Overview
In this role you support NHS England’s cyber resilience by working in the CSOC’s Infrastructure and Networks team. You act as a Tier 2 analyst, guiding Tier 1 staff, handling incidents, and refining security use cases to improve posture. You will apply advanced analytics with SIEMs/XDR to identify threats and support NHS organizations during investigations. You’ll stay current on threats and contribute to a broader mission of safe care and public trust through secure, resilient networks.
Pay / Benefits
- RRP payment of 20% per annum
- Permanent contract
- Flexible working options
- Office-based presence expected (40% in offices)
- Competitive salary band 59,264.40 to 67,818 per year including RRP
Responsibilities
- Serve as a Tier 2 Infrastructure and Networks analyst in the Security Operations team
- Mentor and support Tier 1 Junior Analysts in incidents and investigations
- Escalate and deputise for Senior Analysts when needed
- Research and stay updated on emerging cyber threats and technologies
- Utilize SIEMs and XDR platforms to identify threat patterns and vulnerabilities
- Assist with investigations of triggered security alerts and incident handling
- Refine Use Cases and identify areas to strengthen overall security posture
- Provide technical support to NHS organisations in investigating Infrastructure and Networks incidents
Key requirements
- 1+ years of experience in a Cyber Operations/ SOC environment
- Desirable: SC-200, SANS SEC504 or other relevant SANS qualifications
- Security clearance requirements (minimum level) with UK residency rules for SC clearance
- Demonstrated knowledge of monitoring, analyzing, and responding to network attacks and intrusions
- Experience with intrusion detection and prevention tools and practices
- Strong understanding of Security Information and Event Management (SIEM) concepts and applications
- Post-graduate degree or equivalent experience in Cyber Security, with ongoing professional development
- Mentorship and coaching
- Analytical thinking
- Clear communication and escalation
- SIEM and XDR usage for threat detection and investigation
- Security operations and incident response
- Network security monitoring and threat hunting
…
