Cyber Operations purpose is to support safe care and build public trust by strengthening NHS England's cyber resilience and enabling the wider health system to be cyber resilient, supporting Transformation Directorate's purpose of delivering the best care and outcomes for the NHS.
The Cyber Operations sub-directorate consists of four areas:
* Cyber Security Operations Unit
* Cyber Delivery Unit
* Cyber Improvement Programme
* Chief Information Security Office Function
As a Junior Cyber Security Engineer in the Cyber Security Operations Centre (CSOC), you will support day‑to‑day operation, support and improvement of core cyber security platforms and services. You will maintain and tune security tooling across identity, access, network and XDR technologies, ensuring system health, data integrity and effective alerting. You will support multi‑tenant platforms such as XDR, SIEM, monitoring analytics, queries and dashboards, and identify opportunities to improve performance. You will contribute to onboarding by supporting ingestion pipelines, enrichment processes and integrations that enable CSOC operations. You will also support planning and implementation of system changes through formal change management, considering risk, impact and service continuity. Working with senior engineers, you will help improve service reliability, resilience and scalability, contributing to documentation, runbooks and operational processes, and providing technical support to trainee colleagues.
Responsibilities
* Work within the CSOC providing technical engineering support for core security platforms and services, taking responsibility for their reliable day‑to‑day operation, monitoring and maintenance in line with service requirements.
* Support and maintain CSOC platforms, including monitoring platform health, investigating data ingestion issues, maintaining and tuning detections, and responding to system generated alerts to ensure effective coverage.
* Provide technical input into handling of cyber and IT security incidents, supporting investigation, containment and recovery activities, and contributing to post‑incident remediation and service improvement.
* Diagnose and resolve service incidents relating to security tooling (e.g., SIEM, XDR, logging pipelines), escalating complex issues where appropriate and contributing to root cause analysis and preventative actions.
* Support planning, assessment and implementation of changes to cyber security systems, tooling and configurations via formal change management processes, considering technical risk, impact and service continuity.
* Contribute to operational service activities including system checks, access management, user support requests, and the development and maintenance of standard operating procedures and technical documentation.
#J-18808-Ljbffr