Details Reference number 401399 Salary £41,571 - £56,784 Base salary is £41571 - £45,784 with an additional DDaT allowance of £4,350 - £11,000 available. The final salary and allowance awarded will be based on an assessment of your skills and experience as demonstrated at interview. A Civil Service Pension with an employer contribution of 28.97% GBP Job grade Senior Executive Officer DDaT Lead Contract type Permanent Business area CH - Digital Services Type of role Security Other Working pattern Flexible working, Full-time Number of jobs available 1 Contents Location About the job Benefits Things you need to know Apply and further information Location Cardiff, Wales, CF14 3UZ About the job Job summary We are looking for a motivated and experienced Lead Security Operations Specialist to help strengthen and deliver our core monitoring, triage, and response capabilities. As Companies House grows and transforms, so too does our security team—and this role is essential to ensuring we can detect, investigate, and respond to threats effectively. This is an exciting opportunity for someone who thrives in fast-paced operational environments, enjoys solving complex technical problems, and is eager to contribute to a modern, collaborative, and high-performing Security Operations Centre (SOC). You’ll support the day-to-day monitoring of our systems, lead investigations, and provide guidance to junior SOC analysts. This role offers real impact and room to grow. Companies House offers a flexible and welcoming culture that promotes a healthy work life balance as well as a proactive approach to wellbeing that allows us to be our best at work. We recognise that people are the key to our success so offer a fantastic benefits package including flexible working with no core hours, 30 days annual leave, 8 bank holidays and 1 privilege day as well as enrolment into the Civil Service Pension scheme with a contribution rate averaging 28%. Find out more about what a great place Companies House is to work Job description As a Lead Security Operations Specialist, you’ll play a central role in the day-to-day running of the Security Operations Centre. You’ll take ownership of alert triage, support incident response efforts, and work to optimise our use of security tools like Microsoft Sentinel and Defender. Key deliverables: Monitoring security alerts and logs to identify, assess, and respond to potential threats and suspicious activity. Leading investigations into incidents and determining appropriate escalation or remediation actions. Fine-tuning rules and queries in Microsoft Sentinel and Microsoft Defender to improve detection accuracy and reduce false positives. Supporting and guiding junior SOC analysts, helping to build capability through coaching, shadowing, and knowledge sharing. Maintaining and improving playbooks, dashboards, and incident workflows. Working with IT, platform, and development teams to ensure effective integration of monitoring and security tooling. Advising on security improvements and collaborating on automation opportunities using scripting and playbooks. Providing technical input into incident reports and contributing to policy or procedural updates where needed. Assisting with key security tools, including email and proxy solutions Forcepoint, database monitoring systems, VPNs, and cloud-native security controls. About the team The Cyber Security Team sits within the Data and Cyber Security Directorate, a growing part of Companies House that plays a central role in keeping our systems, data, and services secure as we undergo a large-scale digital transformation. You’ll be joining the Security Operations Centre, a collaborative and skilled team responsible for monitoring, detecting, and responding to security threats across the organisation. We are building out a modern SOC, focused on automation, proactive detection, and intelligent response. The team works closely with digital, platform, data, and infrastructure teams to embed security into everything we do. The team culture is open, inclusive, and centred around learning and collaboration. We believe in shared responsibility, encourage knowledge-sharing, and support individual growth. You’ll have opportunities to shape tooling and processes, contribute ideas, and help build a security function that evolves with the organisation’s needs. Person specification We are looking for the following experience and skills which will be assessed at sift and interview. Experience We are seeking someone with strong experience in operational cyber security and a passion for improving security outcomes through hands-on problem-solving. We are looking for applicants who have: Experience working in a Security Operations Centre or cyber operations team, ideally with exposure to public sector or enterprise environments. Technical knowledge of SIEM platforms such as Microsoft Sentinel, with experience in writing and tuning detection rules. Familiarity with Microsoft Defender, Microsoft Azure, and Amazon Web Services, including how to spot and investigate risks in these platforms. A strong understanding of security alert triage and escalation, including when and how to act during potential incidents. Confidence in reviewing junior analysts’ work, providing mentoring, and helping to build team capability. Practical experience with: Forcepoint email and proxy management tools, including handling alerts and configuring rules. Database monitoring, analysis, and detecting suspicious or unauthorised behaviour. A proactive, collaborative mindset with a desire to improve tooling, processes, and response efficiency. Clear written and verbal communication skills and the ability to explain technical issues to a range of audiences. Behaviours We'll assess you against these behaviours during the selection process: Making Effective Decisions Working Together Developing Self and Others Technical skills We'll assess you against these technical skills during the selection process: Cyber Security operations Intrusion detection and analysis Incident management Incident investigation and response Benefits Alongside your salary of £41,571, Companies