
Security Operations Centre Specialist
Job summary
Are you an experienced cyber security professional who would like the opportunity to play a key role within our Security Operations Centre (SOC)?
Do you have experience of analysing and addressing threats?
If so, we’d love to hear from you!
The Security Operations Centre (SOC) is central to protecting DVLA's critical digital services, ensuring the security and resilience of systems relied upon by millions of citizens every day. The SOC team provide various services such as technical protective monitoring, threat intelligence and hunting, incident response and forensics, working closely with internal stakeholders and specialist suppliers to identify, investigate and respond to cyber threats. Operating within a rapidly evolving threat landscape, the team plays a key role in safeguarding one of the UK's largest public sector digital estates.
Joining our department comes with many benefits, including:
- Employer pension contribution of 28.97% of your salary. Read more about Civil Service Pensions here
- 25 days annual leave, increasing by 1 day each year of service (up to a maximum of 30 days annual leave), plus 8 bank holidays and a privilege day for the King’s birthday
- Flexible working options where we encourage a great work-life balance.
Read more in the Benefits section below!
Find out more about what it's like working at DVLA - Driver and Vehicle Licensing Agency – Civil Service Careers
Job description
This role undertakes technical protective monitoring, monitoring of security events and performance of security tools, as well as investigating and handling (or assisting in handling) security events.
This role is responsible for undertaking all aspects of SOC activity, including hands-on monitoring of SIEM (security incident and event management) tools and other sources of alerts and of threat intelligence, maintaining the relationship with the vendors and suppliers of SOC products, including where relevant contract management responsibilities.
You will work as part of our Cyber Security Services team monitoring, identifying and responding to security relevant events.
We deliver significant and high-profile on-line services to the public, with cyber security being viewed as an essential activity in which the organisation continues to invest.
Your responsibilities will include, but aren’t limited to:
- Responsible for monitoring operational IT Security, producing regular management reports, undertaking trend analysis, tracking resource, evaluating the fitness for purpose and effectiveness of security processes.
- Manages incident and event management processes complying with SLAs.
- Interprets and contributes to the development of SOC playbooks, alarms and policies. Ongoing assurance of fitness for purpose of SOC playbooks, alarms and policies.
- Provides expert advice and recommendations regarding risk assessments and business impact analysis for defined information systems and managing the maintenance processes including quality review.
Great line management is important to us as an organisation, and we will equip and support line managers to develop the skills they need. We aim to empower line managers to create teams where people can flourish and deliver excellent outcomes for the public.
For further information on the role, please read the attached role profile. Please note that the role profile is for information purposes only - whilst all elements are relevant to the role, they may not all be assessed during the recruitment process. This job advert will detail exactly what will be assessed during the recruitment process.
Open Sessions: Would you like to find out more about the role, the team and what it’s like to work in our department? If so, we are organising an open session where you can virtually 'meet the team' on 01/10/2026 at 12:00 pm. Sign up here.
Person specification
You will be a security professional with significant experience of cyber security. You will possess a broad knowledge of the issues and techniques associated with securing a variety of technologies.
To be successful in this role you will need to have demonstrable experience of the range of activities of a security operations centre (SOC) including:
- Responding to alerts and handling incidents.
- Monitoring network traffic and user behaviour for potential malicious activity using a variety of tools.
- Investigating security events and anomalous patterns of activity.
- Practical experience of using LogRhythm or Sentinel, although experience of other SIEM (security incident and event management) tools will be considered.
Working for the DVLA Digital Team
At DVLA, licensing is just the start. Every project you implement, touch and deliver has a ripple effect that’ll wash across the nation. Here the work you’re doing has the capacity to change the way 53 million people interact with our services. As we aim to keep our roads some of the safest in the world, our innovative, transformative digital-led services help optimise a nation of individuals and business every single day.
To see how our people are transforming our digital services, head over to our DVLA Digital Services Blog and, to understand more about the great opportunities and benefits of working at DVLA read our Inside DVLA blog.
Working hours, office attendance and travel requirements
Full time roles consist of 37 hours per week. Whilst we welcome applications from those looking to work with us on a part time basis, there is a business requirement for the successful candidate to be able to work at least 35 hours per week.
There is an opportunity to work as part an on-call rota, (one week in seven) of which a non-pensionable allowance will be paid.
This role is suitable for hybrid working, which is a non-contractual arrangement where a combination of workplace and home-based working can be accommodated subject to business requirements.
The expectation at present is a minimum of 60% of your working time a month will be spent at either your designated workplace (one of the locations cited in the advert) or, when required for business reasons, in another office/work location. There may be occasions where you are required to attend above the minimum expectation.
If you have a question about hybrid working, part time/job share hours, flexible working, travelling for work, or require a reasonable adjustment, please contact the Vacancy Holder during the recruitment process to avoid possible disappointment later in the process should your working arrangements not be compatible with the requirements of the role (see below for contact details).
Security Check
Successful candidates must meet the security requirements before they can be appointed. The level of security needed is security check. To allow for meaningful checks to be carried out, candidates will be required to have at least 5 years continuous residency in the UK. All applicants for this role must ensure that they meet this minimum residency requirement - if you do not, your application will be withdrawn.
