Security Operations Centre Analyst (SOC)

Department for Environment, Food and Rural Affairs

Security Operations Centre Analyst (SOC)

£38551

Department for Environment, Food and Rural Affairs, City of Westminster

  • Full time
  • Permanent
  • Remote working

Posted today, 21 Sep | Get your application in now to be one of the first to apply.

Closing date: Closing date not specified

job Ref: 5fee47ed434a45849db4293d399f78c6

Full Job Description

Please note due the nature of the work and the requirement to be in a location with other team members the location is restricted to either Bristol, Reading of London., Defra's Security Operations Centre (SOC) is accountable for protecting DEFRA against cyber threats. Our SOC analysts monitor the network and investigate any potential security incidents.
We are seeking an individual to help build our capability. Working as part of a small team you will be accountable for providing security monitoring and incident response. Using cyber security techniques, you will be ensuring that the DEFRA’s security is maintained.
Our Analysts are accountable for the day-to-day handling of alerts in our Security Information and Event Management (SIEM), incidents assigned to the Security Operations Centre and investigating indicators of compromise provided by Threat Intelligence.
As a SOC Analyst you will use a wide range of tools and technical expertise, currently focusing primarily on user behaviour, cloud security & application security.
Defra is transforming its IT security processes via a security improvement plan and approach in line with our new multi-supplier IT operating model. As we develop and grow against this plan the range of services that are protectively monitored by Defra’s SOC will increases.
The SOC team is based in Reading and London. The successful applicant will be expected to travel into one of either office on regular basis working a shift pattern during the day to ensure continuous monitoring of the organisation.
We welcome applicants with experience of working in a Security Operations Centre and other technological backgrounds or graduates in a relevant subject who may wish to move into this field of work, it should be noted that you must demonstrate transferable technical skills and a keen interest in cyber security to be considered for the role., + Accountable for detection, identification and triage of security incidents using the provided security tooling and IT Service Management (ITSM) tool.
+ Expand, tune, and enhance rulesets for our SIEM (Security Information and Event Management) tool etc to identify security incidents and reduce false positives.
+ Support the Senior SOC Analyst with Major Incidents and assist the wider SOC team in recovering from security breaches, participating in bridge calls and investigations of security incidents and lessons learned as appropriate.
+ Respond to Information Security related queries from stakeholders e.g. wider Security Team or suppliers.
+ Work with our cyber partners to better know our estate and how to apply current threat intelligence to make it technologically relevant to our estate.
+ Using current tooling run threat hunting queries regularly and investigate results. Work with other members of the SOC to improve our threat hunting capability and investigate IOCs (Indicators of Compromise) provided by Threat Intelligence or our cyber partners, including the National Cyber Security Centre (NCSC).
+ Communicate and engage with a wide range of stakeholders, telling the story of our work and the service we provide to the business to improve the cyber security posture of the organisation., + A 500-word personal statement: Referring to the 'skills and experience' sections of the job advert, please demonstrate how you are suitable for the role by providing relevant examples.
Further details around what this will entail are listed on the application form.
Sift
Sift will begin shortly after the advert closes.
Should there be a large number of applications, an initial sift will be conducted using your personal statement.
Candidates who pass the initial sift may be progressed to a full sift, or progressed straight to assessment or interview.
Sift dates to be confirmed.
Interview
If successful at sift stage, you will be invited to interview where you will be assessed on the Technical Skill and Behaviours listed below.
As part of the recruitment process you will be required to do a presentation. Full details will be provided later within the process.
Interview dates are to be confirmed. Please note that these may be subject to change.
Interviews will be held virtually on Microsoft Teams.
For further information on Success Profiles, please use the links below and watch our videos on Defra Jobs.
Behaviours, Where the location is ‘National’ the successful appointee should discuss and agree an appropriate contractual location in line with both Defra’s location policy and site capacity, prior to proceeding with pre-employment processes.
Successful applicants currently employed by the hiring Defra organisation for this post may choose to remain in their current contractual location or may choose to change contractual location to one of those listed above. This should be discussed and agreed prior to proceeding with pre-employment processes.
The agreed amount of time spent at a workplace for this post will reflect the requirement for Civil Servants to spend at least 60% of their working time in an organisation workplace with the option to work the remaining time flexibly from home. Working time spent at a workplace may include time spent at other organisational locations including field-based operational locations, together with supplier, customer or partner locations. This is a non-contractual agreement which is consistent with common Civil Service expectations.
Travel costs to non-contractual workplaces will be subject to departmental travel and subsistence policies. Travel costs to contractual workplaces are the responsibility of the employee.
The successful candidate is required to carry out all their duties from a UK location, and cannot do so from an overseas location at any time.
Defra includes the core department, APHA, RPA, Cefas and VMD.
Please note due the nature of the work and the requirement to be in a location with other team members the location is restricted to either Bristol, Reading or London.
Reserve list
A reserve list may be held for a period of 12 months from which further appointments can be made.
Near miss
Candidates who are judged to be a near miss at interview may be considered for other positions in Defra which may be at a lower grade, but have a potential skills match.
Merit Lists
Where more than one location is advertised, candidates will be posted in merit order by location. You will be asked to state your location preference on your application., Successful candidates must undergo a criminal record check.
Successful candidates must meet the security requirements before they can be appointed. The level of security needed is security check (opens in a new window).See our vetting charter (opens in a new window).
People working with government assets must complete baseline personnel security standard (opens in new window) checks.

