Jisc grade: TCY3
Salary: c£42,000 per annum (negotiable based on experience) + comprehensive benefits package
Job Type: Permanent
Hours: Extended working period: 08:00 to 18:00 (35 hours per week), working an alternating shift pattern of 08:00 to 16:00 and 10:00 to 18:00.
Reports into: CSIRT Security Lead
Working style: Hybrid - A blend of working from home and your nominated hub office. We have hubs located in London, Bristol, Manchester and Oxford. For this role you may only have to attend an office once a quarter for meetings.
About the Team
Join the team protecting the UK's world-leading education and research sector from an ever-evolving cyber threat landscape.
Jisc's Security Operations Centre (SOC) plays a critical role in safeguarding the Janet Network, the UK's National Research and Education Network, which connects more than 20 million users across universities, colleges and research organisations. Combining cutting-edge security technologies, threat intelligence and specialist expertise, we provide 24/7 protection, rapid incident response and advanced threat detection to help our members stay secure and resilient.
Security Centre brings together Cyber Security Incident Response (CSIRT), Digital Forensics and Incident Response (DFIR), SIEM Analysts and Network Defensive Services specialists. Working at the forefront of cyber defence, we identify and respond to threats, support organisations through cyber incidents, conduct threat hunting activities and continuously evolve our capabilities to stay ahead of emerging risks.
This is an opportunity to work alongside highly skilled security professionals and make a real impact on the organisations that drive education, innovation and research across the UK.
About the role:
Are you passionate about cyber security and thrive in a fast-paced environment where no two days are the same?
We're looking for a Cyber Security Incident Investigator to join our growing Security Operations Centre. This is an exciting opportunity to be on the frontline of cyber defence, investigating security incidents, identifying emerging threats and helping organisations recover quickly from attacks.
You'll work with a range of Jisc-developed and industry-leading security technologies to monitor, analyse and respond to cyber threats across the Janet Network and our customer environments.
From threat detection and incident response to improving security tooling and developing new mitigations, you'll have the opportunity to make a real impact every day.
You'll also work closely with the Lead Cyber Security Incident Investigator to enhance security systems, strengthen defences and support the ongoing evolution of our incident response capabilities.
What you’ll be doing:
As part of our Security Operations Centre, you'll:
- Monitor customer and internal environments for suspicious or malicious activity using SIEM, EDR, DDoS and network security technologies.
- Investigate security alerts, triage incidents and support the delivery of effective incident response services.
- Identify, analyse and respond to cyber threats across multiple monitoring platforms.
- Support threat detection, intelligence gathering and attack mitigation activities.
- Assist organisations with remote and onsite recovery following cyber incidents.
- Work alongside the wider Cyber Security Division, Janet Network Operations Centre and Service Desk to identify and mitigate threats.
- Contribute to incident response exercises, simulations and continuous improvement initiatives.
- Support the enhancement of security analytics, detection capabilities and internal security services.
- Assist in developing tools, scripts and technologies that improve operational efficiency and threat visibility.
- Maintain awareness of emerging cyber threats and help strengthen existing controls and mitigations.
- Support evidential handling requirements and documentation associated with investigations.
- Produce reports, operational metrics and technical documentation for stakeholders and customers.
- Contribute to security awareness activities, workshops, educational materials and industry events.
This role offers a unique opportunity to gain exposure to a broad range of cyber security incidents while working within a threat intelligence-led environment that continuously evolves to stay ahead of emerging threats.
We're looking for someone who brings:
Essential Experience
- Sound understanding of IT environments and common infrastructure including: Microsoft Stack (Azure, Active Directory), Virtualisation Platforms, Backup Systems & Cloud Platforms.
- Active Directory hardening knowledge.
- Operational knowledge and experience of incident response
Desirable Experience
It would be beneficial if you also have:
- Active Directory and server recovery experience.
- Experience with tools and technologies such as SIEM, EDR, SOAR, IDS, WAF, DLP and DDoS mitigation platforms.
- Familiarity with security monitoring, threat detection and network defence capabilities.
Essential Skills
You'll be successful in this role if you have:
- Strong systems administration experience and knowledge of at least one operating system.
- Good knowledge of TCP/IP networking and related internet protocols.
- A solid understanding of cyber security threats and network security principles.
- Excellent analytical and problem-solving skills.
- The ability to remain calm and focused during security incidents.
- Strong organisational skills with the ability to prioritise effectively.
- A collaborative approach and the ability to work as part of a high-performing team.
- Excellent customer service and stakeholder engagement skills.
