About this role
Details
New entrants to the Civil Service will start their role on the salary band minimum £49,850 for National roles. You may be eligible for an additional non-pensionable allowance, pending a Capability and Skills Assessment, with a value of up to £10,200.
A Civil Service Pension with an employer contribution of 28.97%
GBP
Job grade
Senior Executive Officer
Business area
HO - Home Office Digital
Type of role
Digital
Information Technology
Working pattern
Full-time, Compressed hours
Number of jobs available
1
Contents
•
About the job
•
Benefits
•
Things you need to know
•
Apply and further information
About the job
Job summary
Cyber Security at the Home Office is at the front end of protecting one of the largest government departments and safeguarding the critical digital infrastructure. Vulnerability Management is a critical service within this operation, delivering a managed approach to proactively identifying vulnerabilities and developing effective remediation strategies.
Where business needs allow, some roles may be suitable for a combination of office and home-based working. Where this is the case, employees will be expected to spend a minimum of*60% of their working time in the office*. Applicants can raise any queries to the email address at the bottom of the advert.
Watch this short video to hear from members of Home Office Digital talking about the projects they work on and their experience of working here: Working for Home Office Digital.
Job description
The role of Vulnerability Management is to triage vulnerabilities by relevance and criticality to the organisation. Vulnerability Management then identify mitigations for those vulnerabilities and advise on implementing them.
Youll join an expert team of cyber professionals, committed to fighting cyber-attack across a complex network of systems. Youll be aided by a supportive organisational culture, and a commitment to further your continuous development.
Person specification
Main Responsibilities
Your main day to day responsibilities will be
•
Vulnerability Identification Lead the process of identifying and classifying technical vulnerabilities in systems, applications and networks to identify security weaknesses and potential risks. Utilise vulnerability management tools/technologies to identify, assess and report on vulnerabilities.
•
Risk Assessment Analyse and evaluate the results of vulnerability scans to determine the severity and potential impact of identified vulnerabilities, categorising them based on risk to assets and operations.
•
Remediation Planning Collaborate with multiple departments, technical teams and senior stakeholders to recommend remediation plans and complex configuration changes in support of vulnerability remediation.
•
Reporting Create and present detailed reports on vulnerability assessments, remediation efforts, and overall vulnerability management performance for stakeholders, management and technical teams.
•
Incident Management Work closely with other security teams and technical resolver groups to ensure comprehensive approach to managing prioritised vulnerabilities.
•
Tool management - Knowledge and understanding of approaches and tooling used to perform vulnerability assessments against large and complex infrastructure. Implementing continuous monitoring processes to identify new vulnerabilities and assess the effectiveness of remediation efforts over time.
•
Vulnerability Management Service - Onboard assets into the appropriate vulnerability management tooling in line with the Threat and Vulnerability Management Service. Ensure that all vulnerability management activities align with service polices, standards and procedures.
Working Pattern
Due to the business requirements of this role, it is only available on a full-time basis. However, compressed hours are available.
Essential Skills
Youll have a demonstrable passion for Vulnerability Management, with the following skills or strong experience in:
•
Driving improvements in vulnerability management processes and practices, working with security and technology teams to deliver technical and operational change.
•
Conducting vulnerability assessments using recognised frameworks, understanding severity and contextualising risk within an organisational environment to support effective prioritisation.
•
Implementing and operating technical vulnerability management tooling, ensuring effective deployment, maintenance and use of data to identify, analyse and communicate security risk.
•
Managing security risk, working collaboratively with stakeholders to drive remediation and achieving good security outcomes aligned to organisational prioritises and risk appetite.
•
Communicating complex technical vulnerability risk clearly and effectively, producing high quality written and verbal reports tailored to technical specialists and non-technical senior stakeholders.
•
Coordinating effective incident response activities in fast-paced environments, engaging with cross-functional teams to triage, contain and remediate security incidents.
SFIA capability framework
Skills for the Information Age (SFIA) version 8 is the technical framework that sets the standard capability and development of all levels in the Home Office. This is a link to the capability framework: All skills A - Z English (sfia-online.org).
We use set SFIA technical skills to form our interview questions and we will assess you against these technical skills during the selection process.
The essential skills listed above are reflective of the Home Office Government Digital and Data Profession Career Framework (based on the industry standard SFIA framework). Use the SFIA Levels of responsibility to understand what would be expected for each technical skills listed below.
Strategy and Architecture
•
Security and Privacy
- Threat Intelligence (THIN) Level 3
•
Governance, risk and compliance
- Risk management (BURM) Level 3
Delivery and Operation
•
Service Management
- Incident Management (USUP) Level 3
•
Security Operations (SCAD) Level 3
•
Security services
- Vulnerability Assessment (VUAS) Level 3
•
Relationships and engagement
•
Stakeholder management
- Stakeholder relationship management (RLMT) Level 3 (Generic Level 3 descriptor)
Behaviours
We'll assess you against these behaviours during the selection process:
- Making Effective Decisions
- Changing and Improving
- Delivering at Pace
Technical skills
We'll assess you against these technical skills during the selection process:
- Threat Intelligence (THIN) Level 3
- Risk management (BURM) Level 3
- Incident Management (USUP) Level 3
- Security Operations (SCAD) Level 3
- Vulnerability Assessment (VUAS) Level 3
- Stakeholder relationship management (RLMT) Level 3 (Generic Level 3 descriptor)
Benefits
Alongside your salary of £49,850, Home Office contributes £14,441 towards you being a member of the Civil Service Defined Benefit Pension scheme. Find out what benefits a Civil Service Pension provides .
Why work for us...
Find out more information at: Benefits - Home Office Careers, but some of the primary ones are:
•
A Civil Service Pension with employer contribution rates of at least 28.97%.
•
In-year reward scheme for one-off or sustained exceptional personal or team achievements.
•
25 days annual leave on appointment, rising with service.
•
8 days of public holidays, plus 1 additional privilege day.
•
Where business needs allow, some roles may be suitable for a combination of office and home-based working. This is a non-contractual arrangement where all employees will be expected to spend a minimum of 60% of their working time in an office.
Sign-up on our website to receive emails with information about careers at the Home Office.
About cyber security & digital forensics roles for ex-police
Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.
See all cyber security & digital forensics jobs in Sheffield →Why this fits a police background — match score 90/100
- Intelligence & OSINT
- Incident command & response
- Risk & threat assessment
- Working to legislation & regulation
- Security operations
What cyber security & digital forensics roles pay ex-police
Advertised UK ranges, editorial estimates reviewed July 2026
| Digital forensics analyst | £32,000–£45,000 |
| DFIR consultant | £45,000–£65,000 |
| Senior forensics / IR specialist | £60,000–£80,000 |
| Threat-intelligence specialist | £55,000–£80,000 |