Job summary
- Main area
- Cyber Secruity
- Grade
- Civil Service: Grade 7
- Contract
- Permanent
- Hours
- Full time
- Part time
- Job share
- Flexible working
- Job ref
- 919-GB-62190982-EXT
- Employer
- UK Health Security Agency
- Employer type
- Public (Non NHS)
- Site
- Homeworking
- Town
- Homeworking
- Salary
- £54,416 - £68,344 Per annum, Pro Rata ( Market Pay Supplement from £5,000 to £15,000 )
- Salary period
- Yearly
- Closing
- 14/08/2025 23:59
Employer heading

Cyber Security Operations Technical Team Lead
Civil Service: Grade 7
Job overview
Do you have a passion for Cyber Security?
Do you have experience as a cyber security professional, working at a Management Level in an organisation?
Are you interested in working for an organisation that truly champions a healthy work/life balance?
If so, continue reading to find out more about this fantastic opportunity to join UKHSA Cyber Security.
Now is a great time to join us as we establish a team of outstanding people in the field of Cyber Security Operations. This is a chance to work on services that matter and affect the lives of millions of citizens.
UKHSA’s Cyber Security Operations team is responsible for the operational cyber security of UKHSA.
We are looking for an enthusiastic Cyber Security Operations Team Lead, with great leadership and technical skills and a drive to improve the security of our services. In this role you will lead across areas such as security engineering, protective monitoring, vulnerability management, and incident response, as well as contributing to strategic team growth and maturity initiatives.
Main duties of the job
Reporting to the Head of Cyber Security Operations you will supervise individuals within the UKHSA Security Operations team, to ensure effective delivery of security operations projects and BAU delivery into the business. You will also contribute to strategy, providing technical input and guidance to Senior Leaders, Risk Owners, UKHSA staff and partners. You will support and occasionally lead in complex incident management, including liaison with the National Response Centre if required, response activities, working with technical staff and suppliers to detect, contain and remediate security events and risks. The role can be fast paced and reactionary when dealing with a live incident.
You will work closely with contacts across Government and manage networks of internal and external stakeholders. You will have a technical background in cyber security operations, with knowledge of key security technologies, frameworks and best practices. You will also have an awareness of the challenges presented in delivering effective, high performing security services in a complex and evolving environment.
Individuals will be expected to communicate via a number of different tools and methods, such as email, teams, and telephone
Working for our organisation
We pride ourselves as being an employer of choice, where Everyone Matters promoting equality of opportunity to actively encourage applications from everyone, including groups currently underrepresented in our workforce. UKHSA ethos is to be an inclusive organisation for all our staff and stakeholders. To create, nurture and sustain an inclusive culture, where differences drive innovative solutions to meet the needs of our workforce and wider communities. We do this through celebrating and protecting differences by removing barriers and promoting equity and equality of opportunity for all. Please visit our careers site for more information https://gov.uk/ukhsa/careers
Detailed job description and main responsibilities
Detailed job description and main responsibilities
The successful individual will be expected to carry out all functions in all of the “Operations” Role Family outlined in Government Security Profession Career Framework, including:
Monitoring
- Manage the monitoring, triaging, and investigation of security alerts on protective monitoring platforms to identify security incidents, and reviewing analysis of security event data to manage security incident response, reporting, or escalation where appropriate
- Lead small monitoring teams in the design, development and enablement of automated monitoring processes, recommending and implementing the latest SIEM (Security Information and Event Management) and network analysis tools, techniques and procedures to detect malicious activity and ensure continuous improvement through dashboard monitoring or respective assessment
Response
- Manage an organisation’s response policies and processes to meet the needs in line with appropriate standards
- Manage post-incident review, including root cause analysis, to feedback information and so improve monitoring
Vulnerability Management - Manage the triage of vulnerabilities, ensuring mitigation measures are implemented, and managing the life cycle of vulnerability management for a set of assets, providing tailored advice on ways to improve control mechanisms and mitigate risks
- Manage collaboration with stakeholders to create tactical plans relating to managing vulnerabilities, and oversee subsequent activities
Digital Forensics
- Co-ordinate team scene investigation and capture evidence in accordance with legal guidelines to minimise disruption to the business and preserve evidentiary integrity, using specialist equipment as appropriate
- Review evidence to identify breaches of policy, regulation or law
In addition to the above core skills the successful individual will be expected to:
- Manage individuals within the Cyber Security Operations team which may include UKHSAs external Cyber Security partners that provide augmented resourcing.
