SC clearance is mandatory to be considered
An organisation within central government is strengthening its Security Operations capability to meet rising alert volumes, improve incident response, and align with evolving monitoring standards and assurance expectations. We are seeking a Cyber Security Engineer to help implement and operate a modern security operations platform, increasing automation, analytics, and overall detection and response maturity.
This role will support delivery against government security monitoring requirements (e.g., Cyber Assessment Framework and Minimum Cyber Security Standard) and contribute to assurance activity for critical services.
Key Responsibilities
- Implement, configure, and manage the Palo Alto Networks XSIAM platform to ensure stable, secure, and effective operation.
- Develop and maintain security policies, detection rules, and configurations to improve threat detection and response.
- Integrate XSIAM with other security tools and information systems to automate workflows and reduce manual effort.
- Perform continuous monitoring and analysis of alerts and incidents to identify trends, root causes, and potential threats.
- Coordinate with internal teams and external partners to share threat intelligence and improve security awareness.
- Provide hands‑on technical guidance and support on cyber security matters to IT and business stakeholders.
- Keep current with emerging threats, security technologies, and vendor capabilities to continuously improve security operations.
- Produce clear reports and briefings on incidents, trends, and effectiveness of security controls for senior stakeholders.
- Strong background in Security Operations (SOC): alert triage, incident handling, and operational monitoring.
- Experience implementing or operating SIEM/SOAR platforms (XSIAM experience highly desirable).
- Capability in use‑case development, detection engineering, tuning, and reducing false positives.
- Experience integrating security tooling via APIs, connectors, or log pipelines (e.g., identity, endpoint, network, cloud).
- Ability to communicate technical findings clearly to both technical teams and senior/non‑technical stakeholders.
- Understanding of government or regulated security monitoring expectations (CAF / equivalent standards desirable).
- Experience supporting audit/assurance activities and evidencing control effectiveness.
- Threat intelligence operationalisation and workflow automation experience.
#J-18808-Ljbffr…
