Registers of Scotland
Senior Cyber Security Analyst

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Senior Cyber Security Analyst
Grade: SEO
Total remuneration: £60,291 – £70,987
Pay Supplement: The base salary for this role is £50,243 – £59,156. This job qualifies for Digital, Data and Technology Annual Pay supplement 20% is included in the total remuneration above.
Pension: 28.97% (RoS contribution)
Annual leave: 38 days annual holiday, increasing to 42 days with length of service.
Duration: Permanent.
Working Pattern: 35 hours per week. We are a flexible employer and will consider a variety of working patterns on a case-by-case basis. For example, compressed hours, term-time working or part-time working.
Location: Hybrid working model. Contractual base either at Meadowbank House, Edinburgh (EH8 7AU), or St Vincent Plaza, Glasgow (G2 5LD).
Department: Cyber Security
Directorate: Digital and Data and Technology Directorate
Role Reports to: IT Enablement Manager / Cyber Security Technical Product Manager
Closing date: 18th of October 2026
Number of vacancies: 1 (In case that we will have more than 1 successful candidate we will conduct a business and budget review in order to validate a 2nd hire. Merit order will be followed.)
Registers of Scotland (RoS)
Join an award-winning organisation recognised for its technology and innovation. Registers of Scotland is a world-leading pioneer in land and property registration. Our full-stack teams design, architect, and build all our registration products in-house. We work to create digital solutions for the people of Scotland. You will get an opportunity to nurture your creativity and develop with us through access to the latest data, software engineering and product delivery techniques.
This job is for you if you want…
- Work with purpose: working for the people of Scotland to set the bar for land and property registration worldwide.
- Flexible and hybrid working: depending on the role and team requirements, work when and where it’s best for you and your stakeholders.
- Benefits: enjoy pay progression, pension contributions of up to 28.97%, up to a year’s parental leave, and 38 days annual holiday, increasing to 42 days with length of service.
- Investment in professional development: we invest in all our people so that they have the right skills to be productive and confident in their job.
- Diversity and Inclusion: We are an ‘Investor in People’ and a ‘Disability Confident’ employer. We are inclusive, stronger together, and committed to putting our people first.
- Positive work culture: RoS is an agile, digital organisation using leading-edge technology. Colleagues understand their role in achieving our strategy and have the autonomy to deliver.
To learn more about RoS and what we offer visit our careers pages or watch this short video.
Hear from our colleagues about their experience of working within our Digital, Data and Technology teams on our website.
Our Tech stack
Security Operations: Cortex XSIAM, Cortex XSOAR, Microsoft Defender, SIEM/XDR platforms, Incident Response, Detection Engineering, Threat Hunting, Threat Intelligence, Digital Forensics, Vulnerability Management and Ticket Management.
Network & Cloud Security: Firewalls, Network Threat Prevention, Network Traffic Analysis, Network Access Control (NAC), Cloud Security Posture Management (CSPM) and Cloud Security Technologies.
Automation & Engineering: SOAR, Playbook Development, Workflow Automation, Security Analytics, KQL, PowerShell, Python and API Integrations.
The Role
We are seeking an experienced Senior Cyber Security Analyst to join Registers of Scotland (RoS) and help protect the organisation as we continue our digital transformation journey.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Working within our Cyber Security team, you will play a key role in detecting, investigating, and responding to cyber threats and security incidents. You'll collaborate with colleagues across security, IT operations, and development teams to strengthen our security capabilities, improve processes, and deliver effective security solutions. As a senior member of the team, you'll also support and mentor colleagues while helping to shape a strong security culture across the organisation.
On a typical day you will…
Security Operations and Incident Response
- Detect, triage, investigate, and respond to a wide range of cyber security events and incidents using security monitoring and analysis tools.
- Lead and support incident response activities, ensuring security incidents are investigated, contained, eradicated, and resolved in line with agreed procedures.
- Conduct detailed analysis of security alerts to determine impact, severity, and remediation requirements.
- Perform proactive threat hunting activities using indicators of compromise (IoCs), threat intelligence, and emerging threat information from government, industry, and trusted partners.
- Support the wider Security Operations function during major incidents and contribute to post-incident reviews and lessons learned activities.