Visa Sponsorship
Please note that we do not hold a UK Visa & Immigration (UKVI) Skilled Worker Licence sponsor and are unable to sponsor any individuals for Skilled Worker Sponsorship. Candidates must ensure they have the appropriate rights to work in the UK before application.
Behaviours
We'll assess you against these behaviours during the selection process:
- Making Effective Decisions
- Seeing the Big Picture
Technical skills
We'll assess you against these technical skills during the selection process:
- Government Security Profession: Protective Security (Awareness)
- Government Security Profession: Information Risk Assessment and Risk Management (Practitioner)
- Government Security Profession: Threat Understanding (Practitioner)
Benefits
Passionate, reliable and always willing to push yourself and those around you, you’ll continue to seek improvement in your own role and challenge us too. Because we pride ourselves on how we approach your development. From training courses to specialist skills workshops and opportunities to grow your expertise, we thrive when you thrive. You can find out more about all of the above here alongside a full list of our benefits:
- Best in class learning and development tailored to your role
- An environment with flexible working options where we encourage a great work-life balance
- A culture encouraging inclusion and diversity with a range of staff communities to support all our colleagues
- Generous employer contribution of 28.9%, depending on chosen pension scheme
- Flexible working options where we encourage a great work-life balance.
- Digital communities with clear career frameworks
- On-site gym plus personal training available (membership applies)
- On-site nursery, restaurants and coffee bar
- 25 days holiday (plus bank holidays), increasing by 1 each year (up to 30) & 8 Bank Holidays plus an additional Privilege Day to mark the King’s birthday.
- 24-hour Employee Assistance Programme providing free confidential help and advice for staff.
- Free parking
Find out more about the benefits of working at DfT and its agencies (opens in a new window).
Things you need to know
Artificial intelligence
Artificial intelligence can be a useful tool to support your application, however, all examples and statements provided must be truthful, factually accurate and taken directly from your own experience. Where plagiarism has been identified (presenting the ideas and experiences of others, or generated by artificial intelligence, as your own) applications may be withdrawn and internal candidates may be subject to disciplinary action. Please see our candidate guidance (opens in a new window) for more information on appropriate and inappropriate use.Selection process details
This vacancy is using Success Profiles (opens in a new window), and will assess your Behaviours, Experience and Technical skills.How to Apply
Our selection process ensures a comprehensive assessment of each applicant's qualifications, skills, and potential fit within our organisation.
The selection process for this role will be:
Stage 1: Sift of CV and personal statement
Stage 2: Interview
You must be successful at each stage to progress to the next stage.
Stage 1: Sift
At sift, you will be assessed against the following Success Profile elements:
Experience – you will be asked to provide a CV (unlimited wordcount) and personal statement (1250-word count). Please provide evidence of your Experience of the following:
- Evidence of completing SOC Analyst functions such as investigating security events and anomalous patterns of activity.
- Evidence of using a range of security tools.
- Evidence of using SIEM tool as an analyst and administrator.
- Evidence of Cyber Security experience.
- Keeping up to date with trends and challenges in the sector.
The sift will take place week commencing 05/10/2026.
Should we receive a high volume of quality applications, we may invite a shortlist of the highest scoring candidates to interview. This means that some applications that meet the required standard could be placed ‘on hold’ after the sift and invited to interview if the vacant position(s) remain unfilled. You will be notified if your application is being put ‘on hold’ once the sift has been completed. Following interviews, any applicants remaining on hold will be notified by the panel of the next steps regarding their application.
Stage 2: Interview
At interview stage, you will be assessed against the following Success Profile elements:
Behaviours –
- Making Effective Decisions
- Seeing the Big Picture
Technical –
- Government Security Profession: Protective Security (Awareness)
- Government Security Profession: Information Risk Assessment and Risk Management (Practitioner)
- Government Security Profession: Threat Understanding (Practitioner)
The interviews will take place week commencing 12/10/2026.
This interview will be conducted at our office (Long View Road, Morriston, Swansea, SA6 7JL). Further details will be provided to you should you be selected for interview.
Appointments for this position will be made in order of merit. If you are successful in the selection process but there are no further available posts for the advertised role, you may be contacted to discuss an offer for a lower graded role (with similar experience and responsibility requirements). If you are unsuccessful in the selection process, your application may be considered for a lower graded position if your demonstrated skills and experience meet the requirements of the alternative position. Candidates will be considered in order of merit.
You can find out more about our hiring process, how to apply, and application and interview guidance on our careers site (opens in a new window).
Please note that we will try to meet the dates set out in the advert. There may be occasions when these dates will change.
Further information on the selection process
Feedback on your application can only be provided if you attend an interview or assessment.
We will also hold a12-month reserve list for this role, which may lead to potential opportunities beyond the role you applied for. You can read more about our reserve lists here.
Reasonable Adjustments
As a Disability Confident Leader employer, we are committed to ensuring that the recruitment process is fair, accessible and allows all candidates to perform at their best. If a person with a visible or non-visible disability is substantially disadvantaged, we have a duty to make reasonable changes to our processes.
