Cyber Security Analyst
Job Description: HEO Associate Security
Analyst
Who we are
The Cabinet Office supports the Prime Minister and ensures the effective running of government. It
is also the corporate headquarters for the government, in partnership with HM Treasury, and takes
the lead in certain critical policy areas.
We are the Cabinet Office s Cyber and Information Security function. Our mission is to secure the
Cabinet Office s digital and information assets against misuse, and enable the secure delivery of
the department s mission. We do this by developing, operating, and governing the cyber and
information security controls which protect our nationwide internal IT infrastructure, and high-profile
citizen-facing digital services such as GOV.UK.
This role is within the Cyber Defence team, which is responsible for understanding, detecting and
responding to cyber threats and vulnerabilities impacting the Cabinet Office. This role is
responsible for supporting our alert triage and incident response capability.
What you ll do
As an associate security analyst you will:
triage and investigate cyber security alerts and reports from users
use a variety of techniques to analyse systems, files, network traffic and cloud
environments and understand the nature and extent of possible cyber incidents
support the technical response to cyber incidents by identifying and implementing (or
supporting the implementation of) containment, eradication and recovery actions
support the coordination of cyber incidents
contribute to post-incident reviews to identify lessons and actions
identify opportunities for, and support the delivery of, continual improvements to the
incident investigation and response capability
work closely alongside other Cyber Defence functions, supporting the continual
improvement of wider capabilities
contribute to internal plans, playbooks and knowledge base articles
act as an escalation point for, and provide coaching and mentoring to, apprentice security
analysts
be responsible for line management of apprentice security analysts
Cyber incidents can and do arise on a 24/7 basis. The team operates an out-of-hours on call rota,
which you will be expected to join.
Who you are
We re interested in people who have:
experience investigating and responding to cyber incidents
experience using security tools (e.g., EDR, SIEM) to support the investigation and
response to cyber incidents
Experience with SIEM tools (experience of Splunk preferred but experience of Microsoft
Sentinel or an equivalent SIEM tool is acceptable)
an understanding of the tools, techniques and procedures commonly used by threat actors
good analytical and problem-solving skills
good verbal and written communication skills
It s desirable, but not essential, that you have:
experience with Splunk
experience working in an Agile environment
experience with cloud environments such as AWS
Success profiles
We will be looking at your experience, career history and achievements relevant to this specific job
role. For this role, we will be assessing your ability, experience, technical/specialist skills and
behaviours; the following behaviours are the most relevant:
making effective decisions
changing and improving
working together
| Region try { var fgTooltip = new FG.Tooltip({ element: $('#cf_descz18051517413973032789902'), text: "Geographical\x20Region" }).initialize(); } catch(err) {} |
Additional Details
- Senior Interim Hire : No
- Region : Inner London
- Requisition Type : 1. New Requirement
- Name of Nominated Worker : (No Value)
- Please provide any additional information specific to this role : Day rate 600
- If any professional qualifications are required for the role, please list certificates here: : (No Value)
- Desired Skill 1 : TECH & DIGITAL|Cyber / Information Security
- Desired Skill 2 : (No Value)
- Desired Skill 3 : (No Value)
- Desired Skill 4 : (No Value)
- Desired Skill 5 : (No Value)
- Are there any Health and Safety requirements or hazards associated to this role? : No
- If yes, please specify the Health and Safety Considerations : (No Value)
- Is the role in or out of scope of IR35? : In Scope
- Level of screening : SC (Security Clearance)
- Internal Job Title : Associate Security Analyst
- Grade : HEO
- AMS Job Category : Technology|IT Risk/Security Analyst
- Equivalent Permanent Grade : Chief Digital Information Officer (CO CDIO)|HEO
- Armed Forces Covenant Signatory : Yes
- Disability Confident Level : Yes - Leader (L3)
- Business Unit Name Hierarchy : Cabinet Office|Chief Digital Information Officer|Chief Digital Information Officer
- Business Unit Code Hierarchy : CO|CO CHIO|CO CDIO