Location
About the job
Job summary
The Government Security Function (GSF) oversees the delivery of protective security across Government. Our Mission is to enable Government to protect citizens and provide vital public services by understanding and managing security risks. We set the strategy and standards for Government Security, monitor departmental security performance, manage pan-government security incidents, support the delivery of key security capabilities and lead the Government Security Profession.
The Government Security Group (GSG) is the centre of the Security Function, based within the Cabinet Office. GSG is transforming the Government’s approach to protective security to ensure it is fit to meet the challenges of the digital age. This role offers an exciting opportunity to work in a fast-paced, dynamic team, with a breadth of stakeholders including in other Government departments, the National Technical Authorities and the Agencies, and to contribute to delivering improved security across Government.
Who are we?
As our name suggests, Government Security Group (GSG) is charged with overseeing the security of HM Government (HMG).
The newly formed Cyber Directorate within GSG (also known as GSG Cyber) is a team of subject matter experts finding innovative solutions across HMG in response to the cyber security challenge. GSG Cyber covers all aspects of Defensive Cyber Security for HMG, from strategy, policy and standards to the operational deliverables of incident response, risk, threat intelligence and vulnerability management.
The Cyber Incident Response Analyst will be joining the Cyber Operations team which sits within GSG Cyber. We support GSG with understanding, managing and reporting cyber operational risk across the Government sector, working closely with the Cabinet Office National Security team and the National Cyber Security Centre (NCSC).
If you’re passionate about protecting Government and the public, want to be part of a security evolution, and have a grounding in cyber security, this is the team for you.
Job description
The Cyber Incident Response Analyst role plays a central role at the heart of government incidents, working closely with the NCSC, Government departments, and the National Security Unit. You will support with the coordination of GSG’s response to cyber incidents, working to understand their impacts to HMG individually and collectively, drafting and promoting protective advice. This will offer you unique insights into incidents affecting the breadth of Government, how it responds to these, and becomes stronger as a result.
The work is variable and interesting and you will develop strong contacts across HMG. You will also be involved with the COBR process as required, support with briefings to senior government officials and help drive the security agenda of Government.
As part of the wider Cyber Operations team, you will also support the delivery of the Government Cyber Coordination Centre (GCCC) by collaborating across the incident management community, working with NCSC and the Central Digital and Data Office (CDDO) to develop ground-breaking ways to work with government data and processes.
You will ensure we are collecting and exploiting the right kinds of data to understand impact and risk to Government from cyber events and incidents, individually and collectively. You will also help ensure we are identifying the right lessons from them, to help Government become stronger, more resilient and more secure. Your work will allow Government to “Defend as One,” as part of the expectation set out in the Government Cyber Security Strategy (GCSS).
Ideally you will have some experience of working in a crisis management or incident response environment but this is not critical. A good understanding of cyber security would be a real advantage, though you do not have to be a technical expert for this role.
Key areas of responsibility
The post holder will be responsible for:
- Supporting GSG respond to cyber incidents affecting departments across HMG.
- Develop data driven insights into cross government incidents to inform strategic objectives.
- Develop and maintain subject matter expertise on cyber incidents affecting Government as a sector.
- Identifying lessons from incidents, as well as themes and trends across these, to increase HMG’s resilience against cyber attack by sharing across government to Defend as One under the newly formed Government Cyber Co-ordination Centre.
- Informing government strategy, policy and cyber assurance activity.
- Development of advice and support to government departments.
- Support to National Security processes including COBR.
Person specification
Essential skills and experience:
- Experience of working in cyber security.
- Analytical experience including data analysis, research and creativity.
- Experience of working with a range of stakeholders.
Desirable skills and experience:
- Experience of working in a cyber incident response function and/or SOC/Operations environment.
- Understanding of what good cyber incident response looks like, as well as common challenges.
- Experience of developing data-driven insights to inform strategic goals.
Behaviours
We’ll assess you against these behaviours during the selection process:
- Changing and Improving
- Communicating and Influencing
- Delivering at Pace
Benefits
- Learning and development tailored to your role.
- An environment with flexible working options.
- A culture encouraging inclusion and diversity.
- A Civil Service Pension which provides an attractive pension, benefits for dependants and average employer contributions of 27%.
- A minimum of 25 days of paid annual leave, increasing by one day per year up to a maximum of 30.
- Our cyber posts attract a skills based DDAT non pensionable allowance. In certain circumstances exceptional candidates may be eligible for a higher starting salary.