- Monitor emerging cyber threats and vulnerabilities, assessing potential impacts on organisational services and systems.
- Collaborate with infrastructure, cloud, network, and development teams to investigate and resolve complex security issues.
- Contribute to the continuous improvement of incident response processes, playbooks, and operational procedures.
- Participate in out-of-hours or major incident activities where required.
Security Engineering, Improvement and Automation
- Develop, tune, and optimise security monitoring solutions to improve detection accuracy, reduce false positives, and enhance operational effectiveness.
- Identify opportunities to automate routine security activities, improving efficiency and response times across Security Operations.
- Design and implement new security detections, use cases, and alerting mechanisms to address emerging threats.
- Evaluate existing security services, controls, and tooling, recommending improvements based on industry best practice and organisational needs.
- Support the onboarding and integration of new platforms, services, and technologies into security monitoring capabilities.
- Contribute to vulnerability management activities, helping identify, prioritise, and address security weaknesses.
- Develop metrics, dashboards, and reporting to support operational performance and informed decision making.
- Work closely with projects and product teams to ensure security requirements are considered throughout the delivery lifecycle.
- Keep abreast of emerging technologies, industry trends, and evolving cyber threats, applying this knowledge to improve organisational security.
Leadership, Collaboration and Professional Practice
- Act as a subject matter expert, providing advice and guidance on cyber security matters to technical and non-technical stakeholders.
- Respond to security-related enquiries from colleagues across Digital, Data and Technology and the wider business.
- Mentor and support Cyber Security Analysts, promoting knowledge sharing, professional development, and continuous learning.
- Create, maintain, and review technical documentation, including standard operating procedures, playbooks, investigation guides, and system configuration documentation.
- Support the development and adoption of security standards, policies, and operating procedures.
- Build effective working relationships with colleagues, suppliers, and external partners to strengthen security collaboration.
- Contribute to a culture of continuous improvement, innovation, and operational excellence within the Cyber Security team.
- Communicate complex technical information clearly and effectively to a range of audiences, ensuring security risks and recommendations are understood and actionable.
- Support audit, compliance, and assurance activities by providing evidence, technical input, and subject matter expertise where required.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Key Responsibilities
Essential Criteria – Skills and Attributes for Success
Technical Experience: We will assess you against the following Technical Experience during the application and assessment process:
- Demonstrable experience working in a Cyber Security Analyst, Security Operations, or Incident Response role, with responsibilities appropriate to a senior-level position.
- Experience of detecting, triaging, investigating, and responding to cyber security events and incidents using security monitoring and analysis tools.
- Experience of developing, maintaining, and tuning security detections and alerting capabilities to improve threat detection and reduce false positives.
- Experience of conducting security investigations, identifying root causes, and supporting the implementation of remediation and mitigation activities.
- Experience of using threat intelligence and indicators of compromise (IoCs) to undertake threat hunting and support proactive security investigations.
- Experience of using IT Service Management (ITSM) tools to manage security incidents, operational tasks, and service requests.
- Practical experience of working with security technologies such as Security Information and Event Management (SIEM), Extended Detection and Response (XDR), Security Orchestration, Automation and Response (SOAR), Next Generation Firewalls (NGFW), Web Application Firewalls (WAF), Network Access Control (NAC), Cloud Security Posture Management (CSPM), or vulnerability management solutions.
- Ability to explain the purpose and operation of technical security controls and provide expert advice and guidance to technical and non-technical stakeholders.
- Experience of creating and maintaining technical documentation, including standard operating procedures, playbooks, investigation guides, and technical standards.
- Strong analytical and problem-solving skills, with the ability to assess risk, prioritise competing demands, and make informed decisions in a fast-paced operational environment.
- Excellent communication skills, with the ability to communicate complex technical concepts clearly and effectively to a range of audiences, including senior stakeholders.
- Experience of mentoring, supporting, or sharing knowledge with colleagues to develop capability and promote a culture of continuous learning.
- Relevant cyber security certifications, qualifications, or equivalent professional experience demonstrating technical expertise and a commitment to continued professional development.
Behaviours
At application stage, you will be scored against the bolded Behaviours and against all Behaviours for the assessment:
Working Together
- Build effective working relationships with colleagues across cyber security, IT operations,
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Location