£45K/yr to £50K/yr
West Lancashire, England
Permanent, Variable

NMC Cyber Security Detection Engineer

Posted by Police ICT.

Join Police Digital Service as NMC Cyber Security Detection Engineer

£45,000-£50,000

About Police Digital Service

To protect people from harm in our rapidly changing world, police services must not only keep up with technology and business changes but develop capabilities and ways of working that will enable them to adapt to and deal with the complexity of modern criminality.

Police Digital Service strives to be the go-to partner for technology developments and programmes across UK policing. Our team provides technical advice and delivers services to help policing and law enforcement organisations across the UK prioritise and focus on technology efforts.

Our vision is to support UK policing to keep people safe, get more from technology investments and make better use of public money, and we're always on the lookout for great talent to help us achieve this.

The National Management Centre (NMC) is part of Police Digital Service and provides visibility and control of information risks for policing. It supports the 24x7x365 nature of police operations, providing a threat detection and response capability for digital services before, during and after cyber-attacks, enabling stakeholders to understand and proactively manage risk across the technology estate at both the national and force level.

Key Responsibilities

  • Development, maintenance, and deployment of SIEM detection rules for complex technical environments.
  • Working alongside wider NMC functions, maintain knowledge of the threat landscape and TTPs employed by threat actors.
  • Work across wider NMC functions to ensure detections are relevant and effective.
  • Creation of custom solutions using both low-code and traditional development approaches.
  • Optimization of log collection to align with detection requirements.
  • Maintain documentation for detection rules to be used by analysts.
  • Scoping, testing and implementing new SIEM data connectors.
  • Working with wider NMC teams, contributing to Continual Service Improvement and innovations.

What you need to succeed in the role

Essential:

  • Experience with log analysis and correlation of large datasets from multiple data sources to identify and investigate attack patterns.
  • Experience of supporting and developing SIEM platforms in the context of a Security Operations Centre.
  • Experience of log source configuration and parsing, as part of a SIEM implementation, including experience of data normalisation using RegEx.
  • Practical experience in the creation, testing, implementation, and support of custom tooling to support Security Operations.
  • Experience working with APIs.
  • Practical experience in software development and scripting, preferably PowerShell and Python.
  • Initiative and the ability to produce quality work without close supervision.
  • Good written and verbal communication skills, particularly in relation to technical subjects.
  • Attention to detail and genuine passion for maintaining high quality software configuration.
  • Broad cyber security awareness and practical experience.
  • Experience working with code repositories and CI/CD.
  • Ability to acquire SC and NPPV3 level clearances.

Desirable:

  • Microsoft experience and certifications.
  • Experience with configuring and supporting vulnerability management software.
  • ISTM tool integration experience.
  • Previous public sector experience.
  • Experience with Microsoft Power Apps / Power Automate and Azure Logic Apps.

Why Join us?

  • Balance is important and we want you to take time off to recharge – we offer 28 days' annual leave plus bank holidays, rising to 30 days after 5 years of service. Holiday Purchase also available
  • Flexible working hours - We trust you to do your job and we appreciate that life doesn't always fit around a 9 to 5 workday. We operate core hours of 8 to 6, Monday to Friday (37hr week)
  • We care about your well-being – we have an EAP that offers not just welfare benefits but also retail discounts
  • Plan for the future – we offer an excellent pension scheme and life assurance cover
  • Put your mind at rest regarding your health – offering remote GP, mental health and physiotherapy appointments via video consultation
  • Family - Enhanced maternity and paternity pay along with a flexible return to work
  • Community - one paid day off per year for volunteering

You can find out more here:
Benefits – Police Digital Service (pds.police.uk)

Diversity, equity and inclusion

We are committed to equal opportunity for all and will not discriminate on any grounds. We encourage applications from people from the widest possible span of experience. We particularly welcome applications from Black, Asian and Minority Ethnic (BAME) candidates and people with disabilities.

Working Arrangements

At the NMC, you will benefit from hybrid working, getting the advantages of both face-to-face team engagement and home working. NMC employees have the opportunity to work in our modern office environment for in-person collaboration, however you will also get the opportunity to work from home 2 days a week.

All applicants must be eligible for NPPV3 and SC clearances. Successful applicants will require NPPV3 clearance to have been approved before starting with PDS.

We use cookies to measure usage and analytics according to our privacy policy.