Back to the board
No sponsorship
Band 6
Full-time, Part-time, Job share, Flexible working

Junior Cyber Security Analyst (Security Officer)

NHS EnglandWellington Place, Leeds / Hexagon House, Exeter£43,955 - £52,929Closes 21/09/2026

At a glance

Band
Band 6
Contract
Permanent
Pattern
Full-time, Part-time, Job share, Flexible working
Posted
07/09/2026
Closes
21/09/2026

Sponsorship verdict

This contract type is not eligible for Skilled Worker sponsorship.

NHS Trusts cannot issue a Certificate of Sponsorship for part-time, bank, locum, zero-hours, job-share or short fixed-term (under 12 months) contracts under current Home Office rules. This applies even when the wider Trust holds a Skilled Worker licence.

Role summary

This role is for a Junior Cyber Security Analyst within the NHS England Cybersecurity Operations Centre (CSOC), with a national remit. You will perform first-line alert triage from cybersecurity monitoring tools, investigate alerts, and provide conclusions to stakeholders. The position involves working with extensive technical monitoring tools across various environments to protect national healthcare. You will also contribute to developing and refining systems to improve detection rates and support incident response activities.

Key responsibilities

  • Perform first line alert triage from cybersecurity monitoring tooling.
  • Evaluate and investigate alerts, providing conclusions to external healthcare organisations or internal stakeholders.
  • Utilise extensive technical monitoring tooling across networks, cloud environments, endpoint telemetry, collaboration, and identity management services.
  • Develop or use knowledge of cybersecurity tooling to automate and refine systems, improving detection rates and alleviating pain points for the SOC.
  • Review or guide B5 analysts and create/update standard process documentation and triage guides.
  • Support incident response activities and detailed investigations, depending on experience.

Essential criteria

  • Knowledge of concept, procedures and processes of Security Information and Event Management (SIEM); ability to utilise related applications to protect organisational networks from cyber risks.
  • Knowledge of tools, techniques and processes of intrusion detection and prevention; ability to detect, resolve and prevent intrusion behaviours to protect organisational networks.
  • Knowledge of techniques, approaches and processes of digital threats; ability to detect, monitor, analyse and prevent digital threats.

Desirable criteria

  • Knowledge of technologies, methods and tools of forensics investigations for IT security violations or potential threats; ability to identify, uncover and evaluate violations, warning reports, suspected incidents and insidious events.
  • Knowledge of modules, processes and technologies of Information Security Operation Centre (ISOC); ability to detect, response and utilise related platform and applications to perform cyber security initiatives.
  • Knowledge of methods and processes to monitor, analyse and respond to network attacks, intrusions or any unauthorised actions; ability to use techniques and tools to perform network defence.
  • Post-graduate level degree in Cyber Security or relevant subject, or equivalent level of experience.
  • Knowledge of concept, procedures and processes of Security Information and Event Management (SIEM); ability to utilise related applications to protect organisational networks from cyber risks.
  • Knowledge of tools, techniques and processes of intrusion detection and prevention; ability to detect, resolve and prevent intrusion behaviours to protect organisational networks.
  • Knowledge of techniques, approaches and processes of digital threats; ability to detect, monitor, analyse and prevent digital threats.
  • Knowledge of technologies, methods and tools of forensics investigations for IT security violations or potential threats; ability to identify, uncover and evaluate violations, warning reports, suspected incidents and insidious events.
  • Knowledge of modules, processes and technologies of Information Security Operation Centre (ISOC); ability to detect, response and utilise related platform and applications to perform cyber security initiatives.
  • Knowledge of methods and processes to monitor, analyse and respond to network attacks, intrusions or any unauthorised actions; ability to use techniques and tools to perform network defence.
  • Post-graduate level degree in Cyber Security or relevant subject, or equivalent level of experience.

Useful to know

Band 6 pay context

Agenda for Change 2024/25 pays Band 6 at £37,338 – £44,962 a year, across England.

This advert: £43,955 – £52,929 — outside the standard scale; check for HCAS/London weighting.

Application window

Posted 1d ago · Closes in 14d

Plenty of time to prepare a strong application.

Full advert · preview

NHS England

Junior Cyber Security Analyst (Security Officer)

The closing date is 21 September 2026

Job summary

Cyber Operations purpose is to support safe care and build public trust by building NHS England's cyber resilience and enabling the wider health system to be cyber resilient, supporting Transformation Directorate's purpose of delivering the best care and outcomes for the NHS.

The Cyber Operations sub-directorate consists of four operational areas:

  • Cyber Security Operations Unit (CSOU & SIO)
  • Cyber Delivery Unit (CDU)
  • Cyber Improvement Programme
  • Chief Information Security Office Function (CISO)

This is for a role within the NHS England CSOC, the Cybersecurity Operations Centre with a national remit across publicly funded healthcare in England.

Please be aware that should you be successful in this position, you will be hired to the job title of Security Officer and this job title is advertised to attract the right skills needed for the role

The post of Security Officer has been awarded a Recruitment and Retention Premia (RRP) in response to current labour market conditions. In recognition of this, the role attracts an additional monthly RRP payment equal to 10 % per annum.

Please be aware that RRP is none contractual and subject to review.

Please be aware that should you be successful in this position, you will be hired to the job title of Security O

Join the community to read the full pack, responsibilities and person-specification in one place.

Your seat is reserved — activate it

CareerHive is included with your CareerHive Skool community membership. If you haven't claimed your account yet, join the community (or sign in with the same email you joined with) to unlock the full advert, the apply link, HiveMind AI interview & application suite, your private vault, and daily sponsorship alerts.