduce risk, and support the adoption of modern identity security practices across a cloud-first environment.

You will lead the operational delivery and development of key IAM services, including:

  • Identity and Access Management (IAM)
  • Privileged Access Management (PAM)
  • Identity Governance and Administration (IGA)
  • Joiners, Movers and Leavers processes
  • Role-Based Access Controls (RBAC)
  • Authentication and Authorisation Services
  • Multi-Factor Authentication (MFA)
  • Access Reviews and Certification
  • Privileged Account Monitoring and Control

The role requires strong technical knowledge of identity technologies, access governance, and security best practices, alongside the ability to translate business requirements into effective security solutions. You will provide technical leadership, support the development of team capability, and drive continuous improvement to ensure IAM services remain effective, resilient, and aligned to organisational needs.

If you are passionate about identity security and want to play a key role in protecting critical public services and citizen data, we would welcome your application.

Responsibilities

  • Leads the technical design and implementation of Identity and Access Management (IAM) strategy across the agency, including access governance, privileged access management, authentication, and user lifecycle processes.
  • Has oversight of security administration processes and checks that all requests for support are dealt with according to agreed procedures.
  • Provides guidance in defining access rights and privileges across different applications and services across the Agency.
  • Contributes to the development of cyber security IAM policy, standards and guidelines appropriate to business, technology and legal requirements and in accordance with best professional and industry practice.
  • Delivers specific pieces of work resulting from the Cyber Security Strategy, related to cyber business risk and information control/protection requirements.
  • Champions incident management, incident investigation and response policy and/or incident management and investigation processes, procedures and systems.
  • Performs security risk, vulnerability assessments, and business impact analysis for complex information systems or risk-based projects.
  • Specifies requirements for environment, data, resources and tools. Interprets, executes and documents complex test scripts using agreed methods and standards.
  • Maintains current knowledge of malware attacks, and other cyber security threats.
  • Maintains knowledge of specific specialisms, provides detailed advice regarding their application and executes specialised tasks.

Success Profiles

We use an assessment framework called ‘Success Profiles’ which lists the elements we test and provides detailed descriptions of each. Find out more about the framework here.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

For this post, the following Success Profile elements will be assessed:

Experience

  • Subject matter expertise in developing and operationalising cyber security capabilities, including the design and implementation of Identity and Access Management (IAM) controls, automation of identity lifecycle processes, integration of enterprise applications with identity platforms, enhancement of Privileged Access Management (PAM), and implementation of new IAM controls and processes to meet evolving security, compliance and business requirements.
  • Proven experience in incident management and investigation, including reporting, root cause analysis, and resolution, with the capability to provide informed guidance on incident response methodologies and best practice.

Behaviours

  • Changing and Improving (Level 4)
  • Leadership (Level 4)

You can find out more about Success Profiles Behaviours here.

Technical / Professional Skills:

This role is aligned to Lead Cyber Security Analyst within the Government Digital and Data Profession.

These skills will be tested during the Technical Assessment if you are successful at sift stage. They will not be assessed at application stage. Please review the following to understand the skill expectations: Cyber Security: Operations - gov.scot

How To Apply

Apply online, you must provide a CV and Supporting Statement (of no more than 750 words) which provides evidence of how you meet the Experience and Behaviours listed in the Success Profiles above.

Artificial Intelligence (AI) tools can be used to support your application, but all statements and examples provided must be truthful, factually accurate and taken directly from your own experience. Where plagiarism has been identified (presenting the ideas and experiences of others, or generated by artificial intelligence, and presented as your own) applications will be withdrawn and internal candidates may be subject to disciplinary action.

Please see our candidate guidance for more information on acceptable and unacceptable uses of AI in recruitment.

Should a large number of applications be received, an initial sift may be completed using the CV and Supporting Statement against the first experience criteria. Candidates who pass the initial sift will have their applications fully assessed.

