Information & Cyber Security Analyst

Job summary

The NHS Counter Fraud Authority (NHSCFA) is the national body responsible for all matters relating to the prevention, detection and investigation of economic crime across the NHS. Further information about our work and annual plan for delivering this is available on our website.

An exciting opportunity has arisen to join the NHSCFA Technology team as an Information & Cyber Security Analyst. We are looking for someone with a proven background in Information/Cyber security and a flexible 'can do' attitude and approach to work in the Information & Cyber Security Team who manage and maintain the security of NHSCFA ICT infrastructure and information systems.

You will work to proactively monitor IT systems; identify, manage and resolve security incidents, vulnerabilities, security alerts and threats; potentially perform penetration testing; and contribute to maintaining security certifications, assurances and accreditations.

Potential applicants can contact Simon Clark at simon.clark@nhscfa.gov.uk for an informal chat if they have any questions regarding the role.

Role requires Security Clearance

Interviews will be face to face at Canary Wharf 24th & 25th September

We reserve the right to close this vacancy before the advertised closing date should we receive a significant number of applications.

Main duties of the job

Working as part of the Information Security team to actively monitor, maintain, and develop systems and processes to ensure the security of NHS Counter Fraud Authority ICT infrastructure and information systems.

To manage and report on processes and systems that ensure the security of the IT network infrastructure and information systems.

The post-holder will assist the team with identifying and resolving security incidents, vulnerabilities and risks. This can include, but is not limited to, proactively monitoring ICT systems, analysing firewall rules and performing penetration tests.

They will maintain a solid knowledge of the information security principles and practices, ensuring that timely technical support is provided to satisfy the organisation's business needs.

About us

We have offices based in Coventry, Newcastle and London and also offer flexible and home-based working. The NHSCFA values and respects the diversity of its employees and aims to recruit a workforce which reflects our diverse communities. We welcome applications irrespective of people's age, disability, gender, race or ethnicity, religion or belief, sexual orientation, or other personal circumstances. We have policies and procedures in place to ensure that all applicants are treated fairly and consistently at every stage of the recruitment process, including an invitation to the first stage of the selection process and consideration of reasonable adjustments for people who have a disability. We accept secondments from the public and private sector; you should have agreement to being released from your current role in principle prior to submitting an application form. When you apply for this role, you will be redirected to our recruitment system TRAC. Please apply without delay as reserve the right to close any vacancies from further submissions when we have received sufficient applications from which to make a shortlist. The CFA does not hold a sponsor licence in respect of skilled worker visas and so is unable to employ candidates requiring sponsorship.

Job description

Job responsibilities

Manage, monitor, and develop NHSCFA cyber security operations and ICT security infrastructure to manage and reduce cyber risk and mitigate cyber threats.

Actively monitor NHSCFA ICT systems:

manage and operate IT security monitoring tools and systems,

review IT system alerts,

triage to eliminate false positives.

Identify threats that have entered the network.

Evaluate and address system generated and user-reported security incidents:

identify affected systems and scope of the incident,

analyze running processes and configurations on affected systems,

carry out in-depth threat intelligence analysis to identify an attack type, source, entry point, and possible remediation,

implement remediation or escalate incident.

Support the ICT Security Incident Management Process as a member of the NHSCFA Security Incident Response Team.

Manage ICT Security service requests and incidents via the NHSCFA Service Desk system.

Ensure appropriate access control to systems is maintained.

Person Specification

pSpec

Essential
  • Experience of 1st-3rd level technical support of IT infrastructure or security, both in person and remote.
  • Demonstrate detailed knowledge of: IT system monitoring (SIEM). Security Incident Management.
  • Demonstrate detailed knowledge of Information Security in several of the following areas: Intrusion detection and prevention systems. Vulnerability Management. Network technology and operations. Windows 10 and Windows Server. SUSE Linux. Microsoft365. oInformation Security Management Systems ISO27001. Risk Management Process. IT system auditing
  • Experience with IT security architectures.
  • Demonstrate knowledge in some of the following areas: Encryption Systems. Security Products (Authentication, Data Loss Prevention, SEIM). Firewall/WAF administration
  • Degree in computer science, information technology, or a related field OR equivalent experience in a related field, e.g. network operations plus specialist security certification(s).
  • Demonstrate a thorough understanding of the use of remote management tools in the effective support of a user base distributed over a wide geographic area.
Desirable
  • Demonstrate knowledge of Information. Security in several of the following areas in addition to those matching Essential criteria: Windows 10 and Server. SUSE Linux. Microsoft365. Information Security Management Systems ISO27001. Risk Management Process. Public Services Network (PSN) and NHS N3. Database Security. Microsoft Sentinel Experience with software security architecture and software security testing.
  • Recognised qualification in area of specialisation: EC-Council Certified SOC Analyst (CSA) oEC-Council Certified Ethical Hacker ?CompTIA Security+ ?CompTIA Network+

pSpec

Essential
  • Experience of 1st-3rd level technical support of IT infrastructure or security, both in person and remote.
  • Demonstrate detailed knowledge of: IT system monitoring (SIEM). Security Incident Management.
  • Demonstrate detailed knowledge of Information Security in several of the following areas: oIntrusion detection and prevention systems. Vulnerability Management. oNetwork technology and operations. Windows 10 and Windows Server. SUSE Linux. Microsoft365. Information Security Management Systems ISO27001. oRisk Management Process. oIT system auditing
  • Experience with IT security architectures.
  • Demonstrate knowledge in some of the following areas: Encryption Systems. Security Products (Authentication, Data Loss Prevention, SEIM). oFirewall/WAF administration
  • Degree in computer science, information technology, or a related field OR equivalent experience in a related field, e.g. network operations plus specialist security certification(s).
  • Demonstrate a thorough understanding of the use of remote management tools in the effective support of a user base distributed over a wide geographic area.
Desirable
  • Demonstrate knowledge of Information. Security in several of the following areas in addition to those matching Essential criteria: Windows 10 and Server. SUSE Linux. Microsoft365. Information Security Management Systems ISO27001. Risk Management Process. Public Services Network (PSN) and NHS N3. Database Security. Microsoft Sentinel Experience with software security architecture and software security testing.
  • Recognised qualification in area of specialisation: EC-Council Certified SOC Analyst (CSA) oEC-Council Certified Ethical Hacker ?CompTIA Security+ ?CompTIA Network+

Employer details

Employer name

NHS Counter Fraud Authority

Address

7th Floor, HM Government Hub

10 South Colonnade Canary Wharf

London

E14 4PU


Employer's website

https://cfa.nhs.uk/

Company
NHS Counter Fraud Authority
Location
London, United Kingdom E14 4PU
Hybrid / WFH Options
Employment Type
Permanent
Salary
£38682.00 - £46580.00 a year
Posted
Company
NHS Counter Fraud Authority
Location
London, United Kingdom E14 4PU
Hybrid / WFH Options
Employment Type
Permanent
Salary
£38682.00 - £46580.00 a year
Posted