Job Details

National Management Centre Cyber Security Engineer

Police Digital Service

Overview

The new National Management Centre (NMC) in Wigan is part of Police Digital Services and provides visibility and control of information risks for policing.
£50,000
per year
Full time, Permanent, Hybrid
(Full time hours per week)
Wigan / Hybrid

Key information

To protect people from harm in our rapidly changing world, police services must not only keep up with technology and business changes but develop capabilities and ways of working that will enable them to adapt to and deal with the complexity of modern criminality.

At the NMC, you will benefit from hybrid working, getting the advantages of both face-to-face team engagement and home working. NMC employees have the opportunity to work in our new modern office environment for in-person collaboration, however you will also get the opportunity to work from home 2 days a week.

About the role

  • Configuration and maintenance of the National Management Centre (NMC) central Microsoft Azure, Lighthouse and Sentinel platform.
  • Development, maintenance, and deployment of detection rules and other Security information and event management (SIEM) content.
  • Creation of custom solutions using both low-code and traditional development approaches.
  • Providing support to forces for the configuration of Sentinel and log sources.
  • Testing and implementing new Sentinel connectors.
  • Working with wider NMC teams, contributing to Continual Service Improvement and innovations.
  • Creation and ongoing maintenance of technical design documentation  
  • Working with the PDS design team and wider NMC operational teams to create, test and implement new tools and technologies.


We are committed to equal opportunity for all and will not discriminate on any grounds. We encourage applications from people from the widest possible span of experience. We particularly welcome applications from Black, Asian and Minority Ethnic (BAME) candidates and people with disabilities.

Requirements

  • Experience of supporting and developing Security information and event management (SIEM) platforms in the context of a Security Operations Centre.
  • Experience of log source configuration and parsing, as part of a SIEM implementation, including experience of data normalisation using RegEx.
  • Experience and relevant certification in cloud services design and administration.
  • Practical experience in the creation, testing, implementation, and support of custom tooling to support Security Operations.
  • Experience working with Application Programming Interfaces (APIs).
  • Practical experience in software development and scripting, preferably PowerShell and Python.
  • Initiative and the ability to produce quality work without close supervision.