- A pragmatic and methodical approach to incident investigation and response.
Desirable Skills
We're also interested in candidates with:
- Understanding of UK privacy, data protection and cyber security legislation.
- Knowledge of vulnerability management and vulnerability scanning solutions.
- Familiarity with DDoS defence techniques and mitigation strategies.
- Awareness of digital forensics principles.
- The ability to communicate complex technical concepts clearly to both technical and non-technical audiences.
Qualifications
Essential:
- Degree in Computer Security or a related discipline, or
- Equivalent experience gained in a systems administration, network operations or IT operational role.
Desirable:
- Industry-recognised cyber security certifications.
- Microsoft certifications.
Additional Information
- Extended working period: 08:00 to 18:00 (35 hours per week), working an alternating shift pattern of 08:00 to 16:00 and 10:00 to 18:00.
- Enhanced background screening, including an enhanced DBS check, is required for this position.
- Due to the sensitive nature of the role, successful candidates may be required to undertake government security clearance.
This role offers the opportunity to contribute to the security and resilience of the UK's critical education and research infrastructure while working with industry-leading technologies and security experts.
Don’t meet every single requirement?
We know that sometimes people can be put off applying for a job if they think they can’t tick every box, so we encourage you to apply even if you do not meet 100% of the requirements, but you feel this role is perfect for you. You may be just the right candidate for this or other roles!
Hybrid working:
Specific patterns for working in the office are not mandated, and the frequency of time worked in the office is agreed with your manager. Meeting in person is something we value so you may need to travel on occasion to any of our hub offices.
Why work for us?
At Jisc, every role is meaningful, and every individual is valued. We foster a culture of continuous learning and personal growth, offering opportunities to develop new skills and make a real impact in education and research. With a strong focus on work-life balance, we embrace flexible working that prioritises outcomes over hours, empowering you to create a rhythm that energises both your professional and personal life.
Our Guiding Principles:
Jisc’s culture is powered by our four guiding principles: putting customers first, driving innovation, creating impact, and championing inclusive collaboration to deliver sustainable outcomes and shape a better future.
Discover the amazing benefits we provide! Here’s what you can look forward to:
- Flexible work pattern, which can adapt to suit your schedules and personal commitments
- 31 days annual leave (plus bank holidays) that includes three closure days over Christmas
- Buy up to an additional 5 days leave during the flexible benefits window
- Generous flexible pension schemes
- A range of wellbeing lifestyle benefits including company paid health care cash plan, mental health first aiders and support
- A company culture of continuous learning with access to thousands of LinkedIn Learning courses, and lots of resources and opportunities to support your development
- Financial well-being support including access to preferential loan and savings plans, mortgage advice, will writing tools and support and resources to help you make the most of your money
- A wide range of discounts and cashback from retailers and big-name high-street stores
- Family friendly policies including enhanced parental, maternity and paternity and co-parental leave as well as opportunity for career breaks
- Support your volunteering with up to 3 days volunteer leave
Equity, diversity and inclusion:
Jisc believe our people make all the difference in cultivating an inclusive culture that welcomes ideas, encourages innovation, and values belonging.
We work hard to create an equitable experience for our candidates and workforce which embraces all aspects of their identity including race and ethnicity, religion and belief, sex, gender identity, sexual orientation, trans identities, age, class, disability, neurodivergence, or veteran status.
Please let us know how we can best accommodate you throughout the recruitment process. We’re committed to making our process accessible and comfortable for everyone - just tell us what works best for you.
Just so you know, we review CVs as soon as we can and aim to provide an update on your application within 4 weeks of receiving it. However, you may hear from us a lot sooner, so please keep an eye out for our emails or calls!
We’re really looking forward to getting to know the real you. While we encourage the use of AI tools to help you get started on your CV or cover letter, we encourage you to review your application before submitting. Make sure it truly reflects your own voice, experiences, and personality.
If you are currently a Jisc employee, please apply through your Dayforce Employee profile.
We have a thorough background screening process that verifies the details you share with us in your CV and your application. Any inaccurate information supplied during the application stages can lead to a job offer being withdrawn.
Sponsorship:
Jisc has an active sponsor licence to recruit on a Skilled worker visa basis. Candidates wishing to apply who require sponsorship should determine the likelihood of obtaining a Certificate of Sponsorship for the role by assessing their circumstances against the relevant Home Office criteria. Jisc does not offer any financial re-imbursement towards the applicant costs, such as re-location, skilled worker visa and dependant costs or the immigration health charge.
No agencies please.
#INDLP