At a Glance
- Tasks: Lead complex security investigations and enhance our security operations capabilities.
- Company: Join Companies House, a key player in UK cyber security.
- Benefits: Flexible working, 30 days leave, and a strong pension scheme.
- Other info: Collaborative culture with opportunities for continuous learning.
- Why this job: Make a real impact in protecting vital services from cyber threats.
- Qualifications: Proven experience in security operations and technical leadership.
The predicted salary is between 53540 - 68250 £ per year.
Location: Crown Way, Cardiff, UK; 1 Sibbald Walk, Edinburgh EH8 8FT, UK
Salary: 53,540 - 68,250 per year
Employment: Flexible
Category: Security
Posted: Valid to: Employer: Companies House
Job summary
Please note: Applicants should review all aspects of this advert to ensure a thorough understanding. If reviewing via a screen reader, please note that the Job summary, Job description, Person specification and Things you need to know sections have been emphasised.
About The Role
We are looking for an experienced and technically skilled Senior Lead Security Operations Analyst to play a key role in the continued development of Security Operations at Companies House. You will provide technical leadership within the Security Operations team, supporting analysts with complex investigations and helping to ensure security incidents are effectively identified, investigated, contained and escalated. You will remain hands-on, using security monitoring and threat detection technologies including Microsoft Sentinel, Microsoft Defender and Amazon Web Services security tooling to investigate activity across our cloud and technology environments. The role will also help drive improvements to our security monitoring capability, including developing and tuning detection rules, improving investigation and response processes, introducing automation and ensuring our monitoring continues to evolve alongside the threats facing Companies House.
We are looking for someone with:
- Strong security operations experience
- Excellent analytical and investigative skills
- The technical knowledge to lead complex investigations and support the development of others.
You should be comfortable working with large volumes of security and log data, making evidence-based decisions and communicating technical security issues clearly to both technical and non-technical colleagues. This is an opportunity to take a senior technical role within an evolving Security Operations capability and directly influence how Companies House detects, investigates and responds to cyber security threats.
Technical Frameworks
This role aligns with the Government Security Profession Secure Development Framework and the Government Digital and Data (GDaD) DevOps Engineer Capability Framework. Candidates may find these useful when preparing examples for their personal statement and demonstrating relevant technical skills and experience.
Your key responsibilities will include:
- Leading security investigations and incident response – taking technical ownership of complex or high-impact incidents and coordinating investigation, containment, remediation and escalation.
- Providing technical leadership – acting as a senior escalation point for analysts, providing guidance on complex investigations and supporting effective decision making.
- Developing security monitoring and detection – creating, reviewing and tuning security detections to improve our ability to identify malicious and suspicious activity.
- Managing and improving Microsoft Sentinel and Microsoft Defender – using and developing our security technologies to investigate threats, improve detection coverage and maintain effective monitoring.
- Monitoring cloud environments – detecting and investigating security activity across Amazon Web Services and Microsoft Azure using cloud security services, logs and other security telemetry.
- Improving automation and processes – identifying opportunities to automate Security Operations activities and improve monitoring, investigation and response workflows.
- Developing incident response capability – improving investigation procedures, playbooks and escalation processes and supporting security exercises and readiness activities.
- Developing the team – mentoring analysts, sharing technical knowledge and supporting the development of investigative and technical capability.
- Supporting operational leadership – helping prioritise and coordinate Security Operations activity and providing operational leadership in the absence of the Head of Security Operations when required.
- Working across Companies House – collaborating with security, cloud, platform, infrastructure and software engineering teams to investigate security issues and improve monitoring and response.
- Advising senior stakeholders – communicating significant incidents, risks and technical findings clearly and providing evidence-based recommendations.
- Driving continuous improvement – keeping pace with emerging threats and technologies and using lessons from incidents and operational activity to continually improve our security capability.
This is a hands-on technical role with technical and operational leadership responsibility. You will remain actively involved in security monitoring, investigations, detection engineering and incident response while helping to develop the capability of the wider Security Operations team.
About the team
The Security Operations team sits within the wider Security function at Companies House and is responsible for monitoring, detecting, investigating and responding to cyber security threats across our technology and cloud environments. We are a collaborative and technically focused team made up of Security Operations analysts, senior specialists and threat intelligence capability, working closely with colleagues across security, cloud, platform and engineering teams as well as external security partners. The team is continuing to develop and modernise its Security Operations capability, with a strong focus on Microsoft Sentinel and Microsoft Defender, alongside increasing security monitoring and response across Amazon Web Services.
