Lead Security Operations Centre (SOC) Analyst
United Kingdom
Department for Business and Trade
Export support for UK businesses – great.gov.uk
About us The Department for Business and Trade (DBT) has a clear mission - to grow the economy. Our role is to help businesses invest, grow and export to create jobs and opportunities right across the country. We do this in three ways. Firstly, we help to build a strong, competitive business environment, where consumers are protected and companies rewarded for treating their employees properly. Secondly, we open international markets and ensure resilient supply chains. This can be through Free Trade Agreements, trade facilitation and multilateral agreements. Finally, we work in partnership with businesses every day, providing advance, finance and deal-making support to those looking to start up, invest, export and grow. The Digital, Data and Technology (DDaT) directorate develops and operates tools and services to support us in this mission. The team have been nominated three times in a row for ‘Best Public Sector Employer’ at the Women in Tech awards! About the role This position is part of the DBT Security Operations Centre (SOC) and reports directly to the SOC Manager. The SOC is responsible for detecting and responding to both internal and external threats to the security of DBT’s services and the data that supports them. This role plays a vital part in protecting the Department and supporting its mission to drive economic growth. The Lead SOC Analyst will lead the CIDR (Cyber Incident Detection and Response) team acting as a point of escalation for analysts and escalating incidents to the SOC manager and beyond as necessary. A key part of the incident response process will be the collection and implementation of lessons learned as part of a continuous improvement cycle. Working closely with other SOC functions, primarily Cyber Engineering, the role will ensure that appropriate logging and monitoring is in place across DBTs end user and digital estates. The creation and maintenance of new and existing analytic rules based on this logging, and feedback from incidents, is vital to maintaining DBTs detect and respond capability. About you You will be an experienced SOC analyst with an excellent understanding of the threats facing an organisation in a cloud environment. Familiar with SIEM (Security Incident and Event Management) tools and a detailed understanding of logging requirements in digital services, you will be able to both create and review analytic rules to improve detection capability. You will also possess strong communication and line management skills and be able to lead the CIDR team effectively to respond to an ever-changing threat landscape Main responsibilities You will:
- Line manage the CIDR team, monitoring, triaging, and investigating security alerts on protective monitoring platforms to identify security incidents
- Review existing and new data sources being ingested into the protective monitoring platform and propose and implement use cases for detection and analysis
- Communicate the significance of the results of investigations and risk mitigation outcomes, guiding the organisation in the improvement and maintenance of a robust response to new threats and attack vectors
- Provide management information regarding various aspects of the function of the incident detection and response capability
- Ensure analyst work is up to standard by implementing and maintaining peer reviews of investigations
- Lead and develop DBT’s incident detection and response capability, including maintaining and updating existing policies
- Manage post-incident reviews, including root cause analysis, to feedback information and so improve monitoring
- Provide an escalation point for analysts, making decisions regarding resolution of incidents, including escalation, where appropriate to the SOC manager or above
- Experience of SIEM tools, including being proficient in query languages, to create automation, detection rules and dashboards (Lead Criteria)
- Experience managing a team of analysts
- Experience of cyber security incident management, particularly in a cloud-based environment
- Experience of working in a cross-functional cloud-based environment
- Effective verbal and written communication skills
- An appropriate cyber security qualification, preferably related to incident response or security operations
- Intrusion detection and analysis
- Threat understanding
- Cyber security operations
- Threat intelligence and threat assessment
- Secure Operations Management
- Changing and Improving
- Managing a Quality Service
- departmental or company records (personnel files, staff reports, sick leave reports and security records)
- UK criminal records covering both spent and unspent criminal records
- your credit and financial history with a credit reference agency
- security services record
- location details
- learning and development tailored to your role
- a flexible, hybrid working environment with options like condensed hours
- a culture encouraging inclusion and diversity
- a Civil Service pension with an average employer contribution of 28.97%
- annual leave starting at 25 days rising to 30 days with service
- three paid volunteering days a year
- an employee benefits programme including cycle to work
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Job stats:
15
4
0
Categories:
Analyst Jobs
Incident Response Jobs
Leadership Jobs
Tags: Automation Clearance Cloud Finance Incident response Intrusion detection Monitoring SIEM SOC Threat intelligence
Perks/benefits: Career development Flex hours Startup environment
Region:
Europe
Country:
United Kingdom
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.
Security Operations Engineer jobsSystems Administrator jobsIT Security Analyst jobsSenior Cloud Security Engineer jobsSenior Cybersecurity Engineer jobsSenior Security Analyst jobsSenior Information Security Analyst jobsCyber Security Specialist jobsInformation Security Manager jobsSenior Network Security Engineer jobsSecurity Consultant jobsSenior Product Security Engineer jobsInformation System Security Officer (ISSO) jobsChief Information Security Officer jobsInformation Systems Security Engineer jobsSenior Information Security Engineer jobsSecurity Specialist jobsSenior Cyber Security Engineer jobsIT Security Engineer jobsCyber Threat Intelligence Analyst jobsSenior IT Auditor jobsSecurity Operations Analyst jobsCybersecurity Specialist jobsSenior Software Engineer jobsNetwork Engineer jobs
Java jobsBash jobsTS/SCI jobsEncryption jobsEDR jobsSDLC jobsSplunk jobsMalware jobsThreat detection jobsRMF jobsFinance jobsTerraform jobsTop Secret jobsForensics jobsIDS jobsCompTIA jobsSQL jobsITIL jobsIPS jobsActive Directory jobsSOC 2 jobsDocker jobsOWASP jobsClearance Required jobsGIAC jobs
Intrusion detection jobsCRISC jobsAnsible jobsVPN jobsTCP/IP jobsOSCP jobsHIPAA jobsDoDD 8570 jobsMITRE ATT&CK jobsData Analytics jobsZero Trust jobsJavaScript jobsSOAR jobsIT infrastructure jobsBanking jobsCCSP jobsSOX jobsIndustrial jobsUNIX jobsDNS jobsJira jobsNIST 800-53 jobsGCIH jobsKPIs jobsCISO jobs