Threat and Vulnerability Analyst
United Kingdom
Department for Business and Trade
Export support for UK businesses – great.gov.uk
The Department for Business and Trade (DBT) has a clear mission - to grow the economy. Our role is to help businesses invest, grow and export to create jobs and opportunities right across the country. We do this in three ways. Firstly, we help to build a strong, competitive business environment, where consumers are protected and companies rewarded for treating their employees properly. Secondly, we open international markets and ensure resilient supply chains. This can be through Free Trade Agreements, trade facilitation and multilateral agreements. Finally, we work in partnership with businesses every day, providing advance, finance and deal-making support to those looking to start up, invest, export and grow. The Digital, Data and Technology (DDaT) directorate develops and operates tools and services to support us in this mission. The team have been nominated three times in a row for ‘Best Public Sector Employer’ at the Women in Tech awards! About the role You will be helping to protect DBT and the wider UK government from cyber threats in a fast paced and exciting role. Reporting to the Principal Cyber Threat and Vulnerability Manager, the Threat and Vulnerability Analyst will work with other members of the SOC and technical teams to execute operational threat and vulnerability management activities and help shape the development of DBT’s TVM program and capabilities. A healthy curiosity mindset will be essential, to actively go out and discover items of potential interest to the team. About you You will be an analytical thinker with good understanding of cyber threats and mitigation strategies, an adaptable team-player with a curious mindset, and possess strong communication skills to effectively collaborate with various teams across the organisation. Main responsibilities You will be:
- Supporting scoping and delivery activities of penetration tests, vulnerability assessments, security audits to ensure compliance and mitigation of risks.
- Structured Threat Hunting through proactively identifying and leveraging threat intelligence sources to inform threat and vulnerability mitigation measures.
- Working with key stakeholders to create and drive prioritisation of tracked vulnerabilities and maintaining updated vulnerability trackers to meet common organisational objectives such as policy compliance.
- Reviewing and analysing vulnerability data to identify trends and patterns, whilst improving organisation-wide knowledge and understanding of emerging threats.
- Disseminate and apply DBT’s vulnerability ratings to externally rated vulnerabilities to help the department prioritize remediation.
- Continuously research and investigate new and emerging vulnerabilities including Zero Day events, and participate in external security communities, sharing findings across the security functions.
- Research and assess emerging security threats and vulnerabilities affecting DBT.
- Experience working in an enterprise technology setting, preferably with experience working with or in Cyber Security
- Relevant degree or security qualification e.g. BSC. Cyber Security, CompTIA Security +, CEH, Pentest +, CCSP etc.
- Understanding of Cyber threat landscape, threat actors’ techniques, tactics, and procedures. Understanding of Vulnerability management principles
- Understanding of Threat hunting in a cloud-based environment including interpreting device and application logs from various sources in a cloud environment, and monitoring for emerging threat patterns and vulnerabilities.
- Familiarity with industry frameworks and standards such as NIST, OWASP, MITRE ATTACK, CIS etc.)
- Excellent written and verbal communication skills including the ability to relate technical information to a non-technical audience.
- Experience in vulnerability scanning and penetration testing
- Knowledge of a scripting language
- Penetration Testing
- Threat and Vulnerability Understanding
- Threat intelligence and assessment
- Cyber Security Operations
- Legal and regulatory
- Working Together
- Communicating and Influencing
- Delivering at Pace
- departmental or company records (personnel files, staff reports, sick leave reports and security records)
- UK criminal records covering both spent and unspent criminal records
- your credit and financial history with a credit reference agency
- security services record
- location details
- learning and development tailored to your role
- a flexible, hybrid working environment with options like condensed hours
- a culture encouraging inclusion and diversity
- a Civil Service pension with an average employer contribution of 27%
- annual leave starting at 25 days rising to 30 days with service
- three paid volunteering days a year
- an employee benefits programme including cycle to work
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Job stats:
1
1
0
Categories:
Analyst Jobs
Threat Intel Jobs
Tags: Audits CCSP CEH Clearance Cloud Compliance CompTIA Finance Monitoring NIST OWASP Pentesting Scripting SOC Threat intelligence Vulnerabilities Vulnerability management Zero-day
Perks/benefits: Career development Flex hours Startup environment Team events
Region:
Europe
Country:
United Kingdom
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.
Information Security Officer jobsSenior Cybersecurity Engineer jobsInformation System Security Officer jobsSenior Cloud Security Engineer jobsInformation Security Manager jobsInformation Security Specialist jobsCyber Security Specialist jobsSecurity Consultant jobsSenior Network Security Engineer jobsIT Security Engineer jobsSystems Engineer jobsSecurity Specialist jobsSenior Information Security Analyst jobsIT Security Analyst jobsSenior Cyber Security Engineer jobsChief Information Security Officer jobsSystems Administrator jobsSenior Penetration Tester jobsInformation System Security Officer (ISSO) jobsStaff Security Engineer jobsThreat Intelligence Analyst jobsSenior Product Security Engineer jobsInformation Systems Security Engineer jobsSecurity Operations Analyst jobsCloud Security Architect jobs
Encryption jobsForensics jobsJava jobsTop Secret jobsEDR jobsRMF jobsSaaS jobsGDPR jobsIDS jobsSplunk jobsDoDD 8570 jobsIPS jobsSQL jobsSDLC jobsIntrusion detection jobsBash jobsActive Directory jobsThreat detection jobsCompTIA jobsITIL jobsDocker jobsGIAC jobsFinance jobsCRISC jobsOWASP jobs
SANS jobsUNIX jobsIndustrial jobsTerraform jobsTCP/IP jobsClearance Required jobsHIPAA jobsJavaScript jobsOSCP jobsIT infrastructure jobsCCSP jobsBanking jobsSOC 2 jobsVPN jobsDNS jobsCISO jobsPolygraph jobsData Analytics jobsSOX jobsSAP jobsNIST 800-53 jobsJira jobsGCIH jobsMITRE ATT&CK jobsGSEC jobs