Security Operations Centre (SOC) Analyst
Department for Environment, Food and Rural Affairs · GB
Security Operations Centre (SOC) Analyst at Department for Environment, Food and Rural Affairs, based in GB, paying £34,765 - £41,375 per annum. This is a permanent role.
- Salary
- £34,765 - £41,375 per annum
- Location
- GB
- Contract
- Permanent
- Posted
- 1 day ago
- Closes
- 12 Sep 2026
- Sector
- Security Officer
27% below the typical rate for security officer
Reference ab53f9ddaac27fb9068d4c0fcaeb1423a8b8b883
About the role
Job summary
Defra is the UK government department responsible for safeguarding our natural environment, supporting our world-leading food and farming industry, and sustaining a thriving rural economy. Our broad remit means we play a major role in people's day-to-day life, from the food we eat, and the air we breathe, to the water we drink.
Digital, Data, Technology and Security (DDTS) is the trusted team for digital across the entire Defra Group.
We have around 1,000 colleagues across DDTS and our ambition is to make it easier and faster than ever for people to interact with Defra. If you are ready to drive innovation and push boundaries, we want to hear from you. Join us and together we will create a great place for living, and a green and healthy future for all.
Find out more about us on:
We are Government Digital and Data Candidate Information Pack V3 - 1
Job description
Defra's Security Operations Centre (SOC) is accountable for protecting DEFRA against cyberthreats. Our SOC analysts monitor the network and investigate any potential security incidents.
We are seeking an individual to help build our capability. Working as part of a small team you will be accountable for providing security monitoring and incident response. Using cyber security techniques, you will be ensuring that the DEFRA’s security is maintained. Our Analyst are accountable for the day-to-day handling of alerts in our Security Information and Event Management (SIEM), incidents assigned to the Security Operations Centre and investigating indicators of compromise provided by Threat Intelligence. As a Security Operations Centre (SOC) Analyst you will use a wide range of tool and technical expertise, currently focusing primarily on user behaviour, cloud security & application security.
Defra is transforming its IT security processes via a security improvement plan and approach in line with our new multi-supplier IT operating model. As we develop and grow against this plan the range of services that are protectively monitored by Defra’s SOC will increase.
The SOC team is based in Bristol, Reading and London. The successful applicant will be expected to attend one of these offices for 60% of their working hours and no other office locations will be considered.
We welcome applicants with experience of working in a Security Operations Centre and other technological backgrounds or graduates in a relevant subject who may wish to move into this field of work, it should be noted that you must demonstrate transferable technical skills and a keen interest in cyber security to be considered for the role.
Please note this post requires Security Check (SC) clearance. To gain (SC) clearance all applicants are required to have been a UK resident for a minimum of 5 years. If this requirement is not met, the individual will not be able to progress their application further.
Person specification
Responsibilities
- Accountable for detection, identification and triage of security incidents using the
provided security tooling and IT Service Management (ITSM) tool. - Expand, tune, and enhance rulesets for our SIEM (Security Information and Event Management) tool etc to identify security incidents and reduce false positives.
- Support the Senior SOC Analyst with Major Incidents and assist the wider SOC team in recovering from security breaches, participating in bridge calls and investigations of security incidents and lessons learned as appropriate.
- Respond to Information Security related queries from stakeholders e.g. wider Security Team or suppliers.
- Work with our cyber partners to better know our estate and how to apply current threat intelligence to make it technologically relevant to our estate.
- Using current tooling run threat hunting queries regularly and investigate results.
- Work with other members of the SOC to improve our threat hunting capability and investigate IOCs (Indicators of Compromise) provided by Threat Intelligence or our cyber partners, including the National Cyber Security Centre (NCSC).
- Communicate and engage with a wide range of stakeholders, telling the story of our work and the service we deliver.
Skills and Experience
- Experience of working in an Cyber Security environment and hold or be working towards a Cyber Security qualification at level 4 and above or an equivalent.
- A good communicator who has the capability to explain complex technical information to senior management and other non-technical staff using language that is plainly understood.
- Self-starter who is keen to learn about new and emerging technologies and cyberthreats and how those threats may apply to a public sector organisation.
- Demonstrate good customer service skills and experience with the ability to be adjustable in all situations.
Selection process
The Civil Service marks each element of the selection process on a merit basis. You can visit the gov.uk website for further information on the Civil Service rating scale.
Ensure you have tailored your CV and your Personal Statement to the 'responsibilities' and 'skills and experience' section of the job advert by providing examples on how you are suitable for the role. You may find the STAR method helpful when writing your personal statement.
For further information on STAR, you can check out our hints and tips document.
Application
Prior to application you will be invited to complete a Civil Service Judgement test, if successful you will be invited to complete the full application.
Online Test
After submission of the first stage of your application you will be invited to complete a Civil Service Judgement Test. If you successfully pass the test, you will be invited to complete the final stage of the application.
Please complete the online tests as soon as possible (within 24-48 hours is recommended), the closing date for the tests is 23:55pm on 11th September 2026. If you fail to complete the online test before the deadline your application will be withdrawn. Guidance for the test will be available when you are invited to take the test. The tests are administered online and accessed via the CS Jobs website.
Do not leave completing the tests until the last minute in case you experience any access or technical issues. There may not be technical support available after business hours and after 2pm on the closing date of 11th September 2026.
While the tests should work on most operating systems and modern browsers with a good internet con
Reference: ab53f9ddaac27fb9068d4c0fcaeb1423a8b8b883 · Posted 1 day ago · Closes 12 Sep 2026 · Listed via Department for Environment, Food and Rural Affairs
Apply for this job
This role is listed via Department for Environment, Food and Rural Affairs. Applications are handled on the employer's site.
Apply on employer siteOpens the employer's website in a new tab.
Safe applying: a genuine employer will never ask you to pay for a DBS check, training or equipment, or move you onto WhatsApp before you are hired. If this listing does, report it and do not pay anything.