Skip to main content
AfterDuty

Senior Response Manager - Home Office Cyber Security Operations Centre

Home Office · Sheffield, South Yorkshire

Salary
£49,850 – £52,850Estimated
Type
Full-time
Posted
3 days ago

Overview

Details New entrants to the Civil Service will start their role on the salary band minimum £49,850 for National roles. You may also be eligible for an additional non-pensionable allowance, pending a Capability and Skills Assessment, with a value of up to £7,750.

About this role

Details

New entrants to the Civil Service will start their role on the salary band minimum £49,850 for National roles.

You may also be eligible for an additional non-pensionable allowance, pending a Capability and Skills Assessment, with a value of up to £7,750.

A Civil Service Pension with an employer contribution of 28.97%

GBP

Job grade

Senior Executive Officer

Business area

HO - Home Office Digital - Cyber Security

Type of role

Digital

Information Technology

Security

Working pattern

Full-time, Part-time, Compressed hours

Number of jobs available

2

Contents

About the job

Benefits

Things you need to know

Apply and further information

About the job

Job summary

Home Office Digital designs, builds and develops services for the rest of the department and for government. Every year our systems support up to 3 million visa applications, checks on 100 million border crossings, up to 8 million passport applications and deliver 140 million police checks on people, vehicles and property.

As a Senior Response Manager within the Home Office Cyber Security Operations Centre (CSOC) you will be expected to plan, implement and operate capabilities to detect, contain and remediate incidents, identify opportunities to improve detection, response and automation capabilities. You will also support organisational readiness through co-ordinating preparedness exercises and red team activity. The Response function also advises product and service owners on potential mitigations and supports the continuous improvement of security operations through monitoring, detection and standardisation of security practices.

You’ll be joining an expert team of cyber professionals, committed to reducing the exposure to cyber-attack of new and existing digital systems. You’ll be aided in your role by a diverse and supportive organisational culture, and a commitment to further your continuous development.

Where business needs allow, some roles may be suitable for a combination of office and home-based working. Where this is the case, employees will be expected to spend a minimum of**60% of their working time in the office. Applicants can raise any queries to the email address at the bottom of the advert.

Watch this short video to hear from members of Home Office Digital talking about the projects they work on and their experience of working here: Working for Home Office Digital.

Job description

We are recruiting two Senior Response Managers to join the CSOC working in the following roles:

Senior Technical Detection Analyst

This role focuses on improving SIEM detection and monitoring capabilities. You will develop, test, maintain and improve SIEM monitoring and detection content, using threat intelligence and operational insights to improve detection coverage, accuracy and the identification of cyber threats.

You will apply and refine threat-informed detection engineering practices, standards and quality controls, strengthening the organisation’s ability to identify and respond to cyber threats.

Senior SOAR & Detection-as-Code (DaC) Analyst

This role focuses on improving cyber detection, response and automation capabilities through security automation, response playbooks and Detection-as-Code practices. You will design, develop, test, maintain and improve security automation workflows, response playbooks and integrations using SOAR platforms or comparable automation technologies, while applying structured and repeatable DaC methodologies

You will work with SOC teams and other business areas to improve incident handling, implement complex solutions for emerging threats, contribute to relevant standards and process improvements, and reduce operational effort and future risk.

When submitting your application, please clearly indicate which role(s) you wish to be considered for.

As a Senior Response Manager in either of these roles your main responsibilities will be to;

Carry out security monitoring, detection and response activities in line with agreed standards, providing advice on mitigation, escalation and risk reduction.

Identify, analyse and investigate indicators of malicious activity across networks, systems and applications, supporting effective threat detection and incident response.

Triage security events and alerts, supporting investigations and recommending improvements to monitoring controls, detection coverage and overall security posture.

Support incident response activities, including red teaming and threat hunting exercises, communicating investigation outcomes and contributing to lessons learned and post-incident reviews.

