Security Operations Centre Level 1 Analyst
Ministry of Defence
- Department
- Ministry of Defence
- Location
- Hereford
- Openings
- 1 post
- Grade
- EO
- Salary
- £30,740
- Closing
- 32 days left
- Profession
- Analysis and Statistics, DDaT, Operational Delivery
- Contract
- Permanent
- Security clearance
- DV
- Working pattern
- Flexible working, Full-time, Job share, Part-time
Job summary
The Defensive Cyber Analyst will work within a rapidly growing cyber security team who are responsible for designing, delivering and maintaining operational cybersecurity capabilities. You will be conducting pro-active, risk based, defensive monitoring of priority C4IS/networks identifying potential internal and external cyber threats/attacks.
The position involves a broad range of skills to monitor networks/systems, and the post holder must have the ability to analyse and investigate security events, communicate effectively with other team members and articulate clearly when raising escalating to senior team members and management.
Your main objective will be to proactively monitor and hunt through IT environments to detect and respond to information and cyber security threats utilising a range of technologies and processes to prevent, detect and manage cyber threats.
You will contribute to the effectiveness and maturity of the Security Operations Centre (SOC) by contributing to tooling, updating and creating new play books while remaining current with the trends in the wider security industry.
This position is advertised at 37 hours per week.
This is open to Sole UK Nationals Only.
Additional security checks will be required for this role.
What they’re looking for
- As a Defensive Cyber Analyst, you will work independently and as part of a team, you will be responsible for proactive monitoring and detection of security events. You will be responsible for analysing, investigating, and communicating cyber security incidents and risk. You will be an effective team player and bring your good understanding of computer networks (LAN/WAN, network protocols and OSI model) and knowledge of computer-based network attacks (MITRE ATT&CK, NIST CSF) to contribute to successfully defending organisational systems. You will be responsible for seeking opportunities to improve your own knowledge and sharing knowledge with others.
- The ideal candidate will have the following traits:
- A passion for cyber security and a keen interest in IT
- Adopts a creative, yet methodical mind-set when investigating and responding to cyber threats
- Persevering in the face of stressful circumstances to prioritise and meet deadlines.
- Superb attention to detail, good analytical and problem solving skills to assist in resolving Events of Interest and potential Indicators of Compromise
- A continuous desire and willingness to learn and develop your current knowledge and skills
- Good verbal and written communication skills, with particular ability to communicate technical information to non-technical collaborators.
Behaviours you’ll be assessed on
This advert says the panel will score you against these behaviours at EO level. Each one links to worked examples.
Job description
Day to Day Operations:
- Manage and maintain security of computer networks by monitoring situational awareness feeds to detect Cyber threats to users, and the wider MOD community.
- Conduct analysis of all alerts to determine the threat to computer networks, triaging by employing a methodical and coherent response and escalating in accordance with (iaw) Standard Operating Procedures (SOP’s)
- Create and maintain accurate case management records of all actions taken while analysing and closing incidents iaw SOPs.
- Monitor sensor feeds and heuristic detection tools, performing initial analysis to identify process and network events that may indicate a malicious cyber incident.
Incident Response & Management:
- Brief management regarding ongoing security incidents including status and actions to be taken.
- Raise and perform response actions of any incidents that arise during your response time, which may include liaison with external agencies or analysis using the tools available.
- Maintain all incident documentation using the various case management toolsets to maintain the single source of knowledge of the cyber defence task.
- Deliver briefings where required to support the defensive cyber monitoring task.
SOC Development:
- Develop new or improve Security Use Cases, ensure accurate supporting documentation is maintained and reports, rules, and alerts for SIEM tools developed in unison.
- Deliver operationally focused direction, guidance, and SME (subject matter expert) advice to junior security staff and non-security staff.
- Engage with various partners, including service providers within industry regarding the defensive monitoring.
Personal & Professional Development:
- Maintain knowledge of current cyber issues, vulnerabilities and exploits through research, technical reports, and briefs.
- Undertake continual knowledge development in line with NIST Work Role PR-CDA-001
Other Duties as directed by SOC Team Lead and SOC Manager/Director.
Nationality requirements
Open to UK nationals only.
Selection process
This vacancy is using Success Profiles (opens in a new window), and will assess your Behaviours, Experience and Technical skills.
Candidates will be required to provide a statement of suitability. (max 750 words)
At sift, Candidates will be assessed against their Statement of suitability and the following:
- Changing and Improving
- Working Together
- Developing Self and Others
All applications will go through sift and those successful will be invited to attend an interview.
