Job description
Cyber Defence Lead, SC Security Cleared - Inside IR35 Term: 12 Months ing Authority: Cabinet Office Location: Hybrid/London Job Description: Cyber Defence Lead We are the Cabinet Office's cyber security team, and our mission is to secure the department against cyber threats and enable it to deliver for the people of the United Kingdom. We protect our nationwide internal IT infrastructure and high-profile citizen-facing digital services such as GOV.UK, by governing, delivering and assuring cyber security capabilities for the department. What you'll do: The Cyber Defence team delivers cyber threat intelligence, threat detection, incident response and vulnerability management capabilities for the Cabinet Office and is responsible for defending both internal IT infrastructure and citizen-facing services. As the Cyber Defence Lead, you'll be reporting to the Head of Cyber Security and will be responsible for leading and improving the Cyber Defence team. You'll also feed into our wider cyber security strategy and roadmap and take a leadership role in the cyber security team. As Cyber Defence Lead, you will be Security Cleared to SC Level: lead the Cabinet Office's cyber defence function, by providing strategic direction and coordinating day-to-day delivery of threat intelligence, threat detection, incident response, vulnerability management and ethical hacking capabilities identify and deliver opportunities for continual improvement of the cyber defence function lead the technical response to major cyber security incidents and critical vulnerabilities impacting the Cabinet Office brief senior stakeholders on the cyber threat to the Cabinet Office work closely alongside other cyber security functions, supporting the continual improvement of wider capabilities work with Government Security Group, the National Technical Authorities (eg, NCSC) and law enforcement to ensure knowledge sharing and collaboration take a leadership role in the cyber security team, the wider Cabinet Office, and the government security and risk management communities act as an escalation point for, and provide coaching and mentoring to, senior security analysts Cyber incidents can and do arise on a 24/7 basis. The team operates an out-of-hours on call rota, which you will be expected to join. We're interested in people who: have a breadth of experience across cyber threat intelligence, detection and response have experience investigating, managing and coordinating the response to, major cyber incidents have an in-depth understanding of the tools, techniques and procedures used by threat actors can effectively operate at a strategic level have experience taking a leadership role in a cyber security function understand how to influence senior management and communicate with both technical and non-technical audiences have an active interest in coaching and mentoring others It's desirable, but not essential, that you: have experience leading security operations or cyber defence capabilities have an understanding of Agile environments, continual delivery techniques and DevOps cultures have experience with cloud environments such as AWS Jobg8 UK