- Scottish Government Recruitment
- Glasgow, Glasgow City
- Full-Time
- 80 days ago
- £62,100 – £77,400
Principal Cyber Security Analyst.
Before you go
Before you leave us, sign up for our email alerts
We don't do job spam, just the best digital jobs delivered straight to your inbox.
Principal Cyber Security Analyst: our view in 3 lines...
- The Role:A principal cybersecurity role leading Security Operations for Social Security Scotland, combining technical leadership with hands-on security oversight in a public services environment.
- The Person:The person will lead a team of Cyber Security Engineers and Analysts, own the core security tooling estate, and design, implement, and operate key security technologies and services.
- Requirements:The role requires deep technical expertise across Security Information and Event Management, Security Orchestration, Automation and Response, Endpoint Detection and Response, Network Detection and Response, Vulnerability and Exposure Management, Security Incident Management and Response, and Cyber Threat Intelligence.
About the role
At Social Security Scotland, security is fundamental to delivering trusted public services. We're looking for an exceptional Principal Cyber Security Analyst to lead our Security Operations capability, helping us defend critical systems, protect sensitive data, and respond to an evolving cyber threat landscape. This is an opportunity to combine strategic leadership with hands-on technical expertise while making a genuine difference to the lives of people across Scotland.
As a senior technical leader within the Security Operations function, you will lead a team of Cyber Security Engineers and Analysts, providing both strategic direction and hands-on technical oversight. You will take ownership of the organisation’s core security tooling estate, driving continuous evolution and optimisation to ensure our capabilities remain effective against an evolving threat landscape.
You will be accountable for the design, implementation, and operation of key security technologies and services across a cloud-first environment, including:
- Security Information and Event Management (SIEM)
- Security Orchestration, Automation and Response (SOAR)
- Endpoint Detection and Response (EDR/XDR)
- Network Detection and Response (NDR)
- Vulnerability and Exposure Management
- Security Incident Management and Response
- Cyber Threat Intelligence (CTI)
This role requires deep technical expertise across modern security operations tooling and architectures, with a strong understanding of how to operate and optimise these capabilities within a complex, cloud-native environment. You will be expected to articulate and influence security strategy, manage technical risk, and ensure the effective implementation of controls to mitigate cyber threats.
If you are passionate about security operations and eager to make a real difference in public services, we invite you to join our talented team and take the next step in your career.

