skip navigation
skip mega-menu

Principal Network and Security Specialist - CO - G6

Government Digital & Data -

Full-time (Permanent)
£71,730 - £87,521 Offers above the band minimum are subject to our assessment of your skills and experience as demonstrated at interview.
Published on
30 January 2025
Deadline
9 February 2025

The Cabinet Office is undergoing a significant Digital Transformation.  Over the next three years we aspire to make UK Government digital services the best in the world, meeting or exceeding the benchmark set globally by the best public or private sector standards.

For us to meet this ambition we are aiming to further improve the conditions, processes and expertise we have in place to be set up for success. This means we need to go much further and faster and strengthen the delivery of digital data and technology in government. 

To support these ambitions we have established a new to build on existing strengths and is based on six principles;

  • Build trust by stabilising services and getting the basics right;
  • Be the gateway for all digital, data and technology services delivered by the Cabinet Office to its civil servants and ministerial bodies;
  • Provide impeccable service to our users;
  • Drive digital, data and technology thought leadership;
  • Transform ways of working;
  • Build sustainable capabilities.

Job description

The Principal Network and Security Specialist will have the responsibility to design networking and Cyber Security services, create documentation, change management and root cause analysis as well as acting as an escalation point for the Live Service as well as line management of the Lead Network engineers responsible for day to day network operations.

The role is part of Cabinet Office Digital Enterprise Services, (Technical Operations (TechOps)) which provides, maintains and supports the infrastructure, telephony, network, WiFi, end-user devices, cloud capability and software across the entire Cabinet Office estate.

Our user base includes the Government Digital Service (GDS), Crown Commercial Services (CCS), Estates and Government Property Agency (GPA). 

The role will work closely with the Technical Architects and will be designing and maintaining existing network infrastructure, carrying out upgrades and problem resolutions. 

The Principal Network and Security Specialist will have the responsibility to design networking and Cyber Security services, create documentation, change management and root cause analysis as well as acting as an escalation point for the Live Service as well as line management of the Lead Network engineers responsible for day to day network operations.

Main responsibilities

  • Provide leadership to Network Operations and line management to the Lead Network Engineers;
  • Change requests for network changes;
  • Delivery and Resource Plans;
  • Documentation of processes for security processes such as incident processes, vulnerability management, compliance;
  • Maintain GovAssured documentation and artifacts set, including development of processes to ensure compliance;
  • Work with the Principal Infrastructure Engineer, Principal Technical Architect and Lead Infrastructure Engineers on the day-to-day management of the Cabinet Office wireless, LAN, WAN, including the network devices and security devices that are deployed; 
  • Discover shortfalls in protective monitoring and ensure missing data is shipped to the Splunk SIEM systems. Working closely with the Cyber Transformation Team (CTP) to onboard new log sources across the department into the Cyber Security SIEM Platform as required;
  • Work with the Operation teams on security and performance monitoring devices (both virtual and physical) across the IT platforms managed by Cabinet Office Digital; 
  • Oversee the network operations team, including; technical management, people management, including line management of the Lead Network engineer leading the team;
  • Design and implementation of new services as and when required by the Cabinet Office; 
  • Provide guidance to second/third line support and problem solving for the Cabinet Office internal network;
  • Lead on the strategy for the Cabinet Office Network Operations team on the physical and technical implementation of network and security services using key skills to enhance networking and security elements that will be deployed at Cabinet Office; 
  • Develop process and procedures for other engineers to ensure a secure and robust environment for cabinet office users with KPIs in place for security processes and patching and maintain this level;
  • Work with cloud technologies on the migration of existing systems and implementing new solutions;
  • Be prepared to work out of normal office hours to implement change, when necessary, including weekend and evening work, including being on call;
  • Serve as the incident lead for TechOps, managing and overseeing security-related incidents, while coordinating with the Cyber Security team to ensure timely response and resolution. Responsible for developing and escalating security incident reports to the Cyber Security team;
  • Interface with third-party security tools and vendors, such as NCSC, and other government departments, to ensure effective integration and utilisation of external security solutions that complement internal security infrastructure and practices;
  • Collaborate with the Cyber Security Team (SOC Team, and CTP), Operations leads, and Technical Architects to conduct general threat modelling and threat hunting, dedicating time for security improvements and discovery of threats on the platform;
  • Professionally represent the Operations team as a technical (Cyber Security) consultant on projects with an eye to ensure security and protective monitoring.

Mentoring of junior engineers will be expected. 

Person specification

The Government Digital and Data Capability skills required are as set out in the definition for a Principal Network and Security Specialist as set out here.

Essential Skills

It’s essential that you have:

  • Proven expert knowledge and experience in WAN networking;
  • Proven expert knowledge of networking concepts and technologies and proven experience of network implementation and operation;
  • Demonstrable experience in the delivery of secure enterprise networking and the secure configuration of LANs, WLANs and WANs;
  • Experience of change and incident management processes;
  • Professional skills including excellent customer relationship and stakeholder management skills, with the ability to engage with senior management, technical architects and solution providers;
  • Strong understanding of encryption protocols and cipher suites.

