Senior Cyber Security Analyst – Incident Management

Cyber UK
3 weeks ago
Create job alert

Cyber Operations purpose is to support safe care and build public trust by building NHS England’s cyber resilience and enabling the wider health system to be cyber resilient, supporting Transformation Directorate’s purpose of delivering the best care and outcomes for the NHS. The Cyber Operations sub-directorate consists of 4 operational areas:

  • Cyber Security Operations Unit (CSOU) – SIO
  • Cyber Delivery Unit (CDU).
  • Cyber Improvement Programme.
  • Chief Information Security Office Function (CISO)

The Senior Incident Manager role is a great opportunity to work within the CSOU leading on the management of serious and complex cyber security investigations. You should have great communication skills and not be averse to public speaking and be able to communicate concepts and ideas across a range of stakeholders. You will lead on process improvement work within the Incident Management team and act as a Cyber Security subject matter expert. Flexibility is required as during an incident there may be extended hours of work. You must be able to prepare reports to a standard that would withstand robust scrutiny. An understanding of the computer misuse act and the data protection act is required. You should be able to understand the cyber threat landscape. You should understand the volatility of data, the importance of continuity of evidence and digital forensics.

Main duties of the job

  • Manage Serious and Complex Cyber Security Investigations.
  • Write and develop documentation such as playbooks and user guides.
  • Write detailed investigation reports.
  • Gather and manage large volumes of information from a variety of sources during an investigation.
  • Support Incident Managers and Juniors Incident Managers with their investigations.
  • Act as a second-tier escalation point for analysts within the CSOU.
  • Manage and resolve more complex enquiries.
  • Manage Cyber Incident Response teams that are deployed during a cyber security incident.
  • Create strategies for digital forensics investigators.
  • Run and chair blended calls during a Cyber Security Incident, ensuring they are structured and effective.
  • Ensure standards by reviewing security tickets created by analysts and Incident Managers within the CSOU.
  • Deliver cyber security and Incident Management presentations to a diverse audience.
  • Write articles and share information that can help educate the wider systems on current and emerging cyber security threats.
  • Gather key performance indicators and deliver reports.
  • Use tooling such as Sentinel, Microsoft Defender for Endpoint and Splunk during cyber security investigations.
  • Work across teams to develop and advance cyber security investigations by bringing together a variety of skills sets and knowledge to achieve successful outcomes.
  • Act as a cyber security Subject Matter Expert for projects and improvements across the transformation directorate.

About us

The NHS England board have set out the top-level purpose for the new organisation to lead the NHS in England to deliver high-quality services for all, which will inform the detailed design work and we will achieve this purpose by:

  • Enabling local systems and providers to improve the health of their people and patients and reduce health inequalities.
  • Making the NHS a great place to work, where our people can make a difference and achieve their potential.
  • Working collaboratively to ensure our healthcare workforce has the right knowledge, skills, values and behaviours to deliver accessible, compassionate care.
  • Optimising the use of digital technology, research, and innovation.
  • Delivering value for money.

If you would like to know more or require further information, please visitNHS England. Colleagues with a contractual office base are expected to spend, on average, at least 40% of their time working in-person. Staff recruited from outside the NHS will usually be appointed at the bottom of the pay band. NHS England hold a Sponsor Licence; this means that we may be able to sponsor you providing the Home Office requirements are met. To be eligible for sponsorship through the Skilled Worker route you’ll usually need to be paid the ‘standard’ salary rate of at least £38,700 per year, or the ‘going rate’ for your job, whichever is higher. You can find more information on the Government website.

Date posted:11 October 2024

Pay scheme:Agenda for change

Band:Band 8a

Salary:£64,506 to £72,604 a year (this includes a RRP payment of 20%)

Contract:Permanent

Working pattern:Full-time

Reference number:990-TD-CY-6566774-E

Job locations:7-8 Wellington Place, Leeds / Hexagon House, Exeter, Leeds or Exeter, LS1 4AP

Job description

Job responsibilities

Please see the attached Job Description and Person Specification for more information about the role and responsibilities. Please ensure your supporting statement includes demonstrable evidence and specific examples on how you meet the criteria for each of the key skills specified. This will be used in both the shortlisting and interview processes. The post of Senior Security Advisor has been awarded a Recruitment and Retention Premia (RRP) in response to current labour market conditions. In recognition of this, the role attracts an additional monthly RRP payment equal to 20% per annum. Please be aware that RRP is non-contractual and subject to review.

Important:Please be aware there are residency requirements you need to meet: All NHS England Cyber Security personnel must hold security clearance SC level as a minimum. To meet National Security Vetting requirements, you must have resided in the UK for a minimum of 3 out of the past 5 years for SC clearance. Candidates who were posted abroad for service with HM Government, Armed Forces or within a UK government role – will still be considered. Please make sure you meet these requirements before applying for this role. You don’t need to have SC already, however, failure to achieve the requirements for SC after offer, will result in the job offer being withdrawn.

