×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

Lead Cyber Security Monitoring

Job in Swansea, Swansea County, SA1, Wales, UK
Listing for: Ad Warrior Ltd
Full Time position
Listed on 2026-09-04
Job specializations:
  • IT/Tech
    Cybersecurity
Salary/Wage Range or Industry Benchmark: 44241 GBP Yearly GBP 44241.00 YEAR
Job Description & How to Apply Below
Position: Lead Cyber Security Monitoring )

Lead Cyber Security Monitoring

Location:

Bristol, Swansea, Leeds, Nottingham, Newcastle, Oldham (Chadderton), Birmingham(Garretts Green) or Uxbridge.

Salary : £44,241 per annum (Plus an additional Government Digital and Data Profession allowance (non-pensionable) up to £14,756.)

Vacancy Type:
Permanent,Flexible working, Full-time, Job share, Part-time

Closing Date: 31st August 2026

This role sits within the Security Operations Centre and responds to events found as part of the protective monitoring processes led directly by DVSA or its service provider. It also responds to incidents of a technical nature in line with DVSA Incident Management procedures. It restores normal service operation as quickly as possible and minimises any adverse effect on business operations.

This ensures that the best possible levels of service quality and availability are maintained, whilst containing any security breach to allow for forensic analysis to establish cause. It establishes action plans in collaboration with other managers in the team and wider DVSA. It effectively manages, investigates and reports on potential/actual failures to comply with security requirements, and identifies process improvements

Joining our department comes with many benefits, including:
  • Employer pension contribution of 28.97% of your salary.
  • 25 days annual leave, increasing by 1 day each year of service (up to a maximum of 30 days annual leave), plus 8 bank holidays a privilege day for the King's birthday
  • Flexible working options where we encourage a great work-life balance.
Job description

Your responsibilities will include, but aren't limited to:

  • Leading the rapid detection, investigation, and response to cyber security incidents, ensuring threats are contained, impact is minimised, and incidents are handled in line with DVSA policies, legal requirements, and best‑practice security standards, including performing or arranging digital forensics to support evidence gathering and preservation.
  • Driving proactive cyber defence through threat hunting and vulnerability management, using threat intelligence to identify emerging risks, suspicious activity, and weaknesses in DVSA's security posture.
  • Manage post-incident review, including root cause analysis, to feedback information and so improve monitoring and evidencing need for policy change as necessary.
  • Managing and improving SOC processes and protective monitoring capabilities, ensuring DVSA and its suppliers meet contractual and policy obligations for incident reporting and security operations.
  • Planning, leading, and evaluating incident response exercises, including red‑team activity, to strengthen organisational readiness and validate response procedures.
  • Providing expert advice to senior leaders and technical teams, helping them understand risks, make informed decisions, and embed strong security practices.
  • Building strong relationships across DVSA and with external partners, including government departments, regulators, and third‑party suppliers.
  • Producing clear, high‑quality reporting and communication, including incident summaries, performance statistics, lessons learned, and recommendations for continuous improvement.
  • Demonstrating leadership by guiding, mentoring, and supporting SOC analysts and colleagues, acting as a role model for professional standards, technical excellence, and Civil Service values.
Person specification

You may hold or be willing to work towards the following qualifications:

CSSP, CISSP, Degree in IT or Cyber Security, or a Professional Qualification relating to the same

Required experience:

  • Demonstratable experience working with a SIEM tool (Microsoft Sentinel, Splunk, etc), and vulnerability scanners.
  • Ability to explain technical and complex concepts simply to a variety of audiences acting as a bridge between the technical and the non-technical, providing updates and recommendations in a clear and comprehensive manner.
  • Experience in interpreting threat intelligence and building in rulesets into IDS/IPS toolsets to the threat risks.
  • Good working knowledge of security concepts (Physical, Personal, IT and Cyber Security), including security controls, security risk management and…
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary