Lead Cyber Security Engineer at Department for Business and Trade
London, England, United Kingdom -
Full Time


Start Date

Immediate

Expiry Date

01 Nov, 25

Salary

79133.0

Posted On

04 Aug, 25

Experience

0 year(s) or above

Remote Job

Yes

Telecommute

Yes

Sponsor Visa

No

Skills

Sql, Risk Assessment, Security Engineering, Intrusion Detection, Network Security, Azure, Security Operations, Norway, It, Nist, Iso, Log Management, Software Development, Operations Management

Industry

Other Industry

Description

JOB SUMMARY

If you’d like to find out more about the role, the Cyber Security Team and what it’s like to work at DBT, we’re holding a Hiring Manager Q&A session for this role where you can virtually ‘meet the team’ on Wednesday 20th August at 12:30pm. Please click here to book your spot.

ABOUT US

The Department for Business and Trade (DBT) has a clear mission - to grow the economy. Our role is to help businesses invest, grow and export to create jobs and opportunities right across the country. We do this in three ways.
Firstly, we help to build a strong, competitive business environment, where consumers are protected and companies rewarded for treating their employees properly.
Secondly, we open international markets and ensure resilient supply chains. This can be through Free Trade Agreements, trade facilitation and multilateral agreements.
Finally, we work in partnership with businesses every day, providing advance, finance and deal-making support to those looking to start up, invest, export and grow.
The Digital, Data and Technology (DDaT) directorate develops and operates tools and services to support us in this mission.

JOB DESCRIPTION

As a Lead Cyber Security Engineer at DBT, you will play a vital role in safeguarding the department’s digital estate, supporting the UK’s economic resilience and global competitiveness. You’ll lead the design and implementation of secure-by-design solutions across cloud, hybrid, and on-premises environments, embedding security throughout the digital lifecycle.
Your responsibilities will span both strategic and operational domains. You’ll lead security engineering across DBT’s digital platforms, ensuring robust protection of trade, business, and investment systems. You’ll also be at the forefront of our Security Operations Centre (SOC), overseeing the identification, collection, and analysis of security event data to generate high-fidelity, actionable alerts for cyber analysts.
Working closely with the SOC Manager, you’ll ensure that security tooling and data pipelines are current, effective, and tailored to reduce alert fatigue. You’ll create bespoke analytic rules and collaborate with analysts to refine detection capabilities. You’ll also take an active role in managing security alerts and leading incident response and investigation efforts.
As a senior colleague, you’ll advise on cyber risks, emerging threats, and mitigation strategies aligned with the Government Security Framework and standards. You’ll collaborate across government, industry, and international partners to uphold the UK’s cyber reputation. Additionally, you’ll mentor and develop talent within the cyber team, fostering a culture of innovation, continuous improvement, and shared learning.

SKILLS AND EXPERIENCE

It is essential that you have:

  • Proven experience in cloud cyber security engineering in a SecOps/Security environment
  • Ability to lead technical teams and influence senior stakeholders
  • Expertise in Log management
  • Experience working in a DevOps environment and following DevOps practices
  • A good working knowledge of multi-cloud environments, or expert knowledge in at least one recognised major cloud services provider, (e.g. AWS, Azure etc) network security, and secure software development
  • Incident management and alerts triage experience
  • Experience in Microsoft Sentinel
  • Strong understanding of security principles, technologies, and frameworks (e.g., NCSC guidance, ISO 27001, NIST)

It is desirable that you have:

  • Experience working with Django framework
  • Good working knowledge of Query Languages (SQL, KQL (Kusto), etc.)

MORE ABOUT US

This role can only be worked from within the UK, not overseas. If you are based in London, you will receive London weighting. DBT employees work in a hybrid pattern, spending 2-3 days a week (pro rata) in the office on average. Travel to your primary office location will not be paid for by DBT, but costs for travel to an office which is not your main location will be covered.
You can find out more about our office locations, how we calculate salaries, our diversity statement and reasonable adjustments, the Recruitment Principles, the Civil Service code and our complaints procedure on our website.
Find out more about life at DBT, our benefits and meet the team by watching our video or reading our blog!
Feedback will only be provided if you attend an interview or assessment.

NATIONALITY REQUIREMENTS

This job is broadly open to the following groups:

  • UK nationals
  • nationals of the Republic of Ireland
  • nationals of Commonwealth countries who have the right to work in the UK
  • nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities with settled or pre-settled status under the European Union Settlement Scheme (EUSS)
  • nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities who have made a valid application for settled or pre-settled status under the European Union Settlement Scheme (EUSS)
  • individuals with limited leave to remain or indefinite leave to remain who were eligible to apply for EUSS on or before 31 December 2020
  • Turkish nationals, and certain family members of Turkish nationals, who have accrued the right to work in the Civil Service

Further information on nationality requirements

Responsibilities

TYPE OF ROLE

Administration / Corporate Support
Digital
Information Technology
Other

MAIN RESPONSIBILITIES

You will be:

  • Leading large, cross-functional technical team in the design, development, and enablement of automated monitoring processes, advising on the latest SIEM (Security Information and Event Management) and network analysis tools, techniques, and procedures to detect malicious activity, while communicating directly with leadership on the progress and status of monitoring.
  • Leading wider implementation of a monitoring strategy, ensuring roadmaps are achieved as expected, ensuring requirements, policies, and standards to govern all activities and outputs are met.
  • Reviewing high-priority or high-complexity analysis of security event data to manage security incident response, making key decisions on reporting or escalations for monitoring Containing and remediating those incidents, identifying potential process improvements.
  • Communicating with a broad range of senior stakeholders and be responsible for defining the vision, principles, and strategy for incident response Deputising for the SOC manager as a when required.
  • Reviewing incident documentation ensuring that appropriate lessons learned are captured and implemented.
  • Maintaining and integrating Cyber Threat Intelligence services to enhance the Departments capabilities to detect threats.
  • Mentor junior engineers and contribute to the development of the security profession.
Loading...