About this role
Details
New entrants to the Civil Service will start their role on the salary band minimum £49,850 for National roles.
You may also be eligible for an additional non-pensionable allowance, pending a Capability and Skills Assessment, with a value of up to £7,750.
A Civil Service Pension with an employer contribution of 28.97%
GBP
Job grade
Senior Executive Officer
Business area
HO - Home Office Digital - Cyber Security
Type of role
Digital
Information Technology
Security
Working pattern
Full-time, Part-time, Compressed hours
Number of jobs available
2
Contents
•
About the job
•
Benefits
•
Things you need to know
•
Apply and further information
About the job
Job summary
Home Office Digital designs, builds and develops services for the rest of the department and for government. Every year our systems support up to 3 million visa applications, checks on 100 million border crossings, up to 8 million passport applications and deliver 140 million police checks on people, vehicles and property.
As a Senior Response Manager within the Home Office Cyber Security Operations Centre (CSOC) you will be expected to plan, implement and operate capabilities to detect, contain and remediate incidents, identify opportunities to improve detection, response and automation capabilities. You will also support organisational readiness through co-ordinating preparedness exercises and red team activity. The Response function also advises product and service owners on potential mitigations and supports the continuous improvement of security operations through monitoring, detection and standardisation of security practices.
Youll be joining an expert team of cyber professionals, committed to reducing the exposure to cyber-attack of new and existing digital systems. Youll be aided in your role by a diverse and supportive organisational culture, and a commitment to further your continuous development.
Where business needs allow, some roles may be suitable for a combination of office and home-based working. Where this is the case, employees will be expected to spend a minimum of**60% of their working time in the office. Applicants can raise any queries to the email address at the bottom of the advert.
Watch this short video to hear from members of Home Office Digital talking about the projects they work on and their experience of working here: Working for Home Office Digital.
Job description
We are recruiting two Senior Response Managers to join the CSOC working in the following roles:
Senior Technical Detection Analyst
This role focuses on improving SIEM detection and monitoring capabilities. You will develop, test, maintain and improve SIEM monitoring and detection content, using threat intelligence and operational insights to improve detection coverage, accuracy and the identification of cyber threats.
You will apply and refine threat-informed detection engineering practices, standards and quality controls, strengthening the organisations ability to identify and respond to cyber threats.
Senior SOAR & Detection-as-Code (DaC) Analyst
This role focuses on improving cyber detection, response and automation capabilities through security automation, response playbooks and Detection-as-Code practices. You will design, develop, test, maintain and improve security automation workflows, response playbooks and integrations using SOAR platforms or comparable automation technologies, while applying structured and repeatable DaC methodologies
You will work with SOC teams and other business areas to improve incident handling, implement complex solutions for emerging threats, contribute to relevant standards and process improvements, and reduce operational effort and future risk.
When submitting your application, please clearly indicate which role(s) you wish to be considered for.
As a Senior Response Manager in either of these roles your main responsibilities will be to;
•
Carry out security monitoring, detection and response activities in line with agreed standards, providing advice on mitigation, escalation and risk reduction.
•
Identify, analyse and investigate indicators of malicious activity across networks, systems and applications, supporting effective threat detection and incident response.
•
Triage security events and alerts, supporting investigations and recommending improvements to monitoring controls, detection coverage and overall security posture.
•
Support incident response activities, including red teaming and threat hunting exercises, communicating investigation outcomes and contributing to lessons learned and post-incident reviews.
•
Develop, review and continuously improve monitoring use cases, detection content and alert effectiveness across a range of security technologies.
•
Define and enhance processes, tooling and security controls to identify emerging threats, strengthen detection capabilities and implement effective mitigation strategies.
•
Drive service and process improvements by applying industry best practice, sound judgement and problem-solving skills to support efficient security operations and investigations.
Working Pattern
This role is available on a full-time basis with the option of compressed hours working. This role is also suitable for part-time working hours, with a minimum requirement to work 4 days/ 30 hours per week due to business requirements.
Person specification
Essential Skills
You will have a demonstrable passion for Cyber Security, Detection and Response with the following skills, knowledge or experience;
As a Senior Technical Detection Analyst
•
Conducting investigations and working in a Security Operations Centre environment, including the identification and analysis of potentially malicious activity.
•
Developing, maintaining or improving SIEM monitoring and detection content, using threat intelligence and operational insights to improve detection coverage, accuracy and the identification of cyber threats.
As a Senior SOAR & DaC Analyst
•
Conducting investigations and working in a Security Operations Centre environment, supporting security operations and incident response activities.
•
Designing, developing, testing maintaining and improving security automation workflows, response playbooks and integrations using SOAR platforms or comparable automation technologies, while applying DaC methodologies.
Additionally, for both roles, experience of;
•
Communicating in a verbal and written manner, and a good understanding of the use of different channels and formats for different audiences
•
•
Managing a team in a technical environment
SFIA capability framework
Skills for the Information Age (SFIA) version 8 is the technical framework that sets the standard capability and development of all levels in the Home Office. This is a link to the capability framework: All skills A - Z English (sfia-online.org).
We use set SFIA technical skills to form our interview questions and we will assess you against these technical skills during the selection process.
The essential skills listed above are reflective of the Home Office Government Digital and Data Profession Career Framework (based on the industry standard SFIA framework). Use the SFIA Levels of responsibility to understand what would be expected for each technical skills listed below.
About cyber security & digital forensics roles for ex-police
Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.
See all cyber security & digital forensics jobs in Sheffield →Why this fits a police background — match score 90/100
- Intelligence & OSINT
- Incident command & response
- Investigative casework
- Security operations
What cyber security & digital forensics roles pay ex-police
Advertised UK ranges, editorial estimates reviewed July 2026
| Digital forensics analyst | £32,000–£45,000 |
| DFIR consultant | £45,000–£65,000 |
| Senior forensics / IR specialist | £60,000–£80,000 |
| Threat-intelligence specialist | £55,000–£80,000 |