Skip to main content
Posted 28 July, 2026
Government Digital & Data

Cyber Security Analyst - Medr - HEO

Wales, UK Hybrid Full Time
Salary: £39,457 to £46,243 Annually

Location

Aberystwyth, Cardiff, Llandudno Junction, Merthyr Tydfil, Swansea

About the job

Job summary

About Us

We are an arm’s length body of the Welsh Government, responsible for the strategy, funding and oversight of:

  • further education
  • higher education including research and innovation;
  • apprenticeships
  • adult community learning; and local authority maintained school sixth forms.

We work in close collaboration with our partners to enable a tertiary education and research system which is centred around the needs of learners; society; and economy with excellence, equality and engagement at its heart.

Our values really matter to us, they help shape the culture of our organisation:

  • Dysgu (to learn; to teach; to educate) - learning is at the heart of everything we do. We believe curiosity fuels innovation and helps expand our horizons.
  • Cydweithio (to work together; to collaborate; to co-operate) - we can achieve far more together than we ever could alone.
  • Cynnwys Pawb (to include everyone; to involve everyone) - we are passionate about inclusion, seeking to create the right conditions for everyone to achieve their full potential.
  • Rhagori (to exceed; to excel) - we have high aspirations for tertiary education and research in Wales and always set high standards for ourselves to be the best we can be.

We are proud to be a Disability Confident employer and accredited as a Living Wage employer.

Location

Our headquarters is in 2, Capital Quarter, Cardiff, which has been specifically designed to meet our needs. This is where most colleagues will meet to collaborate, both with each other and with stakeholders.

As we operate across Wales, we also have limited office and collaboration space in Welsh Government offices in Llandudno Junction, Aberystwyth, Swansea and Merthyr Tydfil.

Main purpose of the job

The Cyber Security Analyst is responsible for safeguarding Medr’s digital assets by monitoring, analysing, and responding to cyber threats across its systems and services. The role ensures effective security controls are implemented in line with security policies and latest standards, supports secure system and service design, and undertakes real-time threat analysis, risk assessments and incident investigations. The role is critical to maintaining the confidentiality, integrity, and availability of Medr’s data and infrastructure, while supporting the resilience of its digital operations in an evolving threat landscape.



Job description

What you'll be doing

  • Monitor, detect, and respond to cyber threats by conducting real‑time security monitoring, threat hunting, forensic investigations, and timely system patching to protect systems, networks, software, and data.
  • Identify and mitigate security risks and vulnerabilities through software risk assessments, continuous infrastructure monitoring, audits, and validation activities to ensure data integrity, timeliness, and completeness.
  • Design and enforce robust security controls and policies, embedding security into systems and application design and ensuring compliance with Cyber Essentials Plus and IASME Level 2 standards.
  • Manage access and permissions by maintaining strong user access controls and administrative privileges to prevent unauthorised access and data breaches.
  • Promote a strong security culture by delivering employee training and awareness programmes, supporting and challenging users where necessary, and encouraging continuous improvement and compliance with data standards.
  • Collaborate and communicate effectively with Digital teams, management, external suppliers, and stakeholders, maintaining up‑to‑date security documentation, producing security papers, and reporting progress and key challenges to senior leadership.

Key challenges you will face

  • Working in a fast-paced environment, with competing priorities and critical deadlines.
  • Ensuring that data governance and management approaches align with business needs, compliance requirements and best practice.
  • Integrate with a shared SOC/MDR service.
  • Incident response under pressure.
  • Preparing and participating in numerous audits where compliance is critical to the business function.
  • Sector collaboration by securing credibility and trust with a range of stakeholders.

About your team

The Digital Directorate within Medr spans three core areas: Development, Information Systems, and IT Security & Technical Services. Together, we design and manage systems, develop applications and ensure robust security, governance and compliance is in place.

The Cyber Security Analyst will report directly to the Senior Technical Services Manager who also manages the IT Support Manager and Officer posts. The team will be led by the Head of IT Security and Technical Services.

About your line manager

The Senior Technical Services Manager brings over 25 years of digital experience and has been with HEFCW, Medr’s predecessor, since 2019, having seconded from a local Governments Network Team. As lead Technical Architect, he had a key role in the design and implementation of Medr’s IT environments, security profile, corporate IT systems, client solutions, data management processes, governance controls, and IT risk management.

Person specification

What you'll bring

Attributes

  • Drive: You lead by example, showing dedication and perseverance in meeting organisational objectives..
  • Agile: You drive forward improvements, through collaboration, embracing new technologies and nurturing a culture of continuous learning.
  • Resilient : You lead with resilience in terms of uncertainty and change, inspiring your team to persevere despite obstacle
  • Dynamic - You encourage a culture of innovation and continuous improvement, encouraging experimentation and learning.

Experience

  • Technical experience in securing Microsoft Azure and Office 365 environments, with hands-on knowledge of cloud security tools such as Microsoft Sentinel, Purview or Microsoft Defender for Endpoint/Cloud SIEM tools. Capable of analysing and interpreting security events and logs, and performing digital forensics tasks. Experienced in responding to threat intelligence and vulnerability management platforms.
  • Demonstrates comprehensive understanding of cybersecurity frameworks, regulatory compliance requirements such as UK GDPR and the Data Protection Act 2018, and expertise with security technologies including firewalls, VPNs, and intrusion detection/prevention systems. Possesses strong analytical, communication, and problem-solving abilities, as well as proficiency in preparing clear and effective technical and non-technical reports.

Welsh language requirements

We have evaluated that the Welsh language requirements for this post are:

Desirable: Welsh desirable means that while having Welsh language skills is useful for the role, it is not an assessment criterion, so it won’t disadvantage you during recruitment if you don’t currently possess these skills.



Qualifications

A bachelor's degree in computer science, cybersecurity, or a closely related field is typically required; postgraduate qualifications or professional certifications (e.g., CISSP, CISM, CompTIA Security+) or several years of relevant experience in information security, network administration, or IT risk management.

Sign up for Job Alerts