Cyber Security Infrastructure Engineer
Department for Work and Pensions
Apply before 11:55 pm on Sunday 17th November 2024
Details
Reference number
Salary
Job grade
Contract type
Business area
Type of role
Engineering
Information Technology
Security
Working pattern
Number of jobs available
Contents
Location
About the job
Job summary
Are you a Cyber Security Engineer with experience of working in a large Digital Organisation?
If so, click that apply button now and join us as a Cyber Security Engineer.
This role within our Digital Security Transformation Programme is working in a security engineering team with an objective to improve the Department’s Cyber Security posture across our estate of Digital Services, embedding security controls to ensuring we are secure by design.
You will have experience in cyber security design including the products, services and techniques used to build and operate cyber security services. Understanding the impact of a security breach and ability to advise on cyber security protocols.
Please note this role requires you to pass Security Check clearance. For further information, please see 'Selection process details'.
Job description
As a Cyber Security Engineer you will be responsible for embedding security into all stages of the Software Development Life Cycle (SDLC) in a large-scale, complex environment.
You will play a key role in maintaining the security of nearly 1 billion lines of code by implementing and maintaining modern software delivery practices, including automation and continuous integration/continuous delivery (CI/CD) pipelines.
You will ensure the development and deployment of secure, resilient software solutions.
Working collaboratively with development, operations, and security teams, you will design and implement security policies and controls that prevent vulnerabilities, ensuring alignment with industry best practices.
You will contribute to the enhancement of security processes and tooling that support the DevOps model, ensuring security is integrated at every step of the development cycle.
Key Responsibilities:
- Embed security practices throughout the SDLC, leveraging automation, DevOps, and CI/CD pipelines to maintain the integrity of vast, diverse codebases
- Collaborate with engineering and development teams to implement security controls that protect against vulnerabilities in code and infrastructure
- Develop and automate security policies and processes within the CI/CD pipeline, ensuring timely detection and remediation of security issues
- Contribute to the operational security of code and infrastructure in both cloud-native and on-premise environments
- Assist in building and maintaining security tooling to monitor and enforce security standards in the SDLC
- Actively participate in incident response and remediation efforts, working with security operations teams to identify and mitigate risks
- Stay current with industry trends, standards, and best practices for secure software development, sharing knowledge across teams
It would also be helpful to have skills in the following areas:
- Hands-on Experience with Security Tools
- Experience with any of the following security platforms or tools:
- Vulnerability scanning and management tools (e.g., SAST and DAST)
- Cloud security services (e.g., AWS GuardDuty, Azure Security Centre)
- Security Orchestration, Automation, and Response (SOAR) platforms
- Web Application Firewalls (WAFs) and Endpoint Detection and Response (EDR) solutions
- Understanding of Security in DevOps: Experience or familiarity with integrating security into DevOps workflows (DevSecOps)
- Programming/Scripting Skills: Familiarity with languages such as Python, nodeJs, Bash, or similar for automating security tasks
When giving details of your CV, you should therefore include details of the work and projects that you have been involved in, and your role therein.
Person specification
When giving details in your CV you should highlight your experience in line with essential criteria below:
- Ability to demonstrate an understanding of Software Delivery Methods: Knowledge of modern software delivery methods (e.g., DevOps, CI/CD) and how they can be applied within security practices, including experience with automation in the SDLC: Demonstrated experience with automating security processes, including the use of infrastructure as code and automated testing tools
- Proven ability to analyse security requirements and develop security cases compliant with legal and regulatory frameworks (e.g., GDPR, ISO 27001)
- Demonstrable experience writing clear, structured reports and delivering presentations tailored to both technical and non-technical audiences
- Hands-on experience conducting vulnerability assessments, prioritising remediation, and maintaining ongoing security with relevant tools and practices
- Security Frameworks and Standards: Familiarity with security frameworks such as the NIST Cybersecurity Framework, CIS Critical Security Controls, or similar
- Strong coding skills in developing and testing secure scripts or programs, ensuring system functionality and security in critical environments
If you would like to learn more about the role, please contact richard.hanley@dwp.gov.uk.
Benefits
Alongside your salary, the Department for Work and Pensions contributes 28.97% towards you being a member of the Civil Service Defined Benefit Pension scheme. Find out what benefits a Civil Service Pension provides.
We also have a broad benefits package built around your work-life balance which includes:
- Working patterns to support work/life balance such as job sharing, term-time working, flexi-time and compressed hours.
- Generous annual leave – at least 23 days on entry, increasing up to 30 days over time (pro–rata for part time employees), plus 9 days public and privilege leave.
- Support for financial wellbeing, including interest-free season ticket loans for travel, a cycle to work scheme and an employee discount scheme.
- Health and wellbeing support including our Employee Assistance Programme for specialist advice and counselling and the opportunity to join HASSRA a first-class programme of competitions, activities and benefits for its members (subscription payable monthly).
