As a Cyber Security Incident Co-ordinator, you'll take ownership of the end-to-end security incident lifecycle, ensuring incidents are investigated, managed and resolved effectively while maintaining the highest levels of customer service.
Your Responsibilities Will Include
- Coordinating and managing security incidents from initial triage through to investigation and closure.
- Reviewing alerts, security logs and incident data to identify potential threats and determine appropriate actions.
- Working closely with internal resolver groups and specialist cyber security teams, including Threat Hunting, Security Engineering, Digital Forensics and the Cyber Threat Advisory Centre (CTAC).
- Providing operational security advice and guidance to customers and internal stakeholders.
- Escalating complex or high-priority incidents to the appropriate teams where required.
- Producing clear and accurate incident reports, dashboards and management information using Microsoft Excel and PowerPoint.
- Monitoring security trends, identifying recurring issues and making recommendations to improve processes, reduce risk and enhance overall security.
- Supporting the management of customer security directives, operational procedures and governance activities.
- Coordinating security administration activities, including engineering password controls and associated security validation processes.
- Acting as an escalation point and providing guidance to colleagues when managing complex or sensitive incidents.
- Reviewing and continuously improving operational processes to ensure lessons learned are captured and embedded.
- Supporting weekly and monthly reporting against contractual obligations and service level agreements.
- Participating in an on-call rota to support high-severity security incidents outside normal working hours.
What We're Looking For
We're looking for someone who is naturally curious, analytical and enjoys working collaboratively to solve complex problems.
You'll be someone who remains calm under pressure, communicates confidently with a wide range of stakeholders and is passionate about developing your cyber security knowledge.
You'll Ideally Have
- An interest in Cyber Security and Security Incident Management, with a genuine desire to continue learning and developing.
- Strong analytical and investigative skills with excellent attention to detail.
- A good understanding of Defence environments and secure customer operations.
- Excellent communication and stakeholder management skills, with the confidence to engage at all levels.
- The ability to make sound decisions under pressure and manage multiple priorities effectively.
- Experience producing reports, procedures or operational documentation.
- A proactive, organised approach and the ability to work both independently and as part of a collaborative team.
It would be great if you also have
- Experience working within Defence, Government, the Civil Service, Police or other secure environments.
- Previous experience coordinating or investigating security incidents.
- Knowledge of current cyber security threats, vulnerabilities and emerging attack techniques.
- Experience working within operational cyber security, security operations or secure service environments.
- A passion for continuous improvement and developing both yourself and those around you.