Nationality requirements
This job is broadly open to the following groups:
o UK nationals
o nationals of the Republic of Ireland
o nationals of Commonwealth countries who have the right to work in the UK
o nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities with settled or pre-settled status under the European Union Settlement Scheme (EUSS) (opens in a new window)
o nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities who have made a valid application for settled or pre-settled status under the European Union Settlement Scheme (EUSS)
o individuals with limited leave to remain or indefinite leave to remain who were eligible to apply for EUSS on or before 31 December 2020
o Turkish nationals, and certain family members of Turkish nationals, who have accrued the right to work in the Civil Service
Further information on nationality requirements (opens in a new window)

Working for the Civil Service
The Civil Service Code (opens in a new window) sets out the standards of behaviour expected of civil servants.
We recruit by merit on the basis of fair and open competition, as outlined in the Civil Service Commission's recruitment principles (opens in a new window).
The Civil Service embraces diversity and promotes equal opportunities. As such, we run a Disability Confident Scheme (DCS) for candidates with disabilities who meet the minimum selection criteria.
The Civil Service also offers a Redeployment Interview Scheme to civil servants who are at risk of redundancy, and who meet the minimum requirements for the advertised vacancy.

Diversity and Inclusion
The Civil Service is committed to attract, retain and invest in talent wherever it is found. To learn more please see the Civil Service People Plan (opens in a new window) and the Civil Service Diversity and Inclusion Strategy (opens in a new window).

+ Experience of working in an IT technical environment or having studied a STEM subject at A-Level or equivalent.
+ Being a good communicator who has the capability to explain complex technical information to senior management and other non-technical staff using language that is plainly understood.
+ Being a self-starter who is keen to learn about new and emerging technologies and cyber threats and how those threats may apply to a public sector organisation.
+ Demonstrate good customer service skills and experience with the ability to be adjustable in all situations., We'll assess you against these behaviours during the selection process:
o Making Effective Decisions
o Managing a Quality Service

Technical skills
We'll assess you against these technical skills during the selection process:
o Incident management and Information security - presentation

Defra is the UK government department responsible for safeguarding our natural environment, supporting our world-leading food and farming industry, and sustaining a thriving rural economy. Our broad remit means we play a major role in people's day-to-day life, from the food we eat, and the air we breathe, to the water we drink.
Digital, Data Technology and Security (DDTS) is the trusted team for digital across the entire Defra Group.
We have around 1,200 colleagues across DDTS and our ambition is to make it easier and faster than ever for people to interact with Defra. If you are ready to drive innovation and push boundaries, we want to hear from you. Join us and together we will create a great place for living, and a green and healthy future for all.

Alongside your salary of £32,136, Department for Environment, Food and Rural Affairs contributes £9,309 towards you being a member of the Civil Service Defined Benefit Pension scheme. Find out what benefits a Civil Service Pension provides.
o 25 days’ leave (rising to 30 days over 5 years) plus bank holidays.
o A Civil Service pension with an average employer contribution of 28.97%.
o A day off per year for the King's birthday.
o Access to a range of retail discounts (these include supermarket, tech, gym, holiday, phone and more).
o Flexible working options such as condensed hours, part-time and flexi time.
o 3 paid volunteering days per year.
o Funding for professional membership of a recognised professional body.
o Learning and development tailored to your role and budget for training or qualifications.
o A culture encouraging inclusion and diversity.
o Cycle to work scheme.
o Health cash plan to help you manage health costs for a reduced monthly fee.
o Access to the Employee Assistance Programme open 24 hours, 7 days a week, that provides support to you during any times of stress or difficulty.
o Free access to Headspace for wellbeing.
o Season ticket loan for public transport.
Equality, diversity and inclusion (EDI)
The Civil Service is committed to attract, retain and invest in talent wherever it is found. To learn more please see the Civil Service People Plan and the Civil Service D&I Strategy
Check out the video below from Jane McGeagh, Chief Operating Officer on why DDTS is a great place to work., New entrants to the Civil Service are expected to start on the minimum of the pay band. The internal roles rules apply to existing Civil Servants, i.e. level transfers move on current salary or the pay range minimum, transfers on promotion move to new pay range minimum or receive 10% increase. Either case is determined by whichever is the highest.
Visa sponsorship statement
Please take note that Defra does not hold a UK Visa & Immigration (UKVI) Skilled Worker License sponsor and are unable to sponsor any individuals for Skilled Worker Sponsorship.
Reasonable adjustment
If a person with disabilities is put at a substantial disadvantage compared to a non-disabled person, we have a duty to make reasonable changes to our processes.