Back to search

Security Analyst (Incident Response Lead)

Civil Service

Job Description

Job summary

The Cabinet Office supports the Prime Minister and ensures the effective running of government. It is also the corporate headquarters for government, in partnership with HM Treasury, and takes the lead in certain critical policy areas.

The Cyber Defence team delivers cyber threat intelligence, threat detection and incident response capabilities for the Cabinet Office, and is responsible for defending both internal IT infrastructure and citizen-facing services. As an Incident Response Lead, youll take a primary role in building and delivering these core capabilities, focusing on managing and responding to incidents.

IMPORTANT: SECURITY VETTING

This role requires SC (Security Check) which will be conducted by the NSV (National Security vetting). You need to have been resident in the UK within the past five years in order to apply. Here is a short video why this is necessary.

Job description

As an Incident Response Lead, you will:

  • Lead the investigation of security alerts to understand the nature and extent of possible cyber incidents
  • Lead the forensic analysis of systems, files, network traffic and cloud environments
  • Lead the technical response to cyber incidents by identifying and implementing (or coordinating the implementation of) containment, eradication and recovery actions
  • Support the wider coordination of cyber incidents
  • Review previous incidents to identify lessons and actions
  • Identify and deliver opportunities for continual improvement of the incident response capability
  • Work closely alongside other Cyber Defence functions, supporting the continual improvement of wider capabilities
  • Develop and update internal plans, playbooks and knowledge base articles
  • Act as an escalation point for, and provide coaching and mentoring to, security analysts
  • Be responsible for leadership and line management of security analysts

Cyber incidents can and do arise on a 24/7 basis. The team operates an out-of-hours on call rota, which you will be expected to join.

Person specification

Essential criteria

Were interested in people who have:

  • Significant experience investigating and responding to cyber incidents
  • Significant experience using security tools (e.g., EDR, SIEM) to support the investigation and response to cyber incidents
  • Experience managing and coordinating the response to cyber incidents
  • Experience coaching and mentoring junior staff
  • An in-depth understanding of the tools, techniques and procedures used by threat actors
  • Excellent analytical and problem-solving skills
  • Excellent verbal and written communication skills

Desirable criteria

Its desirable, but not essential, that you have:

  • Experience with Splunk
  • Experience working in an Agile environment
  • Experience with cloud environments such as AWS

Additional information:

A minimum 60% of your working time should be spent at your principal workplace. Although requirements to attend other locations for official business will also count towards this level of attendance.

Yodel are hiring now

Working at Yodel, they promise to support you, develop you and give you all the tools you need to do a great job. They have a range of opportunities across the UK now - why not see if Yodel have the perfect role for you?

See Yodel jobs

Good luck with your application