Skip to main content
AfterDuty

Lead Cyber Security Monitoring

Driver and Vehicle Standards Agency (DVSA) · Leeds, West Yorkshire

Type
Full-time
Posted
14 days ago

Overview

Your experience in digital forensics, evidence handling, and incident command from policing maps directly to this SOC lead role.

About this role

473739 Lead Cyber Security Monitoring

Driver and Vehicle Standards Agency

Apply before 11:55 pm on Monday 31st August 2026

📍 Location: Bristol, Swansea, Leeds, Nottingham, Newcastle, Oldham (Chadderton), Birmingham (Garretts Green) or Uxbridge. (This role is suitable for hybrid working)

*💷 Salary:*£44,241 - £58,997

Candidates based in Yeading/Uxbridge will receive the London Weighting allowance of £4,000

Plus an additional Government Digital and Data Profession allowance (non-pensionable) up to £14,756.

A Civil Service Pension with an employer contribution of 28.97%

🕘️ Contract Type: Permanent – Flexible working, Full-time, Job share, Part-time

🏆️ Available Positions: 1

This role sits within the Security Operations Centre and responds to events found as part of the protective monitoring processes led directly by DVSA or its service provider. It also responds to incidents of a technical nature in line with DVSA Incident Management procedures. It restores normal service operation as quickly as possible and minimises any adverse effect on business operations. This ensures that the best possible levels of service quality and availability are maintained, whilst containing any security breach to allow for forensic analysis to establish cause. It establishes action plans in collaboration with other managers in the team and wider DVSA. It effectively manages, investigates and reports on potential/actual failures to comply with security requirements, and identifies process improvements

Top Responsibilities

  • Leading the rapid detection, investigation, and response to cyber security incidents, ensuring threats are contained, impact is minimised, and incidents are handled in line with DVSA policies, legal requirements, and best‑practice security standards, including performing or arranging digital forensics to support evidence gathering and preservation.
  • Driving proactive cyber defence through threat hunting and vulnerability management, using threat intelligence to identify emerging risks, suspicious activity, and weaknesses in DVSA’s security posture.
  • Manage post-incident review, including root cause analysis, to feedback information and so improve monitoring and evidencing need for policy change as necessary.
  • Managing and improving SOC processes and protective monitoring capabilities, ensuring DVSA and its suppliers meet contractual and policy obligations for incident reporting and security operations.
  • Planning, leading, and evaluating incident response exercises, including red‑team activity, to strengthen organisational readiness and validate response procedures.

For more information on the role and responsibilities please see the full job advert on CS Jobs using the link provided.

Benefits

  • Employer pension contribution of 28.97% of your salary. Read more about Civil Service Pensions here
  • 25 days annual leave, increasing by 1 day each year of service (up to a maximum of 30 days annual leave).
  • 8 Bank Holidays plus an additional Privilege Day to mark the King’s birthday.
  • Access to the staff discount portal.
  • Excellent career development opportunities and the potential to undertake professional qualifications relevant to your role paid for by the department, such as CIPD, Prince2, apprenticeships, etc.
  • 24-hour Employee Assistance Programme providing free confidential help and advice for staff.

About You

To be successful in this role you will need to have the following experience:

  • Demonstratable experience working with a SIEM tool (Microsoft Sentinel, Splunk, etc), and vulnerability scanners.
  • Ability to explain technical and complex concepts simply to a variety of audiences acting as a bridge between the technical and the non-technical, providing updates and recommendations in a clear and comprehensive manner.
  • Experience in interpreting threat intelligence and building in rulesets into IDS/IPS toolsets to the threat risks.
  • Good working knowledge of security concepts (Physical, Personal, IT and Cyber Security), including security controls, security risk management and security incident management.
  • Experience leading small monitoring teams in the design, development and enablement of automated monitoring processes, recommending and implementing the latest SIEM (Security Information and Event Management) and network analysis tools, techniques and procedures to: detect malicious activity and ensure continuous improvement through dashboard monitoring or retrospective assessment.

Government Digital and Data Allowance

The role is part of the Government Digital and Data (or Government Security Profession Career Framework) profession and utilises an enhanced Capability–Based Pay Framework which provides access to a Digital and Data allowance.

The base pay is £44,241. In addition to this the role includes a Digital and Data allowance of up to £14,756.

The value of allowance awarded will be based on an assessment of your skills and experience as demonstrated through the selection process.

How to Apply

👉 Read the full description and apply here: https://bit.ly/45neT6O

This vacancy closes at 23:55 on Monday 31st August 2026

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in Leeds

Why this fits a police background — match score 75/100

  • Evidence & case files
  • Intelligence & OSINT
  • Incident command & response
  • Investigative casework
  • Digital forensics & cybercrime

What cyber security & digital forensics roles pay ex-police

Advertised UK ranges, editorial estimates reviewed July 2026

Digital forensics analyst£32,000–£45,000
DFIR consultant£45,000–£65,000
Senior forensics / IR specialist£60,000–£80,000
Threat-intelligence specialist£55,000–£80,000
Full cyber security & digital forensics salary guide →

More cyber security & digital forensics jobs for ex-police

  • Your experience with digital evidence handling and investigative reporting maps directly onto SOC triage and incident documentation.

    Posted 9 days ago

  • Full-time

    Your incident management and digital forensic investigation experience from policing transfers directly to cyber incident response.

    Posted 12 days ago

  • Operational and Cyber Resilience Lead

    Financial Conduct Authority · Leeds

    Full-time

    Your incident command and contingency planning experience directly applies to assessing firms' operational resilience and cyber incident response.

    Posted 21 days ago

  • Full-time

    £47,389 – £56,535Estimated

    This role involves managing infrastructure, network security, and cyber security services, including firewalls, endpoint security, and SOC operations. Your policing experience in incident response, risk assessment, and secure handling of sensitive information directly applies to maintaining a resilient IT environment. While the position requires specific technical leadership in IT, your background in command, crisis management, and operational security gives you a strong foundation for overseeing security technologies and teams.

    Posted 23 days ago