Senior Cyber Security Engineer
United Kingdom
Department for Business and Trade
About us The Department for Business and Trade (DBT) has a clear mission - to grow the economy. Our role is to help businesses invest, grow and export to create jobs and opportunities right across the country. We do this in three ways. Firstly, we help to build a strong, competitive business environment, where consumers are protected and companies rewarded for treating their employees properly. Secondly, we open international markets and ensure resilient supply chains. This can be through Free Trade Agreements, trade facilitation and multilateral agreements.Finally, we work in partnership with businesses every day, providing advance, finance and deal-making support to those looking to start up, invest, export and grow. The Digital, Data and Technology (DDaT) directorate develops and operates tools and services to support us in this mission. About the role This Role sites within the Department for Business and Trade’s SOC (Security Operations Centre), reporting to the Principle Cyber Engineer. The SOC is responsible for identification and mitigation of threats, both internal and external to the security of DBT. This role is to support these actions by creating new capabilities, supporting existing capabilities and providing expertise to analysts when required. Focusing on supporting the delivery of the monitoring and development aspects of DBT’s TOM (Target Operating Model), this role will involve development of security tools, providing cyber security advice to the development community in DBT to ensure best practice is being followed. This role will be suitable for an individual with a DevSecOps (Development and Security Operations) background or someone who has skills in both software development and Cyber Security. Main responsibilities You will be:
- Supporting the Principle Cyber Security Engineer and SOC Manager in the implementation of the monitoring and improvement roadmap
- Identifying areas of improvement within the SOC and building a plan to implement the improvement.
- Testing and Implementing changes within multiple Cloud Environment.
- Producing software documentation to accurately represent the system that has been implemented and its current state for other engineers to use and rely on.
- Updating and maintaining existing tools and infrastructure.
- Facilitating the ingestion and enriching new logging services into the SIEM (Security Incident and Event Management) Tool for the analysts.
- Maintaining the pipelines and infrastructure that is facilitating the ingestion of logs and processing logs.
- Being able to assist with active investigations that and provide expert knowledge to assist analysts.
- Creating Playbooks for creating new capabilities and documentation for maintaining new capabilities.
- Demonstratable experience configuring Security related tools and implementing security policies.
- Demonstratable experience in configuring AWS or Azure policies and infrastructure.
- Demonstratable experience working with a SIEM tool (Microsoft Sentinel, Splunk, etc.)
- Demonstratable skills with cloud environments, underlying logging systems and mechanisms.
- Understanding threats to an organisation and how they can be mitigated using tools.
- Knowledge of Azure and configuring Microsoft Security products
- Knowledge of using Python
- Threat Understanding
- Secure Operations Management
- Intrusion Detection and Analysis
- Information Risk Assessment and Risk Management
- Cyber Security Operations
- Making Effective Decisions
- Delivering at Pace
- Managing a Quality Service
- departmental or company records (personnel files, staff reports, sick leave reports and security records)
- UK criminal records covering both spent and unspent criminal records
- your credit and financial history with a credit reference agency
- security services record
- location details
- learning and development tailored to your role
- a flexible, hybrid working environment with options like condensed hours
- a culture encouraging inclusion and diversity
- a Civil Service pension with an average employer contribution of 27%
- annual leave starting at 25 days rising to 30 days with service
- three paid volunteering days a year
- an employee benefits programme including cycle to work
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Job stats:
0
0
0
Category:
Security Engineering Jobs
Tags: AWS Azure Clearance Cloud DevSecOps Finance Intrusion detection Monitoring Python Risk assessment Risk management Sentinel SIEM SOC Splunk
Perks/benefits: Career development Flex hours Startup environment
Region:
Europe
Country:
United Kingdom
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.
Senior Cloud Security Engineer jobsInformation System Security Officer jobsInformation Systems Security Officer jobsInformation Security Manager jobsSenior Network Security Engineer jobsSenior Cybersecurity Engineer jobsInformation Security Specialist jobsSecurity Consultant jobsSecurity Specialist jobsSenior Information Security Analyst jobsSenior Penetration Tester jobsIT Security Engineer jobsCyber Security Specialist jobsSenior Cyber Security Engineer jobsChief Information Security Officer jobsPrincipal Security Engineer jobsIT Security Analyst jobsStaff Security Engineer jobsInformation System Security Officer (ISSO) jobsCloud Security Architect jobsCyber Security Architect jobsSecurity Operations Analyst jobsSystems Administrator jobsSenior Information Security Engineer jobsThreat Intelligence Analyst jobs
GDPR jobsSaaS jobsEncryption jobsForensics jobsTop Secret jobsEDR jobsSDLC jobsMalware jobsRMF jobsSplunk jobsSQL jobsIDS jobsIPS jobsBash jobsCompTIA jobsIntrusion detection jobsDocker jobsDoDD 8570 jobsFinance jobsITIL jobsThreat detection jobsOWASP jobsTerraform jobsTCP/IP jobsCRISC jobs
Active Directory jobsGIAC jobsVPN jobsClearance Required jobsIT infrastructure jobsUNIX jobsBanking jobsSANS jobsJavaScript jobsJira jobsHIPAA jobsAnsible jobsDNS jobsPolygraph jobsOSCP jobsMITRE ATT&CK jobsSOX jobsData Analytics jobsMachine Learning jobsSOC 2 jobsSOAR jobsCCSP jobsGCIH jobsSecurity strategy jobsCISO jobs