Alexander Mann Solutions – Public Sector Resourcing
On behalf of the Cabinet Office we are looking for a Cyber Security Vulnerability Analyst (Inside IR35) for a 7 month contract working on a hybrid basis with 3 days per week on site in London, Bristol or Manchester.
The Cabinet Office supports the Prime Minister and ensures the effective running of government. The Cabinet Office is also the corporate headquarters for the government, in partnership with HM Treasury, and takes the lead in certain critical policy areas.
The Cyber Defence team delivers cyber threat intelligence, threat detection, incident response and vulnerability management capabilities for the Cabinet Office and is responsible for defending both internal IT infrastructure and citizen-facing services.
The Cyber Security Vulnerability Analyst role forms part of the Cabinet Office Cyber Security team, it reports to the Red Team Manager. The primary focus of the role will be delivering the Cabinet Office core security operations of vulnerability management.
Key outcomes from the role are the delivery of seamless vulnerability management service into Cabinet Office infrastructure and business units, verifying the effectiveness of estate-wide security measures. The focus, outcomes and responsibilities are aligned to the Government Security Profession Framework.
As a Cyber Security Vulnerability Analyst your main responsibilities will be to:
* Manage the operation and roll out of one or more vulnerability identification and
* assessment capabilities across the Cabinet Office’s on-premise and cloud-based IT estate and digital services.
* Coordinate the triage and remediation of identified vulnerabilities using a risk-based approach, working closely with service teams and developers to ensure that appropriate mitigation measures are implemented.
* Work closely with other teams across Cyber Security and the wider Cabinet Office to proactively reduce cyber security vulnerabilities.
* Produce regular reporting which delivers insights on vulnerability management activities and the impact on cyber security risk.
* Establish a detailed understanding of Cabinet Office data security and architectures enabling the delivery of consistent security advice.
* Define requirements for improving and expanding our security tooling.
* Develop and update internal plans, processes, and knowledge base articles.
Essential:
* An active SC Clearance is an essential requirement for this position.
* Strong vulnerability management experience.
* Experience developing, implementing and operating vulnerability management capabilities using Tenable One.
* Experience using a variety of sources of information to identify, analyse and report on relevant threats and vulnerabilities.
* Experience deploying, configuring and using vulnerability assessment (such as Tenable and the NCSC’s Active Cyber Defence Toolkit) and Attack Surface Management tools.
* Excellent stakeholder management skills.
* Excellent verbal and written communication skills, and the ability to communicate technical security issues to both technical and non-technical stakeholders.
* Experience with cloud environments such as AWS, Azure or GCP (preferably AWS).
Desirable:
* Experience with bug bounty programmes and platforms.
* Experience with digital brand protection.
* Experience investigating and responding to cyber incidents.
* Ability to work as part of a team in a multidisciplinary environment.
* Public Sector experience.
Please be aware that this role can only be worked within the UK and not Overseas.
Disability confident
As a member of the disability confident scheme, The Cabinet Office guarantees to interview all candidates who have a disability and who meet all the essential criteria for the vacancy. In cases where we have a high volume of candidates who have a disability who meet all the essential criteria, we will interview the best candidates from within that group.
In applying for this role, you acknowledge the following “this role falls in scope of the Off Payroll Working in the Public Sector legislation. Any rates of payment quoted will reflect the gross rate per day for the assignment and will be subject to appropriate taxes and statutory costs. As such the payment to the intermediary and your income resulting from this contract will be different”.