- Family friendly policies including enhanced maternity and shared parental leave pay after 1 year’s continuous service.
- Funded learning and development to support progress in your role and career. This includes industry recognised qualifications and accreditations, coaching, mentoring and talent development programmes.
- An inclusive and diverse environment with opportunities to join professional and interpersonal networks including Women’s Network, National Race Network, National Disability Network (THRIVE) and many more.
This job role may be suitable for hybrid working, which is where an employee works part of the week in their DWP office and part of the week from home. This is a voluntary, non-contractual arrangement and your office will be your contractual place of work. The number of days that anyone will be able to work at home will be determined primarily by business need but personal circumstances and other relevant circumstances will also be taken into account. If you are successful, any opportunities for hybrid working, including whether a hybrid working arrangement is suitable for you, will be discussed with you prior to you taking up your post.
Salary Information
New entrants to the Civil Service will join on band minimum.
Existing Civil Servants who secure a new role on lateral transfer should maintain their current salary.
Existing Civil Servants who gain promotion may move to the bottom of the grade pay scale or 10% increase in salary whichever would be the greater.
Things you need to know
Selection process details
As part of the application process you will be asked to complete a CV and Personal Statement. Further details around what this will entail are listed on the application form.
Stage 1: Application
Your application will consist of three parts:
1. A Personal Details application form.
2. Your employment history detailing your responsibilities, skills, accomplishments, plus your qualifications and relevant training. Please copy this information into the box field provided.
3. Personal statement up to 1250 words. Further details around what this will entail are listed on the application form.
When giving details in your employment history and personal statement you should highlight your experience in line with essential criteria listed in the Person Specification.
The sift panel will use the information in your employment history and personal statement to assess your experience, skills and knowledge against the essential criteria above.
You will be provided with one combined overall assessment score for both your CV and Personal Statement.
Applications will be sifted at regular intervals from the date the posts are advertised. Please apply as soon as you can, do not wait until the end of the campaign.
Important Information
- You will be asked to complete your employment history any information that you would customarily share on a CV should therefore be entered onto the application form.
- Personal details that could be used to identify you including your name, contact details and address must be removed for your application to be considered.
- If your employment history/personal statement contains any personal details your application will be withdrawn.
Sift and interview dates to be confirmed.
Stage 2: Interview
If you’re successful at sift stage you will be invited to a video interview via Microsoft Teams. There, you will be assessed against the experiences listed in the essential criteria.
Interviews will take place from early December 2024.
Further Information
Find out more about Working for DWP
For Hints and Tips on completing your application visit Applying for jobs at DWP Digital.
A reserve list may be held for a period of 6 months from which further appointments can be made.
Reserve list candidates will be posted in merit order by location.
The Civil Service values honesty and integrity and expects all candidates to abide by these principles. Please ensure that all examples provided in your application are taken directly from your own experience and that you describe the examples in your own words. Applications will be screened and if evidence of plagiarism or copying examples/answers from other sources is found, your application will be withdrawn. Internal DWP candidates may also face disciplinary action.
Reasonable Adjustment
At DWP we value diversity and inclusion and actively encourage and welcome applications from everyone, including those that are underrepresented in our workforce.
We consider visible and non-visible disabilities, neurodiversity or learning differences, chronic medical conditions, or mental ill health. Examples include dyslexia, epilepsy, autism, chronic fatigue, or schizophrenia.
If you need a change to be made so that you can make your application, you should: Contact Government Recruitment Service via DigitalRecruitment.grs@cabinetoffice.gov.uk as soon as possible before the closing date to discuss your needs.
Complete the “Reasonable Adjustments” section in the “Additional requirements” page of your application form to tell us what changes or help you might need further on in the recruitment process. For instance, you may need wheelchair access at interview, or if you’re deaf, a Language Service Professional.
For further information on reasonable adjustments, terms and conditions and how we recruit visit the How We Recruit, page
For further information on National Security Vetting please visit the following page https://www.gov.uk/government/publications/demystifying-vetting
Security Clearance Requirement
You must meet the security requirements before you can be appointed. The level of security needed is security check.
For meaningful checks to be carried out, you will need to have lived in the UK for a sufficient period of time, to enable appropriate checks to be carried out and produce a result which provides the required level of assurance. Whilst a lack of UK residency in itself is not necessarily a bar to a security clearance, and expectation of UK residency may range from 3 to 5 years. Failure to meet the residency requirements needed for the role may result in the withdrawal of provisional jobs offers.
Feedback will only be provided if you attend an interview or assessment.
Security
Nationality requirements
Working for the Civil Service
We recruit by merit on the basis of fair and open competition, as outlined in the Civil Service Commission's recruitment principles (opens in a new window).
Diversity and Inclusion
Apply and further information
Contact point for applicants
Job contact :
- Name : Richard Hanley
- Email : richard.hanley@dwp.gov.uk
Recruitment team
- Email : digitialrecruitment.grs@cabinetoffice.gov.uk