Skip to content
← Back to job listings

Cyber Investigations Manager

Scottish Government Recruitment · Glasgow, United Kingdom

CybersecurityExternal listingfull-timeabout 2 hours ago

About The Role

Lead cyber investigations that help protect critical Scottish Government information and services.

The Cyber Investigation Manager role sits within the Cyber Security Unit (CSU) and are responsible for protecting the confidentiality, integrity and availability of Scottish Government information and information systems. You will join a highly skilled cyber team working across a large and complex technology landscape, helping to strengthen resilience against evolving cyber threats.

This role offers the opportunity to take lead on significant cyber investigation, incident response and security improvement activity that has a direct impact on public services used across Scotland. You will work with a wide range of technical and business stakeholders, shape how incidents are investigated and managed, and help drive improvements to cyber security capability. Alongside interesting technical challenges, Scottish Government offers a 35-hour working week, flexible hybrid working, strong pension benefits and the opportunity to make a meaningful public impact while maintaining a healthy work-life balance.

Please note : This role is based at Saughton House, Edinburgh only, and not Glasgow as may be displayed above.

Responsibilities

  • Champion incident management, incident investigation and response policy and/or incident management and investigation processes, procedures and systems.
  • Produce and facilitate cyber security exercising for customers to ensure a robust and effective incident management and technical response capability.
  • Leads on Data Loss Prevention (DLP) projects to reduce the capability of data leaks of government information through official tools.
  • Deliver specific pieces of work resulting from the Cyber Security Strategy, related to cyber business risk and information control/protection requirements.
  • Contributes to the development of cyber security policy, standards, and guidelines appropriate to business, technology and legal requirements.
  • Maintains current knowledge of malware attacks, and other cyber security threats.
  • Maintains knowledge of specific specialisms, provides detailed advice regarding their application, and executes specialised tasks.
  • Explains the purpose of, and provides advice and guidance on, the application and operation of elementary physical, procedural and technical security controls.

Success Profile

Success profiles are specific to each job and they include the mix of behaviours, experience and technical criteria (if applicable) that candidates will be assessed on.

Experience

  • You are a subject matter expert in developing and operationalising techniques for Cyber Security operations, e.g. detecting anomalous activity, automating orchestration and configuration of IT or have experience in identifying the need for, and implementing, new security operating procedures and practices to meet changing requirements.
  • You have experience of managing incidents, reporting on and bringing investigations to a successful conclusion which allows you to advise on response best practice.
  • You have experience of delivering or reviewing risk assessments using appropriate risk assessment methods for common scenarios such as enterprise IT systems and have a good understanding how assessed risks are addressed.
  • You have advanced knowledge of system architectures in order to articulate the impact of vulnerabilities on existing and future designs and systems.

Experience is assessed at sift, along with a more in-depth assessment at interview.

Behaviours

  • Making Effective Decisions (Level 3)
  • Communicating and Influencing (Level 3)
  • You can find out more about Success Profiles Behaviours, here .
  • Behaviours are assessed at interview. Full details will be shared in advance with all candidates invited to this stage.

Technical Skills

This role is aligned to the Lead Cyber Security Analyst job role within the Cyber Security and Information Assurance job family.

  1. Cyber security operations

Expert

  1. Incident management, incident investigation and response

Expert

  1. Information risk assessment and risk management

Practitioner

  1. Penetration testing Practitioner Specific security technology and understanding

Practitioner

You can find out more about the skills required, here: GDD Profession - Scottish Digital Academy.

These skills are assessed by technical assessment, designed to represent the role. Candidates reaching this stage will receive a Technical Assessment Candidate Pack which outlines the specific skills to be assessed, plus the method of assessment.

How to apply

Apply online, providing a CV and Supporting Statement (of no more than 750 words) which provides evidence of how you meet each of the 4 Experience criteria listed in the Success Profile above.

Candidates will have their applications assessed against all Experience criteria.

Artificial Intelligence (AI) tools can be used to support your application, but all statements and examples provided must be truthful, factually accurate and taken directly from your own experience. Where plagiarism has been identified (presenting the ideas and experiences of others, or generated by artificial intelligence, and presented as your own) applications will be withdrawn and internal candidates may be subject to disciplinary action.

Please see our candidate guidance for more information on acceptable and unacceptable uses of AI in recruitment.

If invited for further assessment, this will consist of an interview and Government Cyber Profession Technical assessment where the behaviours, experiences and technical skills outlined in the Success Profile will be assessed.

The sift is scheduled for w/c Monday 14th September .

Interviews and Technical assessments are scheduled for w/c Monday 5th October , however these may be subject to change.

Recruitment Principles

As a government organisation, we adhere to the Civil Service Commission Recruitment Principles and we investigate any complaints received in relation to recruitment cases.

About us

The Scottish Government is the devolved government for Scotland. We have responsibility for a wide range of key policy areas including: education, health, the economy, justice, housing and transport. We offer rewarding careers and employ people across Scotland in a wide range of professions and roles.

Our staff are part of the UK Civil Service observing the Civil Service Code and working for Ministers and senior stakeholders to deliver vital public services which improve the lives of the people of Scotland.

We offer a supportive and inclusive working environment along with a wide range of employee benefits. Find out more about what we offer .

As part of the UK Civil Service, we uphold the Civil Service Nationality Rules .

Working pattern

Our standard hours are 35 hours per week and we offer a range of flexible working options depending on the needs of the role, including Flexi-leave. Scottish Government staff in hybrid-compatible roles should aim to work in-person 40% of the time, either in an office or other agreed work location. If you have specific questions about the role you are applying for, please contact us.

If you have specific questions about the role you are applying for, please contact [email hidden] .

Security checks

This role requires National Security Vetting (NSV) at Developed Vetting (DV) level. Appointment to the post will be subject to successfully obtaining and maintaining DV clearance.

To support the vetting process, candidates will normally need to have lived in the UK for a sufficient period to allow the necessary checks to be carried out. In most cases, this means having been resident in the UK for at least the previous five years. Further information can be found here .

Government, Digital and Data Profession

The Government Digital and Data (GDD) Profession is a UK-wide group of over 24,000 civil servants dedicated to driving digital transformation in government through more efficient, data-driven public services. This community oversees a wide range of responsibilities, including architects, data scientists, engineers, and content designers, across different, multidisciplinary teams.

The profession, sponsored by the Government Digital Service (GDS), offers the frameworks, skills, and development routes necessary for these individuals to thrive and produce improved outcomes for the public.

In Scotland, cyber roles are attached to the Profession as an additional job family. Details of these roles and associated skills can be found on the beta site UK Government Cyber Profession.

Pay Supplement

This post is part of the Government Digital and Data (GDD) profession and currently attracts a £4,000.00 annual GDD pay supplement, which is paid monthly – pay supplements are reviewed regularly.

Equality Statement

We are committed to equality and inclusion, and we aim to recruit a diverse workforce that reflects the population of our nation.
Find out more about our commitment to diversity and how we offer and support recruitment adjustments for anyone who needs them.
Further information
Find out more about our organisation, what we offer staff members and how to apply on our Careers Website .
Read our Candidate Guide for further information on our recruitment and application processes.
Apply before: 13/09/2026 (23:59). This role is open to internal candidates and Common Citizenship organisations only.
If you would like to learn more about the role before submitting an application, or if you have any questions, please contact:

Contact Name : John Mackay

Contact e-Mail: [email hidden]

This is an external listing. JobSpring does not represent or verify the employer. Report this listing