Cyber & Specialist Operations Command (CSOC) PSYA - SECURITY INCIDENT MANAGEMENT ADVISOR
- Civil Service
- Full Time
- Northwood
- 30,740
Job Description
Job summary
The Security Incident Management Advisor role is part of a small, busy team comprising The Warning, Advice and Reporting Point (WARP). This is CSOCs focal point for all security incidents within the Command. You will triage/ record incidents, direct investigations and move reports onward to relevant departments. You will carry out data/ trend analysis, identify lessons to influence policy and allow CSOC Sub-Commands to understand their strengths and weaknesses in security.
This post sits within the Principal Security Advisor (PSyA) team which provides advice to Commander CSOC (4*) on all security issues relating to the command, including advising on HMG and MOD security policy; evaluating security risks and protective measures; and strategic oversight of all security activities across CSOC sites, units, and personnel worldwide. In addition, advice, direction, and support are given to the constituent organisations as and when required.
The WARP is the main point of contact for all general security questions and is responsible for ensuring security messaging is disseminated to Sub-Commands and formations in varying threat environments around the globe.
Working in a mixed civilian and military team, you will need to be flexible and adaptable, able to act on your own initiative, and quickly develop good working relationships with a wide range of customers.
Being embedded within a team of security experts will enable you to gain a range of knowledge and experience of how security functions in a complex and challenging environment. With exposure to the functioning of Defence, HQ CSOC, and the constituent organisations, you will gain valuable knowledge and experience across a range of security specialisations.
This position is advertised at 37 hours per week.
Job description
You will directly assist the WARP Team Lead and PSyA by:
- Operating the CSOC Warning, Advice, and Reporting Point (WARP), the single point for the issuing
of security messages across CSOC and for the receiving of security incident reports via Security Incident reporting form (SIRF).
Triaging the security incidents and tasking the security investigations to relevant Sub-Command.
Managing the Incidents life cycle and making sure the incidents are brought to closure after successful investigations.
- Conducting statistical analysis, utilising Excel, and other tools, of the number and type of security
incidents in order to identify any patterns and trends.
- Assisting in the management of investigations into security breaches, incidents, and near misses
and to ensure that lessons are learned, and improvements made to mitigate against re-occurrence.
For example, this can include but is not limited to incidents concerning.
- Loss (of, for example, classified information, personal information, ID cards)
- Theft (of, for example, classified information, personal information, keys to secure office)
- Breach of security policy
- Incorrect transmission of classified information
- Insecure classified information (security cabinets/offices left open)
- Security incident concerning MOD Computer Networks
- Hostile Reconnaissance
- Intrusions onto Defence Property
- Loss/Theft/Recovery of Items Attractive to Criminal and Terrorist Organisations (ACTO)
- Assisting in delivering and fostering a strong security culture across the command, which values, protects,
and enables CSOC and wider Defence.
- Assisting team members on a range of security enquiries, tasks, or projects.
- Providing an office management function to ensure that requests for security advice are triaged in a timely manner and passed to the appropriate team member.
- Assisting in the general functioning and administration of the team.
- Some UK travel may be required.
*Note - Participation in the out-of-hours duty roster is required on a rotational basis.
Person specification
The position requires an enthusiastic individual with strong interpersonal, organisational and collaborative skills to be part of a small but highly motivated and energetic team.
The post holder will be required to prioritise and manage a busy workload and high volume of throughput, whilst balancing business needs.
The ability to understand the nature and severity of security breaches/ incidents, apply a triage process and direct counter compromise, impact assessment and investigative activity is therefore essential.
The post holder must be suitably qualified and experienced to make sound breach management assessments and judgements, utilising all available information to ask the right questions and direct the correct response actions within specified timescales.
The WARP utilises a cross-government incident management system and the post holder will be required to input and extract data, upload reports and other relevant document sets and maintain oversight of the status of incidents through life to closure.
This post is only applicable for Sole UK nationals