At a Glance
- Tasks: Develop and deploy SIEM detection rules to combat cyber threats.
- Company: Join the Police Digital Service, a leader in tech for UK policing.
- Benefits: Enjoy 28 days annual leave, competitive salary, and professional growth.
- Why this job: Make a real difference in public safety through innovative cyber security solutions.
- Qualifications: Experience in log analysis, SIEM platforms, and software development required.
- Other info: Dynamic role with opportunities for continuous learning and career advancement.
The predicted salary is between 42000 - 58000 Β£ per year.
Join Police Digital Service as NMC Cyber Security Detection Engineer x 2. Full time Permanent. Salary starting at Β£50,000.
About Police Digital Service
To protect people from harm in our rapidly changing world, police services must not only keep up with technology and business changes but develop capabilities and ways of working that will enable them to adapt to and deal with the complexity of modern criminality. Police Digital Service strives to be the go-to partner for technology developments and programmes across UK policing. Our team provides technical advice and delivers services to help policing and law enforcement organisations across the UK prioritise and focus on technology efforts. Our vision is to support UK policing to keep people safe, get more from technology investments and make better use of public money, and weβre always on the lookout for great talent to help us achieve this.
The National Management Centre (NMC) is part of Police Digital Service and provides visibility and control of information risks for policing. It supports the 24x7x365 nature of police operations, providing a threat detection and response capability for digital services before, during and after cyber-attacks, enabling stakeholders to understand and proactively manage risk across the technology estate at both the national and force level.
Key Responsibilities
- Development, maintenance, and deployment of SIEM detection rules for complex technical environments.
- Working alongside wider NMC functions, maintain knowledge of the threat landscape and TTPs employed by threat actors.
- Work across wider NMC functions to ensure detections are relevant and effective.
- Creation of custom solutions using both low-code and traditional development approaches.
- Optimization of log collection to align with detection requirements.
- Maintain documentation for detection rules to be used by analysts.
- Scoping, testing and implementing new SIEM data connectors.
- Working with wider NMC teams, contributing to Continual Service Improvement and innovations.
- Support with the creation of automation and analyst playbooks.
What you need to succeed in the role
Essential:
- Experience with log analysis and correlation of large datasets from multiple data sources to identify and investigate attack patterns.
- Experience of supporting and developing SIEM platforms in the context of a Security Operations Centre.
- Experience of log source configuration and parsing, as part of a SIEM implementation, including experience of data normalisation using RegEx.
- Practical experience in the creation, testing, implementation, and support of custom tooling to support Security Operations.
- Experience working with APIs.
- Practical experience in software development and scripting, preferably PowerShell and Python.
- Initiative and the ability to produce quality work without close supervision.
- Good written and verbal communication skills, particularly in relation to technical subjects.
- Attention to detail and genuine passion for maintaining high quality software configuration.
- Broad cyber security awareness and practical experience.
- Experience working with code repositories and CI/CD.
- Ability to acquire SC and NPPV3 level clearances.
Desirable:
- Certifications that demonstrate a combination of offensive and defensive knowledge - PNPT / OSCP / BTL2 / GCFAP.
- Practical experience in software development and scripting, preferably PowerShell and Python.
- Previous public sector experience.
- Previous SOC or security engineering experience.
- Previous experience monitoring the security of cloud technologies.
- Experience with Microsoft Power Apps / Power Automate and Azure Logic Apps.
Why Join us?
Balance is important and we want you to take time off to recharge - we offer 28 days' annual leave plus.
Nmc Cyber Security Detection Engineer in Rishton employer: Police Digital Services
Contact Detail:
Police Digital Services Recruiting Team
StudySmarter Expert Advice π€«
We think this is how you could land Nmc Cyber Security Detection Engineer in Rishton
β¨Tip Number 1
Network like a pro! Reach out to folks in the cyber security field, especially those working at Police Digital Service. Attend industry events or webinars, and donβt be shy about asking for informational interviews. You never know who might have the inside scoop on job openings!
β¨Tip Number 2
Show off your skills! Create a portfolio showcasing your projects, especially any SIEM detection rules or custom tooling you've developed. This will give potential employers a tangible sense of what you can bring to the table.
β¨Tip Number 3
Prepare for the interview like itβs a cyber attack! Research common interview questions for cyber security roles and practice your responses. Be ready to discuss your experience with log analysis and SIEM platforms in detail.
β¨Tip Number 4
Apply through our website! Itβs the best way to ensure your application gets seen by the right people. Plus, it shows youβre genuinely interested in joining our team at Police Digital Service.
We think you need these skills to ace Nmc Cyber Security Detection Engineer in Rishton
Some tips for your application π«‘
Tailor Your CV: Make sure your CV is tailored to the NMC Cyber Security Detection Engineer role. Highlight your experience with SIEM platforms, log analysis, and any relevant projects you've worked on. We want to see how your skills match what we're looking for!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about cyber security and how your background makes you a great fit for our team. Keep it concise but engaging β we love a good story!
Show Off Your Technical Skills: Donβt shy away from showcasing your technical skills in your application. Mention your experience with PowerShell, Python, and any custom tooling you've developed. Weβre keen to see how you can contribute to our mission!
Apply Through Our Website: We encourage you to apply through our website for a smoother process. It helps us keep track of applications and ensures you get all the updates directly from us. Plus, itβs super easy!
How to prepare for a job interview at Police Digital Services
β¨Know Your SIEM Inside Out
Make sure youβre well-versed in the specifics of SIEM platforms. Brush up on your experience with log analysis and correlation, as well as any custom tooling you've developed. Being able to discuss your hands-on experience confidently will show that youβre not just familiar with the theory but have practical skills to back it up.
β¨Stay Updated on Cyber Threats
Familiarise yourself with the current threat landscape and the tactics, techniques, and procedures (TTPs) used by cyber adversaries. This knowledge will not only help you answer questions effectively but also demonstrate your proactive approach to staying informed in a rapidly evolving field.
β¨Showcase Your Coding Skills
Be prepared to discuss your experience with scripting languages like PowerShell and Python. If youβve worked on any projects involving APIs or automation, bring those examples to the table. Highlighting your coding abilities will set you apart, especially since custom solutions are part of the role.
β¨Communicate Clearly and Confidently
Since good communication skills are essential for this role, practice explaining complex technical concepts in simple terms. Be ready to discuss how you document detection rules and collaborate with teams. Clear communication can make a big difference in how your technical expertise is perceived.