Cyber Incident Operations Manager

HMRC

Leeds

On-site

GBP 45,000 - 65,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Labour Market Supplement for qualifications

Job summary

A government agency is seeking a Cyber Incident Operations Manager to lead a team in addressing cybersecurity threats and managing incidents. The ideal candidate will have a strong technical background in cybersecurity, excellent leadership skills, and experience with incident response. This role involves analyzing security data, managing threats, and ensuring best practices in incident management. A SANS certification or relevant SOC experience is required, along with familiarity with security technologies like SIEM and EDR.

Qualifications

  • Strong technical background in cybersecurity.
  • Proven track record of managing incident response teams.
  • Excellent vendor stakeholder management skills.

Responsibilities

  • Triaging and investigating security alerts.
  • Managing the response to cybersecurity incidents.
  • Developing alerts against large data sets.
  • Performing malware analysis.
  • Establishing and maintaining incident response processes.
  • Serving as a subject matter expert on cybersecurity frameworks.
  • Conducting computer forensic analysis.

Skills

Cybersecurity management
Incident response
Vendor stakeholder management
Leadership
Problem-solving

Education

SANS certification
Experience in SOC

Tools

SIEM
EDR
IDPS

Job description

Overview

Join to apply for the Cyber Incident Operations Manager role at HMRC.

This range is provided by HMRC. Your actual pay will be based on your skills and experience — talk with your recruiter to learn more.

Cyber Security provides vital protection for digital assets that provide essential services to the public. This role is essential for the investigation and review of our systems and data to identify security weaknesses, provide recommendations to improve our security posture and to drive delivery of those improvements.

The outcome of the role is to methodically identify and reduce threats to the HMRC estate using the technical countermeasures we have available. Ensuring our cyber security controls are effective and fit for purpose with accurate configuration and security posture. As well as continuously identifying new technical controls to answer risks.

You’ll work in our Incident Management Team, an exciting and fast paced group responsible for monitoring and responding to cyber threats. You will lead a team of 6 specialists, providing support and guidance on technical issues whilst remaining cool under pressure.

You will have a strong technical background in cybersecurity, a proven track record of managing incident response teams, excellent vendor stakeholder management skills and possess exceptional leadership, communication, and problem-solving skills.

Responsibilities
  • Triaging and investigating security alerts from multiple systems.
  • Managing the response to cybersecurity incidents and related investigations, following the incident response lifecycle, to a timely and effective resolution.
  • Developing alerts and use cases against very large data sets over some of the latest technology.
  • Malware analysis: ability to perform static and dynamic malware analysis to understand the nature of malware.
  • Establish and maintain incident response processes, procedures, and documentation, ensuring they align with industry best practices.
  • Serve as a subject matter expert on cyber security frameworks, including NIST, MITRE ATT&CK, and the Cyber Kill Chain.
  • Computer forensic analysis: experience using a variety of forensic analysis tools in incident response investigations to determine the extent and scope of compromise.
Person specification

You will be curious and inquisitive by nature, a person who enjoys getting to the root cause of issues, especially around threats to our network.

You are a team player who enjoys working collaboratively with colleagues across teams and business areas, including suppliers.

You will have proven analytical skills, using data and information in various formats. You will have good report writing and presentation skills.

Qualifications/Knowledge

At least one of the following:

  • SANS certification.
  • Experience of working in a SOC as part of an incident response function.
  • Experience using common security technologies such as SIEM, EDR, IDPS, and Network Security Analysis.

EDR and other Microsoft monitoring systems (MCAS, etc).

Good understanding of Threat Hunting TTPs.

Seniority level
  • Mid-Senior level
Employment type
  • Full-time
Job function
  • Information Technology and Legal
Industries
  • Government Administration
Benefits

Labour Market Supplement (LMS) will be paid for suitable qualifications and experience.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Chief Security Officer
Chief Security Officer

Global Resourcing • England

Hybrid
GBP 100,000 - 163,000
Cyber Security Manager
Cyber Security Manager

Virgin Atlantic • Crawley

On-site
GBP 90,000 - 140,000
Digital Investigator - National Digital Investigation Unit
Digital Investigator - National Digital Investigation Unit

HM Revenue & Customs • England

Hybrid
GBP 30,000 - 45,000
Cyber Security Architect
Cyber Security Architect

HM Revenue & Customs • England

On-site
GBP 60,000 - 80,000
SOC – Cyber Threat Operations Specialist
SOC – Cyber Threat Operations Specialist

Advantage Resourcing UK Ltd • Stevenage

On-site
GBP 97,000 - 138,000
Cyber Security Consultant
Cyber Security Consultant

HM Revenue & Customs • England

Hybrid
GBP 50,000 - 70,000
Senior Manager - Cyber Incident & Response - Consulting
Senior Manager - Cyber Incident & Response - Consulting

Oliver James • Greater London

On-site
GBP 120,000 - 180,000
Control Room Officer
Control Room Officer

HM Revenue & Customs • Gillingham

On-site
GBP 31,000 - 36,000
Civil Service Pension contributions
Flexible and hybrid working options
Generous leave allowance
NMC Senior Cyber Threat Hunter
NMC Senior Cyber Threat Hunter

Women in Data® • Wigan

Hybrid
28 days annual leave plus bank holidays
Flexible working hours
Employee Assistance Program (EAP)
Lead Cyber Security Risk Manager
Lead Cyber Security Risk Manager

UK Home Office • Salford

Hybrid
GBP 63,000 - 80,000
Civil Service Pension
25 days annual leave
Public holidays