Back to search

Cyber Security Engineer (SOC)

Civil Service

Job Description

Job summary

Here at the Ministry of Housing, Communities & Local Government (MHCLG), we work on things that make a real difference to peoples lives. Whether it's through the homes we live in, the work of our local councils, or the communities were all part of, our work is at the top of the political agenda. We have ambitious and far-reaching outcomes to achieve this year and, if youre thinking of joining us, theres never been a more exciting time.

Join the frontline of cyber defence and help protect the systems, services and data that support communities across the UK. As a SOC Engineer, you'll play a key role in enhancing the department's security monitoring and detection capabilities across a modern multi-cloud environment spanning Microsoft Azure, Microsoft 365 and AWS. Working within the Cyber Security Operations Centre, you'll design and improve detections, onboard new data sources, develop security automations, support threat hunting activities, and help ensure visibility across critical services and platforms.

You'll work with industry-leading technologies such as Microsoft Sentinel, Defender XDR and cloud-native security tooling to strengthen the department's cyber resilience. While you'll occasionally support the investigation of security incidents and emerging threats, the primary focus of the role is to continuously improve the SOC's ability to detect, monitor and respond to cyber risks through engineering, automation and operational excellence. Whether you're refining detection logic, integrating new services, developing automation workflows, or enhancing monitoring coverage, you'll help shape the future of cyber defence within MHCLG.

Find out more about our Digital teams and what they are working on through our MHCLG Digital blog. Please note that MHCLG do not offer visa sponsorship and applicants will need a valid visa for the duration of your employment.

Job description

This role is ideal for someone who enjoys solving complex security challenges, building detection capabilities, automating operational processes and continuously improving cyber defence within a modern cloud-first environment.

As a Cyber Security Engineer (SOC), you'll:

  • Be responsible for enhancing and maintaining the department's cyber monitoring and detection capabilities across Microsoft Azure, Microsoft 365 and AWS
  • Develop, tune and maintain security detections, analytics rules and alerting use cases within Microsoft Sentinel and associated security platforms
  • Onboard new data sources and services into the SOC monitoring estate, ensuring effective visibility and coverage across cloud and on-premises environments
  • Design and implement automation and orchestration solutions to improve SOC efficiency and reduce manual effort
  • Conduct proactive threat hunting activities to identify malicious, suspicious or anomalous activity across the estate
  • Continuously improve security monitoring capabilities by identifying gaps, refining detection logic and enhancing security controls
  • Support the engineering, configuration and optimisation of SOC tooling, including SIEM, EDR and cloud security technologies
  • Produce operational documentation, detection runbooks and technical procedures to support SOC operations
  • Analyse emerging threats, vulnerabilities and attack techniques, translating intelligence into effective monitoring and detection capabilities
  • Collaborate with infrastructure, cloud, platform and application teams to ensure new services are designed with appropriate security monitoring and logging requirements
  • Provide technical expertise and occasional support during security investigations and incident response activities when required

Person specification

As a Cyber Security Engineer (SOC), you'll have:

  • 3 Years experience of monitoring, analysing and investigating security events across cloud and enterprise environments
  • Experience in creating, tuning and optimising security detections, analytics rules and monitoring use cases
  • Demonstrable experience of onboarding new data sources and services to improve SOC visibility and threat detection coverage
  • Experience of developing automation and process improvements to enhance SOC efficiency and effectiveness
  • 3 Years experience supporting SOC operations and assisting with security incident response activities
  • Experience mentoring and supporting junior analysts, helping to develop cyber security capability across the team
  • Experience contributing to the development of an exemplar Government Security Operations Centre through innovation, continuous improvement and operational excellence

Yodel are hiring now

Working at Yodel, they promise to support you, develop you and give you all the tools you need to do a great job. They have a range of opportunities across the UK now - why not see if Yodel have the perfect role for you?

See Yodel jobs

Good luck with your application