At interview, Candidates will be assessed against the following:
Behaviours:
- Working Together
- Developing Self and Others
- Making Effective Decisions
Technical Skills:
- SFIA – IT Infrastructure (ITOP) – Level 1
- SFIA – Network Support (NTAS) – Level 2
- SFIA – Incident management (USUP) – Level 3
- SFIA – Security operations (SCAD) Level 3
SFIA 9 skills directory A–Z — English
During the interview process candidates' technical/cyber understanding will be assessed via questioning.
As a result of the changes to the UK immigration rules which came into effect on 1 January 2021, the Ministry of Defence will only offer sponsorship for a skilled worker visa under the points-based system, where a role has been deemed to be business critical. The role currently being advertised has not been assessed as business critical and is therefore NOT open to applications from those who will require sponsorship under the points-based system. Should you apply for this role and be found to require sponsorship, your application will be rejected, and any provisional offer of employment withdrawn.
The Civil Service embraces diversity and promotes equal opportunities. As such, we run a Disability Confident Scheme (DCS) for candidates with disabilities who meet the minimum selection criteria.
There may be occasions where it is not practicable or appropriate to interview all DCS candidates that meet the minimum criteria for the job. For example, in certain recruitment situations such as a high volume of applications, seasonal demand, or peak periods, the employer may wish to limit the overall number of interviews offered to both DCS and non-DCS applicants.
As a result of the changes to the UK immigration rules which came into effect on 1 January 2021, the Ministry of Defence will only offer sponsorship for a skilled worker visa under the points-based system, where a role has been deemed to be business critical. This role does not meet that category, and we will not sponsor a visa. It is therefore NOT open to applications from those who will require sponsorship under the points-based system.
Should you apply for this role and be found to require sponsorship, your application will be rejected and any provisional offer of employment withdrawn.
The Ministry of Defence requires all candidates who are successful at interview to declare any outside interests. These declarations will be discussed with successful candidates following the interview process and before a formal offer of employment is made, as some outside interests may not be compatible with MOD civilian roles. This will not, in the majority of cases, prevent employment in MOD, but it is a measure that must be taken to ensure that appropriate mitigations can be put in place to manage any potential, perceived or actual conflicts of interest from the first day of employment.
The Ministry of Defence adopts a zero-tolerance approach to unacceptable behaviours, which includes bullying, harassment, sexual harassment, discrimination, and victimisation. You will not be eligible and will not be considered for this post if you have been dismissed from a role for such unacceptable behaviours within the last five years. This will also apply if you resign or otherwise leave a role but, because of an adverse decision, would have been dismissed for gross misconduct had you continued in that employment. Pre-employment checks will be carried out.
Cyber & Specialist Operations Command (CSOC) generates and operates specialist capabilities, ready to fight across all domains to make the UK secure at home and strong abroad.
Always on, we are across every UK operation, delivering the capabilities you don’t usually see - or those you can’t.
From cyber warriors and medics to intelligence analysts, special forces, educators, and Defence attachés, our collective expertise delivers the warfighting edge Defence needs to deter threats and secure the nation today and prepare for tomorrow.
CSOC unites Defence’s cyber and specialist capabilities under a single, military command alongside the Royal Navy, British Army, and the Royal Air Force - acting as the UK’s fourth Military Command. For more information, please see here.’
Cyber and Specialist Operations Command (CSOC) is going through a significant transformation programme which aims to design the way in which the new Military Command conducts its business and delivers for Defence and the nation. As a consequence of this, posts within CSOC are/or may become subject to review and potential changes as we continuously improve across the period of the transformation programme. These changes may be minor or could be more substantive and will generate new opportunities. Throughout, the Command’s transformation programme is committed to following the MOD’s framework on managing and supporting people through the change process and places an emphasis on early and open consultation and engagement with the Command’s personnel and Trade Unions.
Feedback will only be provided if you attend an interview or assessment.
Practise before you apply
Civil Service panels score every answer against the Success Profiles behaviours at EO level. Practise STAR answers and get them marked against the same framework.
3 free questions · No card needed
Similar vacancies
- Waste Management & Recycling Services - Specialist Production Instructor (SPI): Waste Management & Recycling _ HMP Swinfen Hall (Ref: 21583) · HM Prison & Probation Service · £34,440
- Group Profile: Group Worker (Ref: 21095) · HM Prison & Probation Service · £34,440
- Case Reviewer (Welsh Language) · OFGEM · £26,694+
- Customer Service Officer (Welsh Language) · OFGEM · £26,694+
- Associate Performance Analyst · HM Land Registry · £32,119+