Search

Senior Cyber Security Analyst - Incident Management

Posted: 15/10/24
Recruiter:NHS
Reference:2837034736
Type:Permanent
Disciplines: Network Security
Salary:Competitive
Location:Leeds
Description: Senior Cyber Security Analyst - Incident Management

The Cyber Operations purpose is to support safe care and build public trust by building NHS England's cyber resilience and enabling the wider health system to be cyber resilient, supporting Transformation Directorate's purpose of delivering the best care and outcomes for the NHS.

The Cyber Operations sub-directorate consists of 4 operational areas:

  • Cyber Security Operations Unit (CSOU) - SIO
  • Cyber Delivery Unit (CDU).
  • Cyber Improvement Programme.
  • Chief Information Security Office Function (CISO)

The Senior Incident Manager role is a great opportunity to work within the CSOU leading on the management of serious and complex cyber security investigations. You should have great communication skills and not be averse to public speaking and be able to communicate concepts and ideas across a range of stakeholders. You will lead on process improvement work within the Incident Management team and act as a Cyber Security subject matter expert. Flexibility is required as during an incident there may be extended hours of work. You must be able to prepare reports to a standard that would withstand robust scrutiny. An understanding of the computer misuse act and the data protection act is required. You should be able to understand the cyber threat landscape. You should understand the volatility of data, the importance of continuity of evidence and digital forensics.

Main duties of the job
  • Manage Serious and Complex Cyber Security Investigations.
  • Write and develop documentation such as playbooks and user guides.
  • Write detailed investigation reports.
  • Gather and manage large volumes of information from a variety of sources during an investigation.
  • Support Incident Managers and Junior Incident Managers with their investigations.
  • Act as a second-tier escalation point for analysts within the CSOU.
  • Manage and resolve more complex enquiries.
  • Manage Cyber Incident Response teams that are deployed during a cyber security incident.
  • Run and chair blended calls during a Cyber Security Incident, ensuring they are structured and effective.
  • Ensure standards by reviewing security tickets created by analysts and Incident Managers within the CSOU.
  • Deliver cyber security and Incident Management presentations to a diverse audience.
  • Write articles and share information that can help educate the wider systems on current and emerging cyber security threats.
  • Gather key performance indicators and deliver reports.
  • Use tooling such as Sentinel, Microsoft Defender for Endpoint and Splunk during cyber security investigations.
  • Work across teams to develop and advance cyber security investigations by bringing together a variety of skill sets and knowledge to achieve successful outcomes.
  • Act as a cyber security Subject Matter Expert for projects and improvements across the transformation directorate.
Important Information

All NHS England Cyber Security personnel must hold security clearance SC level as a minimum. To meet National Security Vetting requirements, you must have resided in the UK for a minimum of 3 out of the past 5 years for SC clearance. Candidates who were posted abroad for service with HM Government, Armed Forces or within a UK government role will still be considered.

Colleagues with a contractual office base are expected to spend, on average, at least 40% of their time working in-person.

Staff recruited from outside the NHS will usually be appointed at the bottom of the pay band.

NHS England holds a Sponsor Licence; this means that we may be able to sponsor you providing the Home Office requirements are met. To be eligible for sponsorship through the Skilled Worker route you'll usually need to be paid the 'standard' salary rate of at least £38,700 per year, or the 'going rate' for your job, whichever is higher.

Qualifications
  • Post-graduate degree or equivalent level of experience (3 years' cyber security experience)
Knowledge
  • Expert knowledge of the processes, tools and techniques of information security management, ability to deploy and monitor information security systems, as well as detect, resolve and prevent violations of IT security, to protect organizational data
  • Demonstrable knowledge of technologies and technology-based solutions dealing with information security issues; ability to apply these in protecting information security across the organization
  • Expert knowledge of concept, procedures and processes of Security Information and Event Management (SIEM); ability to utilize related applications to protect organizational networks from cyber risks.
Skills and Experience
  • Demonstrable knowledge of and ability to utilize a variety of specific tools for collecting, analysing, and presenting digital-related evidence
  • Proven knowledge of tools, techniques, approaches and processes of cybersecurity risk management; ability to ensure organizational network operation and minimize negative effect by cybersecurity risks
Disclosure and Barring Service Check

This post is subject to the Rehabilitation of Offenders Act (Exceptions Order) 1975 and as such it will be necessary for a submission for Disclosure to be made to the Disclosure and Barring Service (formerly known as CRB) to check for any previous criminal convictions.

£64,506 to £72,604 a year (this includes a RRP payment of 20%)

Contract

Permanent

Working pattern

Full-time

Reference number

990-TD-CY E

Recruiting now