- Maintain Cyber Threat Intelligence and analysis capabilities to improve organisational understanding and awareness of technical security risks.
- Contribute to strong operational relationships with internal cyber security, technology, and privacy teams to maintain efficient communication and collaboration on security issues.
- You will coordinate your teams to investigate problems, implement solutions and take preventive measures and form part of an on-call rota for service continuity.
- Any other responsibilities appropriate for this grade. Cyber Security Operations can be fast paced and will require a degree of flexibility.
Essential role criteria
- Undergraduate degree in a STEM subject, or Professional Cyber Security qualification
- Significant experience of working at tier 2 or tier 3 in a SOC
- Previous management/mentoring responsibilities
- Effective verbal and written communication skills
- Leadership skills
- Demonstrable experience with KQL or similar query language.
- Demonstrable knowledge and experience of intrusion detection and analysis skills.
- Demonstrable experience in cyber security incident management
- Solid knowledge of various information security frameworks, for example MITRE.
- Demonstrable experience of vulnerability management
Selection Process Details:
This vacancy is using Success Profiles and will assess your Behaviours, Experience and Technical skills.
All individuals must undertake a technical test, presentation and pass the interview process successfully. This allows us to set the rate of the MPS awarded successfully.
Stage 1: Application & Sift
You will be required to complete an application form. You will be assessed on the listed (10) essential criteria, and this will be in the form of a:
- Application form (‘Employer/ Activity history’ section on the application)
- 1250 word supporting statement.
This should outline how your skills, experience, and knowledge, provide evidence of your suitability for the role, with reference to the essential criteria.
The Application form and supporting statement will be marked together.
Longlisting:
In the event of a large number of applications we will longlist into 3 piles of:
- Meets all essential criteria
- Meets some essential criteria
- Meets no essential criteria
The following will be taken through to the next stage:
- Meets all essential criteria
- Meets some essential criteria
Shortlisting:
In the event of a large number of applications we will shortlist on the following:
• Significant experience of working at tier 2 or tier 3 in a SOC
• Demonstrable experience in cyber security incident management
• Previous management/mentoring responsibilities
If you are successful at this stage, you will progress to interview & assessment.
Please do not exceed 1250 words. We will not consider any words over and above this number.
Feedback will not be provided at this stage.
Please note you will not be able to upload your CV. You must complete the application form in as much detail as possible. Please do not email us your CV.
Stage 2: Interview (success profiles)
You will be invited to a (single) remote interview.
Behaviours, technical, and experience, will be tested at interview.
You will be asked to prepare and present a 10-minute presentation. The subject of this will be sent to you prior to interview.
The Behaviours tested during the interview stage will be
- Making Effective Decisions
- Managing a Quality Service – Lead behaviour
- Delivering at Pace
- Leadership
Once this job has closed, the job advert will no longer be available. You may want to save a copy for your records.
Eligibility Criteria - External
Open to all external applicants (anyone) from outside the Civil Service (including by definition internal applicants).
Location
This is a homeworking role.
Security Clearance Level Requirement
Successful candidates must pass a disclosure and barring security check.
Successful candidates must meet the security requirements before they can be appointed. The level of security needed is Security Clearance.
For meaningful National Security Vetting checks to be carried out individuals need to have lived in the UK for a sufficient period of time. You should normally have been resident in the United Kingdom for the last 5 years as the role requires Security Check (SC) clearance. UK residency less than the outlined periods may not necessarily bar you from gaining national security vetting and applicants should contact the Vacancy Holder / Recruiting Manager listed in the advert for further advice.
Person specification
Application form & supporting statement
Essential criteria
- Application form & supporting statement
Behaviours
Essential criteria
- Making effective decisions
- Managing a Quality Service – lead behaviour
- Delivering at Pace
- Leadership
Interview
Essential criteria
- Presentation
Applicant requirements
The postholder will have regular contact with vulnerable people and as such this post is subject to the Rehabilitation of Offenders Act 1974 (Exceptions) Order 1975 (Amendment) (England and Wales) Order 2020 and as such it will be necessary for a submission for Disclosure to be made to the Disclosure and Barring Service to check for any previous criminal convictions.
Documents to download
Further details / informal visits contact
- Name
- Gurkamal Bhambra
- Job title
- Resourcing
- Email address
- [email protected]
List jobs with UK Health Security Agency in Administrative Services or all sectors