Job description
Responsibilities:
As a Cyber Security Monitoring Technical Lead Analyst, you will deliver core monitoring activities over multiple security technologies, supporting and guiding analysts within your team, acting as a point of escalation for important event alerting. You will have the ability to:
- Support the shaping of the monitoring strategy, ensuring requirements, policies and standards to govern all activities and outputs are met.
- Manage the monitoring, triaging, and investigation of security alerts on protective monitoring platforms to identify security events and incidents, reviewing analysis of security event data to manage security incident response, reporting, or escalation where appropriate.
- Lead small monitoring teams in the design, development and enablement of automated monitoring processes, recommending and implementing the latest SIEM (Security Information and Event Management) and network analysis tools, techniques and procedures to:
1. detect malicious activity
2. ensure continuous improvement through dashboard monitoring or retrospective assessment
- Establish a detailed understanding of ONS data security and network architectures enabling the delivery of consistent security advice.
- Report critical security incidents to the Cyber Security Principal
- Build successful working relationships with key stakeholders to improve the security of ONS
You will need a willingness to work towards or obtain relevant professional qualifications and memberships:
- Recognised higher education in an IT related area And / Or
- Certifications from a recognized body in Digital Security e.g. GIAC, ISC2, ISACA, BCS, CompTIA etc.)
Essential Criteria:
- Experience of protective monitoring tools and technologies including SIEM, IDP, IDS, Firewalls and endpoint detection and response capabilities.
- Proficient in analysing a wide range of security logs to triage and investigate security events and alerts.
- Ability to deliver an effective incident response service across the life-cycle from detection and analysis, containment to eradication and recovery.
- Experience of working with a wide range of technology and business stakeholders to provide security advice and implement technical security solutions
- Strong written and verbal communication skills with the ability to present complex information and cyber security concepts clearly and concisely for technical and non-technical audiences.
- Relevant certifications or qualification such as CISSP, GIAC, SANS would be advantageous however more important is an aptitude and passion for cyber security.
For more detailed information on the duties and requirements, as well as to apply, click the APPLY button below!
In return we offer you:
✔Hybrid working in an organization voted top in the UK for work-life balance
✔A market leading pension scheme - our employer contribution rate is around 27%
✔A choice of working patterns *for every role* full-time, part-time, job-share.
✔Maternity, adoption or shared parental leave of 26 weeks full pay (subject to qualifying criteria)
✔Employee Assistance Programmes
✔Diversity Network Groups
✔Mental Health Allies
✔Civil Service Sports and Social club
✔Generous holiday allowance – 25 days annual leave, rising to 30 days after 5 years service in addition to 9 public holidays
For more information about this role and to apply, please click the APPLY button to be taken to Civil Service Jobs.
Job Types: Full-time, Part-time, Permanent
Salary: £39,200.00-£47,400.00 per year
Benefits:
- Casual dress
- Company pension
- Cycle to work scheme
- Discounted or free food
- Employee discount
- Flexitime
- Free parking
- Health & wellbeing programme
- On-site parking
- Sick pay
- Work from home
Schedule:
- Day shift
- Flexitime
- Monday to Friday
- No weekends
Work Location: Hybrid remote in London
Application deadline: 15/06/2023