Cyber Security Analyst - Infrastructure & Networks
At a glance
- Band
- Band 7
- Contract
- Permanent
- Pattern
- Full-time, Part-time, Job share, Flexible working
- Posted
- 16/09/2026
- Closes
- 30/09/2026
Sponsorship verdict
This contract type is not eligible for Skilled Worker sponsorship.
NHS Trusts cannot issue a Certificate of Sponsorship for part-time, bank, locum, zero-hours, job-share or short fixed-term (under 12 months) contracts under current Home Office rules. This applies even when the wider Trust holds a Skilled Worker licence.
Role summary
This role is for a Cyber Security Analyst within the Infrastructure and Networks teams of the national Cyber Security Operations Centre (CSOC). The analyst will act as a Tier 2 analyst, supporting and mentoring junior analysts, and escalating incidents. Key responsibilities include using advanced analytic tools to identify threats, assisting with investigations, and refining security posture. The position contributes to building NHS England's cyber resilience and enabling the wider health system to be cyber resilient.
Key responsibilities
- Act as a Tier 2 Infrastructures and Networks analyst for the Security Operations team.
- Deputise for Senior Analysts in their absence.
- Act as an escalation point for Tier 1 Junior Analysts for incidents and investigations.
- Offer mentorship and guidance to Tier 1 Junior Analysts to support others and their own growth and development.
- Keep up to date with the latest security and technology developments, including researching and evaluating emerging cyber security threats and ways to manage them.
- Use advanced analytic tools including SIEMs and XDR platforms to determine emerging threat patterns and vulnerabilities.
Essential criteria
- Working knowledge of methods and processes to monitor, analyse and respond to network attacks, intrusions or any unauthorised actions; ability to use techniques and tools to perform network defence.
- Proven knowledge of tools, techniques and processes of intrusion detection and prevention; ability to detect, resolve and prevent intrusion behaviours to protect organisational networks.
- Working knowledge of concept, procedures and processes of Security Information and Event Management (SIEM); ability to utilise related applications to protect organisational networks from cyber risks.
- Post-graduate level degree in Cyber Security, or relevant subject, or equivalent level of experience.
- Evidence of continuous professional development.
Desirable criteria
- Working knowledge of modules, processes and technologies of Information Security Operation Centre (ISOC); ability to detect, response and utilise related platform and applications to perform cyber security initiatives.
- Working knowledge of concept, issues and techniques of endpoint security; ability to ensure security compliance of endpoint devices in various circumstances.
Useful to know
Agenda for Change 2024/25 pays Band 7 at £46,148 – £52,809 a year, across England.
This advert: £59,264 – £67,818 — outside the standard scale; check for HCAS/London weighting.
Posted 1d ago · Closes in 14d
Plenty of time to prepare a strong application.
Full advert · preview
NHS England
Cyber Security Analyst - Infrastructure & Networks
The closing date is 30 September 2026
Job summary
Cyber Operations purpose is to support safe care and build public trust by building NHS England's cyber resilience and enabling the wider health system to be cyber resilient, supporting Transformation Directorate's purpose of delivering the best care and outcomes for the NHS.
The Cyber Operations sub-directorate consists of four operational areas:
- Cyber Security Operations Unit (CSOU & SIO)
- Cyber Delivery Unit (CDU)
- Cyber Improvement Programme
- Chief Information Security Office Function (CISO)
This role is for a Cyber Security Analyst in the Infrastructure and Networks teams within the Protective Monitoring area of the national CSOC. This is a Tier 2 role working with the Infrastructure and Networks team to help develop and improve existing analytical rules plus supporting Tier 1 junior analysts with triage and incident handling.
Main duties of the job
The Security Advisor Infrastructure and Networks analyst role is within the Security Operations pillar of the CSOC (Cyber Security Operations Centre) providing second line security analytics and incident response services.
- Act as a Tier 2 Infrastructures and Networks analyst for the Security Operations team.
- Deputise for Senior Analysts in their absence.
- Act as an escalation poi
Join the community to read the full pack, responsibilities and person-specification in one place.
Your seat is reserved — activate it
CareerHive is included with your CareerHive Skool community membership. If you haven't claimed your account yet, join the community (or sign in with the same email you joined with) to unlock the full advert, the apply link, HiveMind AI interview & application suite, your private vault, and daily sponsorship alerts.