Complete the “Assistance required” section in the “Additional requirements” page of your application form to tell us what changes or help you might need during the recruitment process. For instance, you may need wheelchair access at an interview, or if you’re deaf, a Language Service Professional.
If you need a reasonable adjustment so that you can complete your application, you should contact Government Recruitment Service via dftrecruitment.grs@cabinetoffice.gov.uk as soon as possible before the closing date to discuss your needs.
Document Accessibility
This job advert contains links to the DfT Careers website. Our website provides useful guidance and information that can support you during the application process. If you are experiencing accessibility problems with any attachments on this advert or the information on our website, please contact the email address in the 'Contact point for applicants' section.
Further Information
For more information about how we hire, and for useful tips on submitting your application for this role, visit theHow We Hire page of our DfT Careers website. You can find detailed information about the recruitment process and what to expect when applying for a role.
For further information on National Security Vetting please visit the Demystifying Vetting website.
Pre-employment Checking
If your application is successful but you have been dismissed from the Civil Service, your application could be removed at the pre-employment checking stage depending on the nature of the dismissal.
Applicants who are successful at interview will be, as part of pre-employment screening, subject to a check on the Internal Fraud Database (IFD). This check will provide information about employees who have been dismissed for fraud or dishonesty offences. This check also applies to employees who resign or otherwise leave before being dismissed for fraud or dishonesty had their employment continued. Any applicant’s details held on the IFD will be refused employment. A candidate is not eligible to apply for a role within the Civil Service if the application is made within a 5-year period following a dismissal for carrying out internal fraud against government.
All external applicants and current employees of accredited non-departmental public bodies (NDPBs) will be required to undergo a Social Media Check. A Social Media Check is a review of your publicly available online activity, typically across platforms like LinkedIn, Facebook, X (formerly Twitter), Instagram, and others. The purpose is to identify any public posts or content that could raise concerns for employers, such as:
- Hate speech or discriminatory behaviour
- Threats or acts of violence
- Illegal activity or substance misuse
- Sexually explicit material
- Extremist views or affiliations
Importantly, this check does not involve hacking into your accounts or accessing private messages. It only considers content you have chosen to make public. Employers use this kind of screening to help ensure their workplace remains safe, inclusive, and aligned with company values. It’s not about judging your personality or lifestyle - it’s about checking for potential red flags that might affect the role or company culture. If you have questions or concerns about the social media check, we would be happy to explain in more detail what’s being looked at and how your data is handled securely and fairly.
Feedback will only be provided if you attend an interview or assessment.
Security
Successful candidates must undergo a basic (or equivalent) criminal record check.Successful candidates must meet the security requirements before they can be appointed. The level of security needed is security check (opens in a new window).See our vetting charter (opens in a new window).People working with government assets must complete baseline personnel security standard (opens in new window) checks.
Nationality requirements
This job is broadly open to the following groups:
- UK nationals
- nationals of the Republic of Ireland
- nationals of Commonwealth countries who have the right to work in the UK
- nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities with settled or pre-settled status under the European Union Settlement Scheme (EUSS) (opens in a new window)
- nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities who have made a valid application for settled or pre-settled status under the European Union Settlement Scheme (EUSS)
- individuals with limited leave to remain or indefinite leave to remain who were eligible to apply for EUSS on or before 31 December 2020
- Turkish nationals, and certain family members of Turkish nationals, who have accrued the right to work in the Civil Service
Working for the Civil Service
The Civil Service Code (opens in a new window) sets out the standards of behaviour expected of civil servants.We recruit by merit on the basis of fair and open competition, as outlined in the Civil Service Commission's recruitment principles (opens in a new window).The Civil Service embraces diversity and promotes equal opportunities. As such, we run a Disability Confident Scheme (DCS) for candidates with disabilities who meet the minimum selection criteria.
Diversity and Inclusion
The Civil Service is committed to attract, retain and invest in talent wherever it is found. To learn more please see theCivil Service People Plan (opens in a new window) and the Civil Service Diversity and Inclusion Strategy (opens in a new window).Apply and further information
This vacancy is part of the Great Place to Work for Veterans (opens in a new window) initiative.The Civil Service welcomes applications from people who have recently left prison or have an unspent conviction. Read more about prison leaver recruitment (opens in new window).Once this job has closed, the job advert will no longer be available. You may want to save a copy for your records.Contact point for applicants
Job contact :
- Name : ITS Recruitment
- Email : ITSRecruitment@dvla.gov.uk
Recruitment team
Further information
If you feel your application has not been treated in accordance with the Recruitment Principles and you wish to make a complaint, in the first instance, you should contact Government Recruitment Services via email: dftrecruitment.grs@cabinetoffice.gov.uk If you are not satisfied with the response you receive from the Department, you can contact the Civil Service Commission: Click here (https://civilservicecommission.independent.gov.uk/) to visit Civil Service CommissionAttachments
DVLA Digital Job Brochure - V1 2025 Opens in new window (pdf, 2074kB)Role Profile -HEO-Security Operations Centre (SOC) Specialist - V4.0 Opens in new window (pdf, 235kB)Salary range
- £39,163 per year