Lead Offensive Security Operator

Lead Offensive Security Operator

Full-Time 46500 - 65000 £ / year (est.) Home office (partial)
Justice Digital

At a Glance

  • Tasks: Lead cyber-attack simulations to test and improve security measures.
  • Company: Join Justice Digital, a team of 900 tech specialists transforming the justice system.
  • Benefits: Enjoy flexible working, a £1k learning budget, and generous leave policies.
  • Other info: Hybrid working model with opportunities for professional development.
  • Why this job: Be part of a collaborative team making a real impact in cyber security.
  • Qualifications: Experience in complex operations and strong communication skills required.

The predicted salary is between 46500 - 65000 £ per year.

Location: National

Closing Date: 30th June

Interviews: W/C 14th July (subject to change)

Grade: G7 (MoJ candidates who are on a specialist grade, will be able to retain this grade on lateral transfer)

Salary: National: £56532 - £73450 (which may include an allowance of up to £16918). London: £61201 - £78225 (which may include an allowance of up to £17024).

Working pattern: Full-time, part-time, flexible working, job share.

Contract Type: Permanent.

We offer a hybrid working model, allowing for a balance between remote work and time spent in your local office.

The Role

We’re recruiting for a Lead Offensive Security Operator here at Justice Digital, to be part of our warm and collaborative Digital Infrastructure and Security Operations Team (DISO). The team is responsible for the live services, delivery, product changes and developments for all networking, security, voice, video and hosting services across the MoJ estate. This role aligns against Penetration Testing Principle from the Government Security Profession.

You will be part of a small team of cyber red teaming specialists who provide independent full-spectrum adversary emulation services to security stakeholders within the Ministry of Justice. You will conduct safe, simulated cyber-attack simulations against our technology estates, acting as a real-world adversary might, to test our defences, highlight weaknesses and contribute cyber security expertise and insight in support of the department's strategic security decision-making functions.

Key Responsibilities:

  • Designing and executing threat intelligence-based full-spectrum cyber-attack simulations, including long-term campaign planning, persistence, and post-exploitation operations against the Ministry of Justice.
  • Adopting a red team approach, discovering high-impact weaknesses across the organisation’s most important technology estates and business areas, and validating whether the overarching cyber security apparatus is working effectively.
  • Communicating technical findings in clear risk and impact-focused terms to senior stakeholders, enabling effective understanding and support for strategic decision-making.
  • Development and implementation of technology platforms, tools and methodologies to augment and to automate team offensive and analytical capability.
  • Mentoring junior Red Team members to improve their skills and capabilities, along with wider knowledge transfer to other security and non-security teams to help build a culture of cyber security in the department.

37 hours per week and flexible working options including working from home, working part-time, job sharing, or working compressed hours.

A £1k per person learning budget is in place to support all our people, with access to best in class conferences and seminars, accreditation with professional bodies, fully funded vocational programmes and e-learning platforms.

Staff have 10% time to dedicate to develop & grow.

Generous civil service pension based on defined benefit scheme, with employer contributions of 28.97% from April 1st 2024.

25 days leave (plus bank holidays) and 1 privilege day usually taken around the Kings’ birthday. 5 additional days of leave once you have reached 5 years of service.

Compassionate maternity, adoption, and shared parental leave policies, with up to 26 weeks leave at full pay, 13 weeks with partial pay, and 13 weeks further leave. And maternity support/paternity leave at full pay for 2 weeks, too!

Wellbeing support including access to the Calm app.

Bike loans up to £2500 and secure bike parking (subject to availability and location).

Season ticket loans, childcare vouchers and eye-care vouchers.

Free membership to BCS, the Chartered Institute for IT.

Some offices may have a subsidised onsite Gym.

Person Specification

  • Proven ability to plan and execute complex, multi-phase operations, including scenario-driven adversary simulation.
  • Threat intelligence analysis and assessment.
  • Exploitation of a wide range of technologies, including infrastructure, web application and cloud platforms.
  • Post-exploitation, persistence and lateral movement, including tactical analysis of attack paths leading to high-value targets.
  • Conducting engagement activities in line with operational security best practice and within a range of threat actor capabilities and tradecraft.
  • Deep understanding of security technologies found in end-user and server operating systems and supporting infrastructure.
  • Experience using, developing and deploying tools in support of red teaming activities.
  • Strong communication skills with the ability to clearly explain complex technical issues related to vulnerabilities and risk to diverse audiences.
  • Experience in threat and/or vulnerability research, including publication and presentation to the wider cyber security community.
  • Willingness to be assessed against the requirements for SC clearance.

How to Apply

Candidates must submit a CV and statement of suitability (of no more than 750 words) via our applicant website Jobtrain, which describes how you meet the requirements set out in the Person Specification above.

