Head of Security Operations & Incident Management
- Civil Service
- Part Time
- Bristol
- 67,126 - 77,813
Job Description
We're seeking a dynamic leader to join the GDS Information Security team as our Head of Security Operations and Incident Management, playing a central role in safeguarding the information and privacy of millions of UK people.Your job will be to manage the response procedures and investigations of security events at GDS, including incidents identified within our flagship digital services. Working with delivery teams, youll contain and remediate those incidents, identify potential process improvements, and maintain organisational readiness. You will also advise product and service owners of potential mitigations, working with our cyber assurance experts.While GDS is primarily a digital and engineering-focused organisation and this is a cyber-focused role, as our incidents lead you will also manage incidents related to potential personnel, technical and physical security breaches, working with the appropriate stakeholders.Specifically, you will:shape GDSs response policies and processes to ensure that these meet our evolving needs, in line with appropriate government and other standardscommunicate with a broad range of senior stakeholders and be responsible for defining the vision, principles and strategy for incident responseaggregate and evaluate post-incident feedback to inform board-level reporting on security incidentsbecome a recognised expert and adviser to investigators and senior leadership across GDS and across governmentlead monitoring, triaging, and investigation of security alerts on protective monitoring platforms to identity security incidentsreview high-priority or high-complexity analysis of security event data to manage security incident response, making key decisions on reporting or escalations for monitoringlead cross-functional monitoring at GDS in the design, development and enablement of automated monitoring processes, advising on the latest Security Information and Event Management (SIEM) and network analysis tools, techniques and procedures to detect malicious activity