Person Specification

Qualifications

Essential

  • Post-graduate degree or equivalent level of experience (3 years’ cyber security experience)

Knowledge

Essential

  • Expert knowledge of the processes, tools and techniques of information security management, ability to deploy and monitor information security systems, as well as detect, resolve and prevent violations of IT security, to protect organizational data.
  • Demonstrable knowledge of technologies and technology-based solutions dealing with information security issues; ability to apply these in protecting information security across the organization.

Desirable

  • Expert knowledge of concept, procedures and processes of Security Information and Event Management (SIEM); ability to utilize related applications to protect organizational networks from cyber risks.

Skills and Experience

Essential

  • Demonstrable knowledge of and ability to utilize a variety of specific tools for collecting, analysing, and presenting digital-related evidence.

Desirable

  • Proven knowledge of tools, techniques, approaches and processes of cybersecurity risk management; ability to ensure organizational network operation and minimize negative effect by cybersecurity risks.

Apply For Job

#J-18808-Ljbffr

Related Jobs

View all jobs

Senior Information Security Analyst ( Hybrid / Leeds )

Regional Security Analyst ( up to 80K plus bonus )

Regional Security Analyst ( up to 80K plus bonus )

IT Security Lead ( West London / Newcastle )

IT Security Lead ( Newcastle / London )

Senior SOC Analyst

Get the latest insights and jobs direct. Sign up for our newsletter.

By subscribing you agree to our privacy policy and terms of service.

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

10 Must-Read Cyber Security Books for UK Professionals: Boost Your Career and Stay Ahead of Threats

With rapid advancements in digital infrastructure, cloud computing, and the Internet of Things (IoT), cyber threats continue to evolve at lightning speed. For organisations across the UK—and globally—robust cyber security is no longer optional: It’s a strategic imperative. From healthcare and finance to government agencies and tech start-ups, every sector needs skilled professionals to safeguard critical data and protect users. If you’re looking to break into or advance within the cyber security industry, staying updated on the latest techniques, threat landscapes, and defence strategies is paramount. One of the best ways to build and sharpen your expertise is by reading authoritative, high-quality books that combine foundational knowledge with cutting-edge insights. In this guide, we’ve compiled a list of ten books that cater to various skill levels, spanning ethical hacking and threat intelligence to secure software development and cryptography. By diving into these resources, you’ll fortify your understanding of cyber security fundamentals, explore hands-on techniques for defending systems, and gain the strategic perspective needed to excel in roles throughout the UK’s thriving cyber security landscape.

Navigating Cybersecurity Career Fairs Like a Pro: Preparing Your Pitch, Questions to Ask, and Follow-Up Strategies to Stand Out

In a world where digital threats are escalating and online infrastructure underpins nearly every aspect of our personal and professional lives, cybersecurity has swiftly become one of the most sought-after career fields. Demand for skilled cybersecurity professionals outstrips supply, both in the UK and globally. From ethical hackers and penetration testers to governance, risk, and compliance (GRC) specialists, the opportunities are extensive—and lucrative. Amidst this surge in demand, cybersecurity career fairs provide an invaluable chance to meet potential employers face-to-face, gain industry insights, and make connections that can accelerate your career trajectory. Unlike applying to countless jobs online, these events bring companies, security leaders, and aspiring candidates together under one roof. When approached with the right strategy, a single conversation at a cybersecurity fair can open the door to your dream job. In this comprehensive guide, we’ll explore how to prepare thoroughly, engage confidently, and follow up effectively after a cybersecurity career fair. By incorporating these insights into your approach, you’ll stand out from the crowd and maximise your chances of securing the perfect role in this fast-growing field.

Common Pitfalls Cyber Security Job Seekers Face and How to Avoid Them

The cyber security industry in the UK and worldwide is experiencing rapid growth. With cyber attacks growing in sophistication and frequency, organisations are investing more resources than ever into defending their digital assets. From penetration testers and threat analysts to security architects and compliance officers, cyber security professionals are in high demand across a variety of sectors—including finance, healthcare, government, and retail. Yet, in spite of this high demand, the process of landing a cyber security role can be more challenging than many candidates anticipate. The stakes are high: prospective employers entrust cyber professionals with their most sensitive data, their compliance posture, and often their core business operations. Therefore, they’re looking for candidates who can demonstrate not just technical know-how, but also excellent communication, adaptability, and an awareness of the broader business context. In this article, we’ll explore the most common pitfalls that cyber security job seekers face, especially in the UK market, and how to avoid them. Whether you’re a recent graduate, a professional transitioning from a different field, or an experienced practitioner aiming for a senior role, these insights will help you stand out and secure the opportunities that fit your skill set and career goals.