Cyber Security Monitoring and Investigations - Security Alert Analyst

Stratford, Greater London

The Cyber Security Monitoring & Investigations Team is part of the DWP Cyber Resilience Centre, and it plays a vital role in securing the DWP estate; ensuring that service delivery is not affected by potential malicious activity from either internal or external threat actors. The team operates in a dynamic environment at the forefront of the Department's cyber protection capability. This role is for a first line monitoring analyst who will have responsibility for the initial triage of security alerts generated from across the DWP estate. We have vacancies in two areas. The job roles are the same but they have different working hours' arrangements. Please specify in your application which opportunity/opportunities you are applying for. Opportunity A - Shift worker (up to 9 posts). Operating as part of a team working continental shifts to provide 24/7/365 monitoring coverage. The shift pattern is a 28-day repeating pattern with a mixture of day shifts (7am - 7pm) and night shifts (7pm - 7am) and including weekends and bank holidays. A shift allowance may be applicable. Opportunity B - Core Hours (3 posts). Working as part of a core hours team. Working flexible hours, providing coverage between 7am and 7pm Monday to Friday. Working as a Security Alert Analyst you will monitor systems to detect potential indicators of compromise. You will lead the first stage categorisation and investigation of security alerts generated by analytical tools and capabilities operating across DWP systems and networks. You will be responsible for interpreting reports and dashboards and, using your knowledge of security risks and latest cyber intelligence, will ensure an effective response to alerts. Where appropriate you will escalate potential incidents, collating and presenting all necessary information to others, to enable immediate and accurate investigations. You will use malware analysis tools as appropriate to support your decision-making. You will support the development of theoretical rules to test and deploy across large data sets and will continually review and refine those rules to ensure high quality outputs are maintained and supplied to operational stakeholders. Responsibilities: Successful candidates can expect to be involved in a range of activities including the following

  • Effectively use security tooling including Security Information and Event Management (SIEM) platforms and open-source intelligence, to identify security compromises within large amounts of complex data.
  • Provide in-depth analysis of reports and dashboards and respond to alerts generated by the latest analytical tools and capabilities operating across machine data within DWP systems.
  • Demonstrate knowledge of the latest security threats and indicators of compromise, to ensure an effective response to alerts as well as to new threats and attack vectors.
  • Undertake proactive interrogation of activity captured in system logs and across large data sets to quickly determine if systems have been compromised.
  • Use intelligence effectively to ensure appropriate response actions to security threats.
  • Provide cyber security specific input to investigations through the application of technical knowledge and exploitation of cyber intelligence.
  • Use malware analysis tools (commercial and/or open source) to support analysis and decision making.
  • Work within the confines of relevant legislation as it applies to cyber security and digital forensics activities.
  • Provide timely intervention to protect the DWP IT estate through initiating containment processes to isolate and prevent the spread of malware.
  • Drive forward the development of monitoring systems and supporting processes and playbooks, ensuring systems are in place to review and continually improve existing capabilities.
  • Demonstrate strong knowledge and understanding of the concepts of information security, and of current and emerging IT security, data protection and information risk principles and technologies.
  • Ensure that all team activities comply with legal and internal requirements and that all evidence produced from investigations is suitable for use in disciplinary or legal actions.
  • Ensure the Department's data is used safely, proportionately, and legally at all times.
  • Support remedial activity as a result of identified weaknesses within the estate.
  • Manage multiple priorities and respond flexibly to competing demands.
  • Line management of apprentices.

    Disability Confident
  • About Disability Confident A Disability Confident employer will generally offer an interview to any applicant that declares they have a disability and meets the minimum criteria for the job as defined by the employer. It is important to note that in certain recruitment situations such as high-volume, seasonal and high-peak times, the employer may wish to limit the overall numbers of interviews offered to both disabled people and non-disabled people. For more details please go to .
Posted 2025-09-18

Recommended Jobs

Lead Platform Engineer

LinuxRecruit
London

Want to become a Cloud subject matter expert? Well, this opportunity is where you'll be bringing all of your DevOps experience together to become the subject matter expert within your team. You'll b…

View Details
Posted 2025-07-09

Full-time Nanny role in London, Job ID J1DB2B

Little Ones UK Ltd
Holland Park, Greater London

A lovely family in Holland Park, London, is looking for a Full-time Nanny to provide proper care for their two children. They seek an enthusiastic and proactive individual who is flexible, happy to t…

View Details
Posted 2025-08-20

Chadburn Clinical Lecturer

King's College London
London

About Us The Faculty of Life Sciences & Medicine (FoLSM) at King's College London is one of the largest and most successful centres for biomedical research and education in the UK. The Faculty has…

View Details
Posted 2025-08-24

Corporate Tax Manager

Buckley Consulting
London

Corporate Tax Manager London/hybrid To £75,000 + Benefits This team is a breadth of fresh air and really can offer it all - terrific clients, interesting work, friendly colleagues, the opportun…

View Details
Posted 2025-09-05

1958 - Sales Operations Associate

Career Moves Group
London

Sales Operation Associate Location: London. St Giles Length: Asap – 13/02/2026 Rate: £50.96 per hour Hours: 40 hours per week (Hybrid, 2 days per week office based) …

View Details
Posted 2025-09-07

SAP FI CO Consultant

NTT DATA Business Solutions
London

Senior SAP FI CO Consultant (with Product Costing experience) NTT DATA Business Solutions - NTT DATA Business Solutions Group is part of the NTT DATA Corporate Group a top 10 global IT servic…

View Details
Posted 2025-07-26

Senior Cloud Engineer , Data Stores

Forter
London

About the Role: Forter is seeking a Senior Cloud Engineer to join our Data Stores team. We are looking for a proactive, detail-oriented individual to be responsible for designing, implementing, an…

View Details
Posted 2025-09-07

Speculative Application - Technical Coordinator

Architecture Social
London

Speculative Application – Technical Coordinator Be the vital link between design intent and construction reality. Who We Are Architecture Social works with a range of clients, from major archi…

View Details
Posted 2025-09-12

Head Chef

Stratford, Greater London

Do you have a passion for leading the way in providing genuine hospitality and impeccable service? Can you motivate a team? Are you friendly, professional and efficient? Yes? Then this is the role fo…

View Details
Posted 2025-08-31

Customer Experience Officer

Merton, Greater London

Customer Experience Officer needed in Colliers Wood, SW London The rate is £16.46ph PAYE This is a temporary role The reference number is:                   5274725 The successful candidat…

View Details
Posted 2025-09-10