House contributes £12,043 towards you being a member of the Civil Service Defined Benefit Pension scheme. Find out what benefits a Civil Service Pension provides. We believe that our success is driven by the well-being and satisfaction of our team members at all levels of the organisation. At Companies House we’re committed to providing a comprehensive benefits package that goes beyond the ordinary, ensuring your career journey with us is not only fulfilling, but also rewarding. We pride ourselves on offering a quality work-life balance with our employee wellbeing being central to our working practices. Head to Our benefits - Working for us - Recruitment (companieshouse.gov.uk) to find out more about the fantastic benefits package we have at Companies House. We celebrate diversity... As an equal opportunity employer, we celebrate diversity, being committed to ensuring we’re representative of the citizens we serve and creating an inclusive environment. Everyone in Companies House brings something different, and so will you. To fulfil our commitment to recruiting and attracting diverse talent we welcome applications from underrepresented groups. We also welcome applications from Welsh speakers. We are proud to be a disability confident leader. Our recruitment process is fully inclusive and we can make adjustments as needed through our process. These could include having an interview buddy, extra time at interviews/assessments and receiving interview questions in advance, to name a few. If you require any reasonable adjustments at application stage, or if you'd like to discuss any person-centred adjustments, please contact us by emailing [email protected] . Where will you be working? You will be aligned to our Cardiff office, where you will be expected to attend on a regular basis. We are currently using a hybrid approach to the way we work which provides opportunities for you to be adaptable in the way you work so that you can achieve a healthy balance between your work and home life. The degree of choice you have will depend on your role and your day-to-day work activities. Your manager will agree regular patterns of attendance with you, however you may be required to make yourself available to attend the office more frequently when required to meet business needs. Things you need to know Selection process details This vacancy is using Success Profiles , and will assess your Behaviours, Experience and Technical skills. In your application form we’d like you to: Tell us about your employment history, including any key responsibilities and achievements. Write a personal statement of 1250 words where you demonstrate how you meet the skills required for this role, providing examples to evidence your level of skill. In your personal statement we are looking for evidence of: Experience working in a Security Operations Centre or cyber operations team, ideally with exposure to public sector or enterprise environments. Technical knowledge of SIEM platforms such as Microsoft Sentinel, with experience in writing and tuning detection rules. Familiarity with Microsoft Defender, Microsoft Azure, and Amazon Web Services, including how to spot and investigate risks in these platforms. A strong understanding of security alert triage and escalation, including when and how to act during potential incidents. Confidence in reviewing junior analysts’ work, providing mentoring, and helping to build team capability. What will the process look like? Sift Once the advert has closed we will sift applications - this involves reading through them all, please bear with us as this can take some time. We may raise the score required if we receive a high number of applications. At sift candidates will be assessed against experience listed in the advert and alongside your work history the panel will score your personal statement against the following criteria: Experience working in a Security Operations Centre or cyber operations team, ideally with exposure to public sector or enterprise environments. Technical knowledge of SIEM platforms such as Microsoft Sentinel, with experience in writing and tuning detection rules. Familiarity with Microsoft Defender, Microsoft Azure, and Amazon Web Services, including how to spot and investigate risks in these platforms. A strong understanding of security alert triage and escalation, including when and how to act during potential incidents. Confidence in reviewing junior analysts’ work, providing mentoring, and helping to build team capability. Interview Successful candidates from the sift stage will be invited to attend a virtual interview, which will conducted using Microsoft Teams. We use a blended interview technique, allowing us to find out more about you. We use the Success Profile framework and at interview we will use Success Profiles assessing the Behaviours, Technical Skills and Experience listed in the advert. There will be a scenario-based technical discussion as part of the interview process. This will assessing Technical Skill: Intrusion detection and analysis. Details of this will be shared at the beginning of your interview and will form the first 10 minutes of the interview before going into Behaviour and Technical questions. A reserve list may be held for up to 12 months from which further appointments may be made for the same or similar roles. Key dates (dates are indicative only and could be subject to change) Closing date - 8 May 2025 (at 23:55) Sifting - from 9 May 2025 Interviews - from 15 May until 23 May 2025 We’re committed to being diverse and inclusive, so please make your application anonymous by removing all identifying personal information (such as names and dates) from your employment history and personal statement. Our recruitment process is underpinned by the principle of recruitment based on fair and open competition with decisions made on the basis of merit, as outlined in the Civil Service Commissioners’ Recruitment Principles. Artificial Intelligence (AI) We understand that you might use AI and other resources for your application; however, please ensure all information you provide is factually accurate, truthful, and