Develop, review and continuously improve monitoring use cases, detection content and alert effectiveness across a range of security technologies.

Define and enhance processes, tooling and security controls to identify emerging threats, strengthen detection capabilities and implement effective mitigation strategies.

Drive service and process improvements by applying industry best practice, sound judgement and problem-solving skills to support efficient security operations and investigations.

Working Pattern

This role is available on a full-time basis with the option of compressed hours working. This role is also suitable for part-time working hours, with a minimum requirement to work 4 days/ 30 hours per week due to business requirements.

Person specification

Essential Skills

You will have a demonstrable passion for Cyber Security, Detection and Response with the following skills, knowledge or experience;

As a Senior Technical Detection Analyst

Conducting investigations and working in a ‘Security Operations Centre’ environment, including the identification and analysis of potentially malicious activity.

Developing, maintaining or improving SIEM monitoring and detection content, using threat intelligence and operational insights to improve detection coverage, accuracy and the identification of cyber threats.

As a Senior SOAR & DaC Analyst

Conducting investigations and working in a ‘Security Operations Centre’ environment, supporting security operations and incident response activities.

Designing, developing, testing maintaining and improving security automation workflows, response playbooks and integrations using SOAR platforms or comparable automation technologies, while applying DaC methodologies.

Additionally, for both roles, experience of;

Communicating in a verbal and written manner, and a good understanding of the use of different channels and formats for different audiences

Managing a team in a technical environment

SFIA capability framework

Skills for the Information Age (SFIA) version 8 is the technical framework that sets the standard capability and development of all levels in the Home Office. This is a link to the capability framework: All skills A - Z English (sfia-online.org).

We use set SFIA technical skills to form our interview questions and we will assess you against these technical skills during the selection process.

The essential skills listed above are reflective of the Home Office Government Digital and Data Profession Career Framework (based on the industry standard SFIA framework). Use the SFIA Levels of responsibility to understand what would be expected for each technical skills listed below.

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in Sheffield

Why this fits a police background — match score 90/100

  • Intelligence & OSINT
  • Incident command & response
  • Investigative casework
  • Security operations

What cyber security & digital forensics roles pay ex-police

Advertised UK ranges, editorial estimates reviewed July 2026

Digital forensics analyst£32,000–£45,000
DFIR consultant£45,000–£65,000
Senior forensics / IR specialist£60,000–£80,000
Threat-intelligence specialist£55,000–£80,000
Full cyber security & digital forensics salary guide →

More cyber security & digital forensics jobs for ex-police

  • Senior Vulnerability Manager

    Home Office · Sheffield

    Full-time

    £53,850 – £56,850Estimated

    Details New entrants to the Civil Service will start their role on the salary band minimum £49,850 for National roles. You may be eligible for an additional non-pensionable allowance, pending a Capability and Skills Assessment, with a value of up to £10,200.

    Posted 9 days ago

  • Cyber Security Officer

    Bridgend County Borough Council · Cardiff

    Full-time

    £44,075 – £46,142Estimated

    37 hours per week Bridgend County Borough Council’s ICT Department is committed to providing a customer-led information technology service. Our aim is to continuously improve our services by meeting the evolving business needs of our customers through appropriate investment in technology,…

    Posted 2 days ago

  • Full-time

    £80,000 – £84,000Estimated

    Job Title: Senior Solution Architect Job Type: Full Time Employment Type: Permanent Experience Level: Senior We are seeking a Senior Solution Architect to shape and deliver scalable, secure and resilient technology solutions across a complex enterprise environment.

    Posted 2 days ago

  • Job details *Location:*London, Manchester *Capability:*Advisory *Experience Level:*Associate/Assistant Manager *Type:*Full Time *Business Area:*Cyber *Contract type:*Permanent Job description Cyber Response & Recovery Assistant Manager (Reactive DFIR) This role requires current SC or DV clearance,…

    Posted 3 days ago