
Cyber Security Lead (Analyst)
- Leeds Exeter
- £83,792-97,365 per year
- Contract
- Full-time
- Cyber Security Operations Unit (CSOU)
- Cyber Delivery Unit (CDU).
- Cyber Improvement Programme.
- Chief Information Security Office Function (CISO)
- Lead the Protective Monitoring team responsible for network security, ensuring continuous monitoring of NHS England's core infrastructure and systems.
- Line-manage and mentor a team of analysts, providing guidance on monitoring strategies, threat detection, and incident response.
- Deputise for the Detect & Respond Lead when required, ensuring operational continuity and effective decision-making during critical events.
- Provide quality assurance on investigations, reviewing analysts' work to maintain accuracy and consistency in threat detection and response.
- Design, develop, and enhance SOC use cases and associated tooling, working closely with the DevOps team to implement automation, improve detection logic, and streamline response workflows--demonstrating strong capability in creating detailed, effective use cases rather than only analysing incidents.
- Stay ahead of emerging threats and technologies, particularly those impacting internal networks, by researching vulnerabilities and implementing proactive measures.
- Utilise advanced monitoring tools, including SIEM platforms, XDR solutions, and network analytics, to identify anomalies, insider threats, and lateral movement.
- Support incident management and response as a technical SME and incident coordinator, ensuring timely containment, root cause analysis, and recovery during major security events.
- Enabling local systems and providers to improve the health of their people and patients and reduce health inequalities.
- Making the NHS a great place to work, where our people can make a difference and achieve their potential.
- Working collaboratively to ensure our healthcare workforce has the right knowledge, skills, values and behaviours to deliver accessible, compassionate care
- Optimising the use of digital technology, research, and innovation
- Delivering value for money.
- In-depth knowledge of modules, processes and technologies of Information Security Operation Centre (ISOC); ability to detect, response and utilise related platform and applications to perform cyber security initiatives.
- Demonstrable knowledge of tools, techniques and processes of intrusion detection and prevention; ability to detect, resolve and prevent intrusion behaviours to protect organisational networks.
- Highly developed specialist knowledge of and ability to investigate, troubleshoot, resolve and prevent the recurrence of incidents that interfere with the normal delivery of IT services.
- Extensive knowledge of techniques, approaches and processes of digital threats; ability to detect, monitor, analyse and prevent digital threats.
- Working knowledge of concepts, issues and techniques of endpoint security; ability to ensure security compliance of endpoint devices in various circumstance.
- Masters level degree or equivalent level of experience.
- Evidence of continuous professional development.
- SANS FOR572 / GIAC GNFA or SANS FOR508 / GIAC GCFA
- In-depth knowledge of modules, processes and technologies of Information Security Operation Centre (ISOC); ability to detect, response and utilise related platform and applications to perform cyber security initiatives.
- Demonstrable knowledge of tools, techniques and processes of intrusion detection and prevention; ability to detect, resolve and prevent intrusion behaviours to protect organisational networks.
- Highly developed specialist knowledge of and ability to investigate, troubleshoot, resolve and prevent the recurrence of incidents that interfere with the normal delivery of IT services.
- Extensive knowledge of techniques, approaches and processes of digital threats; ability to detect, monitor, analyse and prevent digital threats.
- Working knowledge of concepts, issues and techniques of endpoint security; ability to ensure security compliance of endpoint devices in various circumstance.
- Masters level degree or equivalent level of experience.
- Evidence of continuous professional development.
- SANS FOR572 / GIAC GNFA or SANS FOR508 / GIAC GCFA