We encourage new ideas, continuous improvement and knowledge sharing, with team members given the opportunity to develop their technical skills, take ownership of meaningful work and contribute to the future direction of Security Operations at Companies House. We have a supportive and collaborative culture where people are encouraged to challenge existing approaches, share knowledge and learn from each other.
Where will you be working?
You will be aligned to either the Cardiff or Edinburgh office, where you will be expected to attend at least once a week. We are currently using a hybrid approach to the way we work which provides opportunities for you to be adaptable in the way you work so that you can achieve a healthy balance between your work and home life.
What we’re looking for
The successful candidate will be an experienced cyber security professional with:
- Strong hands-on Security Operations expertise
- Significant hands-on experience working within Security Operations
- Strong practical experience using Microsoft Sentinel
- Strong experience working with Amazon Web Services
- Experience leading complex security investigations
- Experience developing and improving Security Operations capabilities
- Advanced knowledge of Microsoft Sentinel
- Strong knowledge of Amazon Web Services security
- Good working knowledge of Microsoft Defender security technologies
- Strong analytical and diagnostic skills
- Practical knowledge of scripting and security automation
- Strong understanding of cyber threats
Leadership and Abilities
Ability to provide technical leadership within Security Operations, lead complex investigations and provide authoritative guidance to analysts and other technical teams. Ability to mentor and develop others while communicating complex security incidents, risks and recommendations clearly to technical, non-technical and senior stakeholders.
Behaviours
We'll assess you against these behaviours during the selection process: Making Effective Decisions.
Technical skills
We'll assess you against these technical skills during the selection process: Cyber Security Operations, Intrusion Detection and Analysis and Incident Management, Incident Investigation and Response.
Benefits
Alongside your salary of 53,540, Companies House contributes 15,510 towards you being a member of the Civil Service Defined Benefit Pension scheme. We believe that our success is driven by the well-being and satisfaction of our team members at all levels of the organisation. At Companies House we’re committed to providing a comprehensive benefits package that goes beyond the ordinary, ensuring your career journey with us is not only fulfilling, but also rewarding.
We offer a comprehensive range of benefits designed to support your wellbeing, professional development and financial security, including:
- Flexible working arrangements, with no core hours and working patterns available between 6am and 8pm.
- Hybrid working opportunities, helping you balance office collaboration with home working.
- 30 days annual leave, plus bank holidays, increasing with service.
- Civil Service Pension Scheme, with an average employer contribution of 28%.
- A strong commitment to learning, development and career progression.
- Access to wellbeing support, resources and initiatives that promote positive physical and mental health.
- A collaborative and inclusive working environment where colleagues are encouraged to bring their whole selves to work.
Things you need to know
Artificial intelligence can be a useful tool to support your application, however, all examples and statements provided must be truthful, factually accurate and taken directly from your own experience. Where plagiarism has been identified, applications may be withdrawn and internal candidates may be subject to disciplinary action.
Selection process details
This vacancy is using Success Profiles, and will assess your Behaviours, Experience and Technical skills. Successful candidates must meet the security requirements for Security Check (SC) before they can be appointed.
To be eligible for SC clearance, candidates must meet the vetting criteria and have been a resident in the UK for at least 3 out of the last 5 years. Failure to meet the residency requirements will result in your security clearance application being rejected.
We welcome applications in Welsh / Rydym yn croesawi ceisiadau yn y Gymraeg.
Senior Lead Security Operations Analyst in Cowbridge employer: Companies House
Companies House is an exceptional employer, offering a flexible and inclusive work culture that prioritises employee wellbeing and work-life balance. With a strong commitment to career development, employees benefit from a comprehensive package that includes generous annual leave, a robust pension scheme, and opportunities for continuous learning and progression within a supportive community. Located in vibrant Cardiff or Edinburgh, this role allows you to be part of a significant digital transformation, contributing to meaningful public services while enhancing your technical and leadership skills.
StudySmarter Expert Advice🤫
We think this is how you could land Senior Lead Security Operations Analyst in Cowbridge
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Companies House, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through Companies House
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Companies House. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace Senior Lead Security Operations Analyst in Cowbridge
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Companies House insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Companies House that you’re committed to staying ahead in the game.
How to prepare for a job interview at Companies House
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at Companies House to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Companies House.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.