original and doesn’t include ideas or work that isn’t your own. This is so that your application is authentically and credibly your own. Your application may be rejected if evidence of plagiarism or reliance on AI is detected. Examples include presenting the ideas and experience of others, or generated by artificial intelligence (AI), as your own. If you are invited to interview, please be aware the use of AI tools is prohibited (including recording or note taking) and any suspected use may result in the termination of your interview and subsequent withdrawal from the campaign. More information on the ways you should and shouldn’t use AI can be found here. Sponsorship Companies House cannot offer Visa sponsorship to candidates through this campaign. Companies House holds a Visa sponsorship licence but this can only be used for certain roles and this campaign does not qualify. Should you apply for this role and require sponsorship, your application may be rejected, and any provisional offers of employment withdrawn. Successful candidates must pass a Baseline Personnel Security Standard (BPSS) check before they can be appointed. BPSS is an entry level security check. It uses the Police National Computer (PNC) to make sure a candidate has no convictions. The check returns evidence of any current criminal record and un-spent convictions under the Rehabilitation of Offenders Act 1974. Successful candidates must meet the security requirements for Security Check (SC) before they can be appointed. The requirement for SC clearance is to have been present in the UK for at least 3 of the last 5 years. Failure to meet the residency requirements will result in your security clearance application being rejected. Further information on National Security Vetting Nationality statement Candidates will be subject to UK immigration requirements as well as Civil Service nationality rules. If you're applying for a role requiring security clearance, please be aware that foreign or dual nationality is not an automatic bar. However certain posts may have restrictions which could affect those who do not have sole British nationality or who have personal connections with certain countries outside the UK. As part of our recruitment process, it is essential for all candidates to independently verify their eligibility to work in the UK before applying. This includes a thorough check of your right to work to ensure compliance with UK employment laws, being mindful of the recent changes to going rates detailed on GOV.UK. Please ensure you have the necessary documentation and permissions in place. Our team is dedicated to fostering a diverse and inclusive workforce and encourages applicants from all backgrounds to apply. However, it is the candidate's responsibility to ensure they meet the UK's legal requirements to work. Feedback will only be provided if you attend an interview or assessment. Security Successful candidates must undergo a criminal record check. Successful candidates must meet the security requirements before they can be appointed. The level of security needed is security check . See our vetting charter . People working with government assets must complete baseline personnel security standard (opens in new window) checks. Nationality requirements This job is broadly open to the following groups: UK nationals nationals of the Republic of Ireland nationals of Commonwealth countries who have the right to work in the UK nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities with settled or pre-settled status under the European Union Settlement Scheme (EUSS) nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities who have made a valid application for settled or pre-settled status under the European Union Settlement Scheme (EUSS) individuals with limited leave to remain or indefinite leave to remain who were eligible to apply for EUSS on or before 31 December 2020 Turkish nationals, and certain family members of Turkish nationals, who have accrued the right to work in the Civil Service Further information on nationality requirements Working for the Civil Service The Civil Service Code sets out the standards of behaviour expected of civil servants. We recruit by merit on the basis of fair and open competition, as outlined in the Civil Service Commission's recruitment principles . The Civil Service embraces diversity and promotes equal opportunities. As such, we run a Disability Confident Scheme (DCS) for candidates with disabilities who meet the minimum selection criteria. The Civil Service also offers a Redeployment Interview Scheme to civil servants who are at risk of redundancy, and who meet the minimum requirements for the advertised vacancy. Diversity and Inclusion The Civil Service is committed to attract, retain and invest in talent wherever it is found. To learn more please see the Civil Service People Plan and the Civil Service Diversity and Inclusion Strategy . Apply and further information This vacancy is part of the Great Place to Work for Veterans initiative. Once this job has closed, the job advert will no longer be available. You may want to save a copy for your records. Contact point for applicants Job contact : Name : Katie Jones Email : [email protected] Recruitment team Email : [email protected] Further information We welcome applications in Welsh / Rydym yn croesawi ceisiadau yn y Gymraeg. Selection for appointment to the Civil Service is on merit, on the basis of fair and open competition, as outlined in the Civil Service Commission’s Recruitment Principles. In accordance with the Civil Service Commissioners’ Recruitment Principles, our recruitment and selection processes are underpinned by the requirement of appointment on the basis of merit by fair and open competition. If you feel your application has not been treated in accordance with the Recruitment Principles and you wish to make a complaint, you should contact [email protected] in the first instance. If you are not satisfied with the response you receive you can contact the Civil Service Commission . [email protected] Civil Service Commission, Room G/8, 1 Horse Guards Road SW1A 2HQ. Location : Cardiff