Back to search

Cyber Security Operations Support Analyst

  • NHS
  • Part Time
  • Birmingham
  • 41983.00 - 52113.00 a year
NHS

Job Description

Job summary

Do you have a passion for Cyber Security?

Do you have experience as a cyber security professional, working as part of a Security Operationsteam?

Are you interested in working for an organisation that truly champions a healthy work/life balance?

If so, continue reading to find out more about this fantastic opportunity to join UKHSA Cyber Security. Now is a great time to join us as we establish a team of outstanding people in the field of Cyber Security Operations. This is a chance to work on services that matter and affect the lives of millions of citizens.

UKHSA's Cyber Security Operations team is responsible for the operational cyber security of UKHSA. We are looking for an enthusiastic Cyber Security Operations Team Member, with great technical and collaborative skills. In this role you will participate in areas such as security engineering, protective monitoring, vulnerability management and incident response.

Main duties of the job

Reporting to a Cyber Security Operations Team Lead you will be a part of the UKHSA Security Operations team, to ensure effective delivery of security operations projects and BAU delivery into the business. You will also support in complex incident management, including response activities, working with technical staff and suppliers to detect, contain and remediate security events and risks.

The role can be fast paced and reactionary when dealing with a live incident. You will manage networks of internal and external stakeholders. You will have a technical background in cyber security operations, with some knowledge of key security technologies, frameworks and best practices.

About us

We pride ourselves as being an employer of choice, where Everyone Matters promoting equality of opportunity to actively encourage applications from everyone, including groups currently underrepresented in our workforce.

UKHSA ethos is to be an inclusive organisation for all our staff and stakeholders. To create, nurture and sustain an inclusive culture, where differences drive innovative solutions to meet the needs of our workforce and wider communities. We do this through celebrating and protecting differences by removing barriers and promoting equity and equality of opportunity for all.

Please visit our careers site for more information https://gov.uk/ukhsa/careers

Job responsibilities

The successful individual will be expected to carry out all functions in all of the Operations Role Family outlined in Government Security Profession Career Framework, including:

Monitoring

  • Monitor, triage and investigate security alerts on protective monitoring platforms to identify security incidents and perform analysis of security event data to support the response, reporting or escalating where appropriate.
  • Design, develop and support automated monitoring processes, using a variety of the latest SIEM (Security Information and Event Management) and network analysis tools, techniques and procedures to detect malicious activity and ensure continuous improvement through dashboard monitoring or retrospective assessment

Response

  • Carry out UKHSAs response policies and processes to meet the needs in line with appropriate standards
  • Provide standardised advice on mitigation, escalating to a team leader where appropriate

Vulnerability Management

  • Triage and prioritise vulnerabilities, implement mitigating measures, and support in the life cycleof vulnerability management, providing standardised advice on ways to improve control mechanisms and mitigate risk
  • Communicate common mitigation strategies such as patching and basic configuration change (system hardening)

Digital Forensics

  • Support the application of forensic readiness policy and work with other teams to ensure its implementation
  • Analyse evidence to identify breaches of policy, regulation or law

In addition to the above core skills the successful individual will be expected to:

  • Contribute to strong operational relationships with internal cyber security, technology, and privacy teams to maintain efficient communication and collaboration on security issues.
  • Any other responsibilities appropriate for this grade. Cyber Security Operations can be fast paced and will require a degree of flexibility.

This list is not exhaustive.

Before submitting your application, please take a moment to review the Essential Criteria and Security Clearance sections to confirm that you meet the eligibility requirements for this position. This will help ensure your application can be fully considered.

Essential criteria

  • An interest in cyber security
  • A proactive approach to investigating data in a work or educational environment
  • Demonstrable ability to analyse and interpret data
  • Effective verbal and written communication skills
  • Knowledge of Common Security Vulnerabilities (CVEs) and remediation techniques
  • Solid operational knowledge of working with Threat Intelligence Platforms, SIEM appliances, or intelligence feeds that have been acquired in large organisations
  • Experience with large LANs and cloud environments, preferably AWS/Azure

Selection Process Details

This vacancy is using Success Profiles and will assess your Behaviours, Experience and Technical skills.

Stage 1: Application & Sift

You willbe requiredto complete an application form. You will be assessed onthe listed 7 essential criteria,and this will be in the form ofa:

  • Application form(Employer/ Activity history section on the application)
  • 750 word supporting statement.

This should outline how you consider your skills,experienceandknowledgeprovide evidence of your suitability for the role, with reference to the essential criteria.You will receive a joint score for your application form and statement. (The application form is the kind of information you would put into your C.V please beadvisedyou will not be able to upload your CV. Please complete the application form in as much detail as possible). Please do not email us your CV.

HealthjobsUK has a word limit of 1500, but your supporting statement must be no more than 750 words. We will not consider any words over 750 words.

Longlisting

In the event ofa large number of applications we will longlist into 3 piles of:

  • Meets all essential criteria
  • Meets some essential criteria
  • Meets no essential criteria

If used, the pile Meets all essential criteria willproceedto shortlisting.

Shortlisting

In the event ofa large number ofapplications wemay conductan initialsift, on the lead criteria of:

  • Solid operational knowledge of working with Threat Intelligence Platforms, SIEM appliances, or intelligence feeds that have been acquired in large organisations
  • Demonstrable ability to analyse and interpret data

Desirable criteria may be used in the event ofa large number ofapplications/largeamountof successful candidates.

If you are successful at this stage, you will progress to interview & assessment.

Feedback will not be provided at this stage.

Stage 2:Interview

You will be invited to a single remote interview.

Behaviours, Experience and Technical skillswill be tested at interview.

There will be a 5-10 minute Presentation. The presentation topic will be "How AI is Transforming Both Cyber Threats and Security Operations"

The Behaviours tested during the interview stage will be:

  • Managing a quality service (Lead Behaviour)
  • Making effective decisions
  • Delivering at pace
  • Working together

Interview dates are to be confirmed.

Once this job has closed, the job advert will no longer be available. You may want to save a copy for your records.

Location

This role is being offered as hybrid working based at any of our Core HQs. We offer great flexible working opportunities at UKHSA and operate using a hybrid working model where business needs allow. This provides us with greater flexibility about how and where we work, to get the best from our workforce. As a hybrid worker, you will be expected to spend a minimum of 60% of your contractual working hours (approximately 3 days a week pro rata, (averaged over a month) working at one of UKHSA's core HQs (Birmingham, Leeds, Liverpool, and London). Our core HQ offices are modern and newly refurbished with excellent city centre transport links and benefit from co-location with other government departments such as the Department for Health and Social Care (DHSC).

Security Clearance Level Requirement

Successful candidates must pass an basic disclosure and ...

Good luck with your application