About this role
Details
Candidates based in Yeading/Uxbridge will receive the London Weighting allowance of £4,000
Plus an additional Government Digital and Data Profession allowance (non-pensionable) up to £14,756.
A Civil Service Pension with an employer contribution of 28.97%
GBP
Job grade
Senior Executive Officer
Business area
DVSA - Digital Operations - Digital and Data
Type of role
Digital
Working pattern
Flexible working, Full-time, Job share, Part-time
Number of jobs available
1
Contents
- Location
- About the job
- Benefits
- Things you need to know
- Apply and further information
You can be based at any of the above locations, however if your chosen location is Yeading/Uxbridge please note:
This role is advertised as being based in Uxbridge; however, the contractual base will be Yeading.
While estate works are being carried out at the Yeading site, all roles will be temporarily located in Uxbridge. Successful applicants will therefore begin their employment at the Uxbridge location.
Please be aware that all employees will be required to work from the Yeading site once it reopens in 2028.
Employees based at Uxbridge will receive a London Weighting allowance of £4,000. This allowance will continue when the location moves to Yeading.
About the job
Job summary
This role sits within the Security Operations Centre and responds to events found as part of the protective monitoring processes led directly by DVSA or its service provider. It also responds to incidents of a technical nature in line with DVSA Incident Management procedures. It restores normal service operation as quickly as possible and minimises any adverse effect on business operations. This ensures that the best possible levels of service quality and availability are maintained, whilst containing any security breach to allow for forensic analysis to establish cause. It establishes action plans in collaboration with other managers in the team and wider DVSA. It effectively manages, investigates and reports on potential/actual failures to comply with security requirements, and identifies process improvements
Joining our department comes with many benefits, including
- Employer pension contribution of 28.97% of your salary. Read more about Civil Service Pensions here
- 25 days annual leave, increasing by 1 day each year of service (up to a maximum of 30 days annual leave), plus 8 bank holidays a privilege day for the Kings birthday
- Flexible working options where we encourage a great work-life balance.
Read more in the Benefits section below!
Find out more about what it's like working at Driver and Vehicle Standards Agency - Department for Transport Careers
Job description
Your responsibilities will include, but arent limited to
- Leading the rapid detection, investigation, and response to cyber security incidents, ensuring threats are contained, impact is minimised, and incidents are handled in line with DVSA policies, legal requirements, and best‑practice security standards, including performing or arranging digital forensics to support evidence gathering and preservation.
- Driving proactive cyber defence through threat hunting and vulnerability management, using threat intelligence to identify emerging risks, suspicious activity, and weaknesses in DVSAs security posture.
- Manage post-incident review, including root cause analysis, to feedback information and so improve monitoring and evidencing need for policy change as necessary.
- Managing and improving SOC processes and protective monitoring capabilities, ensuring DVSA and its suppliers meet contractual and policy obligations for incident reporting and security operations.
- Planning, leading, and evaluating incident response exercises, including red‑team activity, to strengthen organisational readiness and validate response procedures.
- Providing expert advice to senior leaders and technical teams, helping them understand risks, make informed decisions, and embed strong security practices.
- Building strong relationships across DVSA and with external partners, including government departments, regulators, and third‑party suppliers.
- Producing clear, high‑quality reporting and communication, including incident summaries, performance statistics, lessons learned, and recommendations for continuous improvement.
- Demonstrating leadership by guiding, mentoring, and supporting SOC analysts and colleagues, acting as a role model for professional standards, technical excellence, and Civil Service values.
Great line management is important to us as an organisation, and we will equip and support line managers to develop the skills they need. We aim to empower line managers to create teams where people can flourish and deliver excellent outcomes for the public.
For further information on the role, please read the attached role profile. Please note that the role profile is for information purposes only - whilst all elements are relevant to the role, they may not all be assessed during the recruitment process. This job advert will detail exactly what will be assessed during the recruitment process.
Person specification
You may hold or be willing to work towards the following qualifications:
CSSP, CISSP, Degree in IT or Cyber Security, or a Professional Qualification relating to the same
Required experience
To be successful in this role you will need to have the following experience:
- Demonstratable experience working with a SIEM tool (Microsoft Sentinel, Splunk, etc), and vulnerability scanners.
- Ability to explain technical and complex concepts simply to a variety of audiences acting as a bridge between the technical and the non-technical, providing updates and recommendations in a clear and comprehensive manner.
- Experience in interpreting threat intelligence and building in rulesets into IDS/IPS toolsets to the threat risks.
- Good working knowledge of security concepts (Physical, Personal, IT and Cyber Security), including security controls, security risk management and security incident management.
- Experience leading small monitoring teams in the design, development and enablement of automated monitoring processes, recommending and implementing the latest SIEM (Security Information and Event Management) and network analysis tools, techniques and procedures to: detect malicious activity and ensure continuous improvement through dashboard monitoring or retrospective assessment.
Government Digital and Data Allowance
The role is part of the Government Digital and Data (or Government Security Profession Career Framework) profession and utilises an enhanced CapabilityBased Pay Framework which provides access to a Digital and Data allowance.
The base pay is £44,241. In addition to this the role includes a Digital and Data allowance of up to £14,756.
The value of allowance awarded will be based on an assessment of your skills and experience as demonstrated through the selection process. Here are more details on the pay framework.
Additional Information
Full time roles consist of 37 hours per week.
Whilst we welcome applications from those looking to work with us on a part time basis, there is a business requirement for the successful candidate to be able to work at least 30 hours per week.
Occasional travel to other offices will be required, which may involve overnight stays.
This role is suitable for hybrid working, which is a non-contractual arrangement where a combination of workplace and home-based working can be accommodated subject to business requirements.
The expectation at present is a minimum of 60% of your working time a month will be spent at either your designated workplace (one of the locations cited in the advert) or, when required for business reasons, in another office/work location. There may be occasions where you are required to attend above the minimum expectation.
About cyber security & digital forensics roles for ex-police
Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.
See all cyber security & digital forensics jobs in Birmingham →Why this fits a police background — match score 75/100
- Evidence & case files
- Intelligence & OSINT
- Incident command & response
- Investigative casework
- Digital forensics & cybercrime
What cyber security & digital forensics roles pay ex-police
Advertised UK ranges, editorial estimates reviewed July 2026
| Digital forensics analyst | £32,000–£45,000 |
| DFIR consultant | £45,000–£65,000 |
| Senior forensics / IR specialist | £60,000–£80,000 |
| Threat-intelligence specialist | £55,000–£80,000 |