Overview
In this role you will support NHS England’s cyber resilience by performing first line alert triage and driving improvements in detection. You will work within the CSOC to protect national healthcare networks and endpoints, and engage with external organisations and internal stakeholders. You will develop or tune detection rules and assist in incident response and remediation as needed. This role offers a structured training pathway to advance your toolset expertise and security certifications. A national remit and collaboration with cross-functional teams provide a meaningful opportunity to strengthen NHS cyber security.
Pay / Benefits
- Recruitment and Retention Premia (RRP) 10% per annum
- structured training pathway with certifications
- flexible working
- opportunity to work across national public healthcare
Responsibilities
- Perform first line alert triage from cybersecurity monitoring tooling and provide initial conclusions to stakeholders
- Leverage and expand monitoring capabilities across networks, cloud environments, endpoints, and identity management to protect NHS systems
- Develop or refine detection rules and automate content to improve threat detection rates
- Review and guide B5 analysts; create and update standard operating procedures and triage guides
- Assist other CSOC areas in assessing alerts and ensure proper remediation by affected organisations
- Support incident response activities and detailed investigations for major incidents based on experience
- Engage in the CSOC training pathway and obtain industry certifications as part of professional development
Key requirements
- Knowledge of SIEM concepts, procedures, and use in protecting networks
- Knowledge of intrusion detection and prevention tools and techniques
- Knowledge of digital threat detection, monitoring, analysis, and prevention
- Post-graduate level degree in Cyber Security or relevant subject, or equivalent experience
- Security clearance requirements (SC) with 5 years of UK residency or as specified
- Ability to review security incidents and guide remediation with appropriate technical understanding
- Desirable knowledge of forensics investigations and ISOC technologies
- Knowledge of network defence techniques and tools
- analytical mindset
- collaboration across cross-functional teams
- clear communication and documentation
- Security Information and Event Management (SIEM)
- Intrusion detection and prevention
- Digital threat monitoring and analysis
…
