Cyber Security Operations Analyst
Listed on 2026-06-12
-
IT/Tech
Cybersecurity
The Cyber Security Team sits within Enterprise Information Services (EIS), part of the Enabling Services Directorate. We provide cyber security services to SDS and its shared service partners:
Scottish Enterprise, Highlands and Islands Enterprise, and South of Scotland Enterprise, supporting around 3,800 users. The team comprises two core functions:
Security Operations and Security Operations Engineering, reporting to the Information Security Manager. This role sits within the Sec Ops engineering function, working hands‑on with the Microsoft security tooling stack to protect our people, data, and services.
Be part of something bigger — build skills, change lives!
What You’ll Be DoingThis is a hands‑on security engineering role. You’ll be responsible for configuring, optimising, and continuously improving our Microsoft security tooling stack including Sentinel, Defender Suite, Entra , Intune, Purview, and Forcepoint to mature the cyber security posture across all four partner organisations.
You’ll engineer, review, and tune detection analytics rules in Sentinel, onboard new log sources, and develop automated security workflows using playbooks and Logic Apps. While our managed Security Operations Centre (SOC) provider supports the creation and tuning of analytics, you’ll provide the in‑house technical capability to understand how detections work, validate and optimise them, and perform gap analysis so we have independent assurance that coverage is effective and efficient.
You’ll assess detection coverage against frameworks like MITRE ATT&CK, identify gaps, and build the content to close them.
You’ll own security‑related changes through the Change Advisory Board (CAB) process, produce supporting technical documentation, and test and validate configurations to make sure they perform as intended. Working alongside our Security Operations Engineer, you’ll support security programme delivery aligned to tooling maturity and provide direct operational resilience to the security operations function. You’ll act as the primary technical interface with our managed SOC provider and Microsoft, challenging supplier performance and driving continuous service improvement.
You’ll also contribute to a security tooling roadmap, maintain an improvement backlog, and help maximise the return on our Microsoft E5 licence investment. Your work will directly strengthen our Cyber Essentials Plus accreditation and improve the security posture for thousands of users across Scotland.
What We’re Looking ForYou’ll have solid experience in using Microsoft security and compliance technologies, including Sentinel, Defender Suite, Entra , Intune, and Purview. You’ll also understand how to implement security baselines aligned to Centre for Internet Security (CIS) benchmarks, which are industry best practice standards for securing IT systems.
You’ll be confident in raising and presenting technical changes at the Change Advisory Board (CAB), producing clear technical documentation, and troubleshooting when configurations do not perform as expected. You’ll know how to work with external suppliers and hold them to agreed standards and deliverables.
Experience in Sentinel automation, mapping detections to the MITRE ATT&CK framework, or improving an organisation’s Secure Score would be advantageous.
A degree‑level qualification in cyber security or equivalent practical experience is essential. A recognised professional certification such as CISSP, CISM, Microsoft Certified:
Security Operations Analyst Associate (SC‑200), or Microsoft 365 Security Administrator (MS‑500) would be beneficial.
Skills Development Scotland (SDS) is Scotland’s national skills agency, focused on driving productivity and inclusive economic growth by investing in skills and supporting people and businesses to reach their full potential. Through deep partnership working, expert insights and innovative solutions, SDS helps address Scotland’s skills and labour‑market challenges, ensuring employers can access the talent they need while individuals gain opportunities to develop and thrive.
SDS is guided by strong organisational values, placing customers at the…
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: