At a Glance
- Tasks: Lead a team in advanced threat hunting and detection engineering to enhance cybersecurity.
- Company: Join NESO, a key player in securing Great Britain's energy future.
- Benefits: Enjoy a competitive salary, bonus potential, flexible working, and generous leave.
- Other info: Diverse and inclusive workplace with excellent career growth opportunities.
- Why this job: Make a real impact in cybersecurity while shaping a sustainable energy future.
- Qualifications: Experience in threat hunting and security engineering; leadership skills are a plus.
The predicted salary is between 70000 - 80000 £ per year.
NESO are looking to hire a manager for an established Threat Hunting and Detection Engineering Team. The Threat Hunting and Detection Engineering team work alongside the Cyber Security Operations Centre (CSOC). The team develop industry leading threat detection capabilities across two SIEM platforms. The team also perform advanced threat hunting, enabling us to go beyond day-to-day detections, identifying advanced or unknown threats early.
The Threat Hunting and Detection Engineering Manager will manage a team of threat hunting analysts. The team will identify, assess, prioritise and deliver threat hunting activities, whilst ensuring threat led detection content is continuously applied to the SIEM. The team also provide Subject Matter Expertise and analysis in support of security incident management.
This role can be based from Wokingham or Warwick, and we continue to offer hybrid working from office and home. We are open to full time and part time applicants, as well as flexible working arrangements.
This role is designated as requiring a National Security Vetting (NSV) clearance. The level of clearance associated with the role is Security Check (SC). You will usually need to have been a resident in the UK for the last five years to apply for an SC clearance. We would invite any applicants who do not currently meet this residency requirement to still express an interest in the role.
Key Accountabilities- Lead and manage threat hunting and content development to enable an effective Cyber Security Operations team.
- Partner with Cyber Security Operations, Incident Response, Threat Intelligence, and Security Engineering to agree and prioritise requirements for threat detection and threat hunting.
- Be accountable for the development and deployment of a prioritised set of threat detection rules across two SIEM platforms.
- Be accountable for the development and maintenance of work instructions and playbooks to enable the CSOC analysts to triage and respond to events.
- Develop and maintain security content, such as rules, signatures, indicators, dashboards, reports, etc., to enhance the detection and response capabilities of the CSOC.
- Provide subject matter expertise and analysis support in the event of security incidents.
- Support the team to ensure they utilise detection as code and secure development pipelines.
- Ensure an intake process is managed to allow a feedback loop from the CSOC.
- Conduct proactive, iterative, and human-centric identification and analysis of cyber threats that have evaded existing security controls.
- Coordinate and collaborate with internal and external stakeholders, such as IT teams, business units, vendors, auditors, and regulators.
- Provide regular reports and metrics on the threat hunting and content development activities, outcomes, and value.
- Develop and implement threat hunting and content development policies, standards, procedures, and best practices.
We’re forging the path, and we know we can’t do it alone. That’s why we need visionary minds like yours to join us on this transformative journey. In this case, we’re looking for someone who:
- A desire to take on an active leadership role, remaining engaged with the team deliverables.
- Team player and adept at working in multi-disciplinary and diverse teams.
- In-depth knowledge and experience in threat hunting, content development, security engineering concepts, operations, analysis, and response.
- Proficient in various threat hunting and content development tools and technologies, such as SIEM, IDS, IPS, firewall, antivirus, encryption, VPN, etc.
- Familiar with various security frameworks and standards, such as NIST and NCSC CAF.
- Strong analytical and problem-solving skills and ability to handle complex and dynamic situations.
- Excellent communication and presentation skills and ability to communicate effectively with technical and non-technical audiences.
- Sound knowledge of IT systems, networks, applications, and cloud services.
- Awareness of current and emerging cyber threats, trends, and best practices.
Relevant degree-level qualification or equivalent experience with strong background in providing threat hunting services in a large hybrid environment, within a government or critical infrastructure domain. Significant experience in threat hunting, content development, security engineering, operations, or related field with strong demonstrable experience in managing or leading security teams or projects. Relevant professional certifications, such as CISSP, CISM, GSEC, GCIA, GCED, etc.
Don’t meet every single requirement? Studies have shown that women and people of colour are less likely to apply for jobs unless they meet every single qualification. At NESO, we are committed to building a diverse, inclusive, and authentic workplace for everyone. So, if you’re excited about this role but your experience or qualifications don’t match the job description exactly, we encourage you to apply anyway. You might just be the right person for our growing business in this role or another one.
What You'll GetA competitive salary of £70,000 - £80,000 dependent on experience and capability. As well as your base salary, you will receive a bonus of up to 15% of your salary for stretch performance, 28 days annual leave as standard, and a competitive contributory pension scheme where we will double match your contribution to a maximum company contribution of 12%. NESO's flexible benefits programme provides you with more flexibility around your health, lifestyle and protection benefits.
- Flexible Bank Holidays & Holiday Trading
- Additional Birthday Day Off
- Cycle to Work Scheme, Retail & Gym Discounts
- Private Medical Insurance, Critical Illness Insurance & Personal Accident Insurance
At the National Energy System Operator (NESO), we play a vital role in tackling climate change and securing Great Britain's energy future. We already operate the world's fastest decarbonising electricity system and are working towards our ambition to run it carbon-free for a short period this year - provided the market supplies electricity exclusively from renewable sources. Alongside this, we provide expert advice to government on how to deliver a clean power system by 2030.
In autumn 2024, the Electricity System Operator (ESO) transitioned to become NESO - an independent, expert public corporation with a whole-system view across electricity, gas, and hydrogen. NESO operates independently and transparently, always acting in the best interests of all energy users. Licensed and regulated by Ofgem, we make impartial decisions that balance sustainability, affordability and security. Our organisation is fully independent from government, the regulator and all commercial interests, with a clear focus on system-wide benefit, long term thinking and public value.
The time to deliver is now. Join the energy transformation and help shape the future. Your energy. Our future. Together.
National Energy System Operator (NESO) recognises the potential of bright and talented individuals, and we encourage you to join us as Great Britain’s energy system undergoes an ambitious, exciting, and vital transformation. Together with industry, we are creating a cleaner, more sustainable energy future.
More InformationThis role closes at 23:59, on the day before date shown above, however we encourage candidates to submit their application as early as possible and not wait until the published closing date as this can vary. Research shows that some people may hesitate to apply unless they meet every single requirement. At NESO, we believe potential comes in many forms and we're committed to a fair, inclusive recruitment process where everyone has the opportunity to show their talents. We celebrate the difference people can bring into our organisation, and welcome and encourage applicants with diverse experiences and backgrounds.
Threat Hunting and Detection Engineering Manager in Wokingham employer: National Energy System Operator Limited
At NESO, we pride ourselves on being an exceptional employer, offering a dynamic work culture that fosters innovation and collaboration in the field of cyber security. With competitive salaries, flexible working arrangements, and a strong commitment to employee growth through training and development opportunities, we empower our team members to thrive in their careers while contributing to a sustainable energy future. Our locations in Wokingham and Warwick provide a supportive environment where diverse talents are celebrated, ensuring that every individual feels valued and has the chance to make a meaningful impact.
Contact Details:
National Energy System Operator Limited Recruitment Team
StudySmarter Expert Advice🤫
We think this is how you could land Threat Hunting and Detection Engineering Manager in Wokingham
✨Tip Number 1
Network like a pro! Reach out to folks in the industry, attend meetups, and connect with people on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Tip Number 2
Prepare for interviews by practising common questions and scenarios related to threat hunting and detection. Get comfortable explaining your thought process and how you tackle complex problems—this will show you're the right fit for the team.
✨Tip Number 3
Showcase your skills through projects or case studies. If you've worked on threat detection or hunting initiatives, be ready to discuss them in detail. This hands-on experience can really set you apart from other candidates.
✨Tip Number 4
Don't forget to apply through our website! It’s the best way to ensure your application gets seen. Plus, it shows you're genuinely interested in joining our team at NESO and contributing to our mission.
We think you need these skills to ace Threat Hunting and Detection Engineering Manager in Wokingham
Some tips for your application 🫡
Tailor Your Application:Make sure to customise your CV and cover letter to highlight your experience in threat hunting and detection engineering. Use keywords from the job description to show that you understand what we're looking for.
Showcase Your Leadership Skills:As a manager, we want to see your leadership style. Share examples of how you've led teams in the past, especially in cyber security contexts. This will help us envision you in the role!
Be Clear and Concise:When writing your application, keep it straightforward. We appreciate clarity, so avoid jargon unless it's relevant. Make it easy for us to see your qualifications and fit for the role.
Apply Through Our Website:We encourage you to submit your application through our website. It’s the best way to ensure your application gets seen by the right people. Plus, it’s super easy to do!
How to prepare for a job interview at National Energy System Operator Limited
✨Know Your Threat Hunting Basics
Before the interview, brush up on your knowledge of threat hunting and detection engineering. Be ready to discuss specific tools and technologies like SIEM, IDS, and IPS, as well as your experience with them. This will show that you’re not just familiar with the concepts but can also apply them in real-world scenarios.
✨Showcase Your Leadership Skills
As a manager, you'll need to demonstrate your leadership abilities. Prepare examples of how you've successfully led teams in the past, particularly in high-pressure situations. Highlight your approach to team collaboration and how you’ve fostered a culture of continuous improvement within your teams.
✨Prepare for Scenario-Based Questions
Expect scenario-based questions that assess your problem-solving skills and analytical thinking. Think about past incidents you've managed or challenges you've faced in threat detection. Be ready to explain your thought process and the steps you took to resolve those issues.
✨Understand the Company’s Mission
Familiarise yourself with NESO's mission and values, especially their commitment to sustainability and energy transformation. Be prepared to discuss how your skills and experiences align with their goals. Showing that you understand and resonate with their mission can set you apart from other candidates.