Location
About the job
Job summary
We offer a diverse range of flexible working career opportunities: roles that are stimulating and rewarding, where you can get involved in ground-breaking work. It’s important to us to recruit from a wide range of professional and personal backgrounds – bringing different perspectives and experiences to our work. Within this role, you’ll be a part of our Cyber Profession within Ofgem alongside talented and collaborative individuals. Within this profession you’ll be supported across all aspects of personal and professional development throughout your career with Ofgem, boosted by our learning and development offering.
As a Cyber Security Analyst, you will play a vital role in ensuring the security of Ofgem. Through your involvement in identifying, containing and resolving security incidents, you will be able to identify opportunities to improve security of our systems and operations and enhance organisational awareness of security threats, as well as our readiness to manage them if they occur. You’ll collect and analyse security event data to identify potential malicious activity and support speedy resolution. You’ll work with colleagues to design and implement automated monitoring processes, making use of the latest Security Information and Event Management and network analysis tools, techniques and procedures.
We expect you will have experience in a Security Operations environment, where you’ve been responsible for analysing incidents across a complex environment. This includes experience in intrusion detection and analysis and you’ll be accustomed to working with network security and technologies alongside system, security, and network monitoring tools. This is an ideal opportunity for someone who already has some experience in Cyber Security to take the next step in their career. You’ll be part of a developing and expanding team, during a formative time, so there is real scope to make your mark and influence how the team works, making a personal contribution to shaping Ofgem’s security strategy.
Job description
Ofgem is a non-ministerial government department and an independent National Regulatory Authority. Our principal objective is to protect the interests of existing and future electricity and gas consumers. We do this by promoting value for money, promoting security of supply and sustainability, for present and future generations of consumers, domestic and industrial users, the supervision and development of markets and competition, regulation and the delivery of government schemes. We work effectively with, but are independent of, government, the energy industry and other stakeholders within a legal framework determined by the UK government and the European Union.
This role will be part of the Security, Privacy and Resilience function within the Corporate Services Directorate at Ofgem, ensuring that Ofgem maintains appropriate levels of security, privacy and resilience to protect; our people, data, operations, and facilities from harm.
Ofgem is proud to be an equal opportunity employer. We embrace diversity and are committed to creating an inclusive environment for all employees. All employment is decided on the basis of open and fair competition, merit and business need.
Key Responsibilities
The Cyber Security Analyst plays a critical part in ensuring the security of Ofgem, heavily involved in the monitoring of and investigation of security events and incidents.
You will identify, contain and assist in remediating incidents, identify potential process improvements, and maintain organisational readiness through preparedness exercises, advising product and service owners of potential mitigations.
- You will collect and analyse security event data arising from activity across the organisation, tune and improve generating security alerts, and follow up by investigating indicators of potentially malicious activity, escalating incidents or initiating responses as required.
- Monitor, triage and investigate security alerts across various monitoring platforms to identify security incidents and perform analysis of event data to support the response, reporting and resolution of security incidents.
- Support implementation of the monitoring roadmap to enhance monitoring in line with requirements, policies and standards to govern all activities and outputs.
- Operate as a key member of the security incident response team, providing log analysis and investigation as required.
- Assist project teams in the design, development and enablement of automated monitoring processes, recommending and implementing the latest SIEM (Security Information and Event Management) and network analysis tools, techniques and procedures to detect malicious activity.
Key Outputs and Deliverables
- Monitoring and response to various security alerting channels, including SIEM tools
- Daily investigations based on cyber threat intelligence from open sources and HMG partners
- Development of incident response playbooks
- Ongoing tuning of SIEM alerts and automation of regular tasks
- Assisting with remediation activities
- Undertake research and produce reports to improve knowledge of Ofgem cyber threat landscape
- Input into regular security control dashboard reporting
Key Stakeholder Relationships
External
- Other Government Departments’ Security Operations teams
- The National Cyber Security Centre (NCSC)
- Key vendor support personnel
Internal
- Security Operations Manager
- SecOps Team (Analysts / Engineers / Specialists)
- DDaT Operational Teams
Person specification
Essential Criteria
- Experience in a Security Operations environment (lead criteria)
- Demonstrable experience in analysing incidents across a complex environment
- Experience in intrusion detection and analysis
- Previous exposure to IT and network security and networking technologies and with system, security, and network monitoring tools
- Either holds, or has the ability to achieve, SC clearance.
Desirable Criteria
- Sound awareness of the threat environment faced by government, regulatory departments and the energy industry.
- Experience with M365 and Azure-related Security tooling
Behaviours
We’ll assess you against these behaviours during the selection process:
- Making Effective Decisions
- Delivering at Pace
- Working Together
Technical skills
We’ll assess you against these technical skills during the selection process:
- Please refer to the Candidate Pack attached for full details