Applicants who do not submit both a CV and a separate statement of suitability will not be invited to attend an interview.

In Justice Digital, we recruit using a combination of the Government Security Profession and Success Profiles Frameworks. We will assess your Experience, Technical Skills and the following Behaviours during the assessment process: Communicating and Influencing, Delivering at pace.

A diverse panel will review your application against the Person Specification above. Successful candidates who meet the required standard will then be invited to a 1-hour panel interview held via video conference.

Should we receive a high volume of applications, a pre-sift based on the following criteria will be conducted before the sift - Proven ability to plan and execute complex, multi-phase operations.

Should you be unsuccessful in the role that you have applied for but demonstrate the capability for a role at a lower level, we reserve the right to discuss this opportunity with you and offer you the position without needing a further application.

A reserve list may be held for up to 12 months, from which further appointments may be made.

Terms & Conditions

Please review our Terms and Conditions which set out how we recruit and provide further information related to the role and salary arrangements.

If you have any questions, please feel free to contact digitalanddatarecruitment@justice.gov.uk

Please note that if you are NOT a passport holder of the country for the vacancy you might need a work permit.

Bank or payment details should not be provided when applying for a job.

Lead Offensive Security Operator employer: Justice Digital

Justice Digital Data and Science is an exceptional employer, offering a dynamic work environment where innovation meets security. With a strong focus on employee development, generous benefits including a robust pension scheme and ample leave, as well as the flexibility of hybrid working, this role provides a unique opportunity to shape the future of security architecture within the Ministry of Justice. Join us to make a meaningful impact while advancing your career in a supportive and forward-thinking culture.

Justice Digital

Contact Details:

Justice Digital Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Lead Offensive Security Operator

Tip Number 1

Familiarise yourself with the latest trends and techniques in offensive security. This role requires a deep understanding of various attack methodologies, so being well-versed in current practices will help you stand out during discussions.

Tip Number 2

Network with professionals in the cyber security field, especially those involved in red teaming. Engaging with the community can provide insights into the role and may even lead to referrals or recommendations.

Tip Number 3

Prepare to discuss your experience with complex, multi-phase operations. Be ready to share specific examples of past projects where you've successfully executed adversary simulations or threat intelligence analysis.

Tip Number 4

Showcase your communication skills by practising how to explain technical concepts to non-technical stakeholders. This is crucial for the role, as you'll need to convey findings clearly to senior management.

We think you need these skills to ace Lead Offensive Security Operator

Penetration Testing
Threat Intelligence Analysis
Adversary Simulation
Exploitation Techniques
Post-Exploitation Tactics
Communication Skills
Technical Writing

Some tips for your application 🫡

Understand the Role:Before you start writing your application, make sure you fully understand the responsibilities and requirements of the Lead Offensive Security Operator position. Familiarise yourself with the key responsibilities mentioned in the job description, such as conducting cyber-attack simulations and mentoring junior team members.

Craft a Strong CV:Your CV should highlight relevant experience and skills that align with the job description. Focus on your proven ability to plan and execute complex operations, as well as your experience with threat intelligence analysis and exploitation of various technologies. Tailor your CV to showcase achievements that demonstrate your suitability for this role.

Write a Compelling Statement of Suitability:In your statement of suitability (up to 750 words), clearly articulate how your experience meets the requirements set out in the Person Specification. Use specific examples to illustrate your skills in communication, technical expertise, and your ability to deliver results under pressure. Make sure to address each point in the specification to strengthen your application.

Proofread and Edit:Before submitting your application, take the time to proofread your CV and statement of suitability. Check for any spelling or grammatical errors, and ensure that your documents are clear and concise. A well-presented application reflects your attention to detail and professionalism, which is crucial for a role in security operations.

How to prepare for a job interview at Justice Digital

Understand the Role Thoroughly

Before your interview, make sure you have a solid grasp of the responsibilities and expectations for the Lead Offensive Security Operator position. Familiarise yourself with the key tasks such as conducting cyber-attack simulations and communicating findings to stakeholders.

Showcase Your Technical Skills

Be prepared to discuss your experience with various technologies and methodologies relevant to offensive security. Highlight specific tools you've used in red teaming activities and be ready to explain complex technical concepts in simple terms.

Prepare for Scenario-Based Questions

Expect questions that assess your ability to plan and execute complex operations. Think of examples from your past experiences where you successfully managed multi-phase operations or conducted threat intelligence analysis.

Demonstrate Strong Communication Skills

Since the role involves communicating technical findings to non-technical stakeholders, practice articulating your thoughts clearly and concisely. Use examples to illustrate how you've effectively communicated risks and vulnerabilities in previous roles.