Successful candidates will be invited to a competency based interview which will assess the experience and behaviours, and a technical assessment comprising a 10 minute presentation which will assess the technical skills.

Please note: there may be a telephone interview prior to the final interview stage.

Full details of the interview and assessment process will be shared with shortlisted candidates once the sift has been completed.

We aim to provide feedback on request. However, where a large number of applications are received, it may not be possible to give feedback to candidates who are not invited to interview or assessment. Feedback will be available on request to all candidates who attend an interview or assessment.

Information Session

We will be hosting a candidate information session on Friday 14th August from 12noon - 1pm to provide you with further information about the role.

We Will Be Discussing

  • The Lead Cyber Security Analyst role and Digital Risk & Security team
  • Social Security Scotland
  • Our recruitment process
  • Q&A with the hiring manager

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

Please Join Us Using The Link Below

Join the meeting

Expected Timeline (subject to change)

  • Sift - week commencing 17th August 2026
  • Interview – week commencing 7th September 2026
  • Location - In Person in either Dundee or Glasgow

Reserve List

In the event that there are more successful candidates than posts available, a reserve list will be kept for up to 12 months.

About Us

Social Security Scotland is an Executive Agency of the Scottish Government. Our benefits help people from all walks of life in Scotland. We offer rewarding careers and employ people across Scotland in a wide range of professions and roles. We are committed to recruiting a diverse workforce that is representative of the clients we serve. Find more about us here.

We offer a supportive and inclusive working environment along with a wide range of employee benefits. Find out more about what we offer here.

As part of the UK Civil Service, we uphold the Civil Service Nationality Rules.

GDD Pay Supplement

This post is part of the Government Digital and Data (GDD) profession and currently attracts a £4,000 annual GDD pay supplement, which is paid monthly. Pay supplements are reviewed regularly.

Working Pattern

Our standard hours are 35 hours per week and we offer a range of flexible working options, depending on the needs of the role. We embrace a hybrid working style where all colleagues will spend time in either our Glasgow or Dundee offices. There is an expectation of a minimum 2 days per week in your assigned location, which will be either Glasgow or Dundee. If you have specific questions about the role you are applying for, please contact us.

Security Checks

This post requires the successful candidate to clear additional National Security Vetting clearance (Security Check) as well as a Baseline Personnel Security Standard (BPSS) before a start date can be offered.

Further information regarding National Security Vetting clearance can be found here - United Kingdom Security Vetting: Applicant - GOV.UK

Equality Statement

Social Security Scotland are committed to equality and inclusion, and we aim to recruit a diverse workforce that reflects the population of our nation.

Social Security Scotland are a Disability Confident Employer. We will consider and implement any reasonable adjustments you may require throughout the recruitment process and during the course of your employment, should you be successful in securing a post. If you feel you may require assistance with any part of our recruitment process, please contact us at Recruitment@socialsecurity.gov.scot.

Find out more about our commitment to diversity and how we offer and support recruitment adjustments for anyone who needs them.

Right to Work in the UK

Social Security Scotland is an approved sponsor under the UK Visa and Immigration (UKVI) Skilled Worker route. Please note that UK immigration guidance, including skill and salary thresholds and eligible occupations, is reviewed regularly and subject to change. If you require visa sponsorship, you should check the latest criteria to confirm whether this role meets current requirements before applying. You can find further advice on Gov.UK - Skilled Worker visa: Overview - GOV.UK.

Further Information

Social Security Scotland’

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Skills

Identity And Access Management
Privileged Access Management
Identity Governance And Administration
Role-Based Access Control
Multi-Factor Authentication
Incident Management
Security Risk Assessment
Vulnerability Assessment
Technical Design
Cloud Security
User Lifecycle Management
Authentication And Authorisation
Access Certification
Cyber Security Strategy
Stakeholder Management
Technical Leadership

Location

Glasgow, Scotland, United Kingdom

Sign up to applySee more jobs like this