Desirable Skills

  • Experience of working in an agile environment;
  • Use of Cloud-based systems and platforms;
  • Substantial configuration and maintenance experience with Palo Alto and Fortigate;
  • Experience with performance monitoring applications such as Zabbix, Nagios or SolarWinds; 
  • Experience using Sophos Cloud and working with Managed Threat Response;
  • Experience using NCSC HBC (Host Based Capability).

Additional information:

A minimum 60% of your working time should be spent at your principal workplace. Although requirements to attend other locations for official business will also count towards this level of attendance.

You must have flexibility to work weekends and evenings as required.

Successful candidates will need to go through SC clearance as a minimum and desirable that the candidate should be willing to go through DV clearance.

Behaviours

We'll assess you against these behaviours during the selection process:

  • Changing and Improving
  • Seeing the Big Picture
  • Making Effective Decisions
  • Managing a Quality Service
  • Delivering at Pace

Technical skills

We'll assess you against these technical skills during the selection process:

  • Strong Understanding of Cyber Security principles especially with respect to operational security. Experience with Incident Response and Threat and vulnerability management processes.
  • Subject matter expertise in security tools implementation and projects, and providing Cyber Security Guidance to Operational Technology teams.
  • Experience of management and administration of SIEM system, and the creation and management of dashboards and reporting.
  • Proven expert knowledge and experience in LAN and Wireless LAN networking design, preferably with equipment from a range of different product vendors.
  • Proven experience in leading teams and providing both technical and line management.
  • Proven problem solving and analytical skills in a fast paced, multidisciplinary digital/technology environment.
  • Experience installing and supporting Cyber Security products and tools such as endpoint detection and response (EDR) and vulnerability scanning.
  • Proven strong understanding of network equipment especially with Fortinet.

More jobs at Government Digital & Data

Lead Business Analyst-Department for Transport
£51,997
Full-time (Permanent)
Technical Architect Vehicle Certification Agency-SEO
£57,400
Full-time (Permanent)
Software Engineer - ONS - HEO
£32,452
Full-time (Permanent)
IT Support Engineer - Met Office - EO
£26,954 - £29,531
Full-time (Permanent)
DDaT Senior BI Design & Integration Manager - MoD - SEO
£43,080
Full-time (Permanent)
Lead Applied AI Engineer (i.AI) - CO - G6
£67,126 - £103,924
Full-time (Permanent)
DDAT Lead Technical Architect - MoD - G7
£57,670 - This post is eligible for a Digital Skills Allowance of up to £15,300 per annum
Full-time (Permanent)
Interaction Design Industrial Placement 2025 - Met Office - AO
£25,606
Full-time (Permanent)
Lead DevOps Engineer - DWP - G6
£72,664 - £89,995
Full-time (Permanent)
Software Development Engineer In Test (Automation Test Engineer
Full-time (Permanent)
Senior Technical Architect - MHPRA - G7
£58,983
Full-time (Permanent)
Lead Data Architect Data Services and Analytics (DSA) - HO - G7
£60,300 - £70,730 You may be eligible for an additional non-pensionable allowance with a value of up to £20,100 (location dependent).
Full-time (Permanent)
Technical Architect Data Services and Analytics (DSA) - HO - SEO
£44,720 - £52,130 You may be eligible for an additional non-pensionable allowance, pending a Capability and Skills assessment, with a value of up to £12,680.
Full-time (Permanent)
Senior Performance Test Engineer - DVLA - SEO
£42,848 plus an additional allowance up to £14,552
Full-time (Permanent)
Software Developer in Test - HM Courts and Tribunals Service - SEO
£41,463 - £52,040 location dependant. Offers above will be an additional GDD allowance based on experience.
Full-time (Permanent)
Lead Interaction Designer - DESNZ - G7
National: £55,105 - £62,475; London: £60,620 - £67,565 (pro-rata for part-time hours)
Full-time (Permanent)
Interaction Designer - HM Courts and Tribunals Service - SEO
National £41,463 - £45,276 London £47,657 - £52,040. Your salary will be dependent on your base location
Full-time (Permanent)
Senior Software Developer (LITE) - DBT - G7
London: £63,248 to £79,133 / National: £59,634 - £75,618 (including allowance)
Full-time (Permanent)
Software Developer - HSE - HEO
£36,235 - £39,611
Full-time (Permanent)
Software Engineer (Navy Aviation) - MoD - EO
£29,580 This post presently attracts a Market Skills Allowance of £3000 per annum
Full-time (Permanent)
Senior Technical Architect (Software & Solutions) - HM Land Registry
£54,388 - £68,900
Full-time (Permanent)
Associate Data Scientist - ONS - HEO
£34,075 - £38,718
Full-time (Permanent)
Specialist Network Lead Infrastructure Engineer - DfE - G7
National: £56,353 London: £60,373 This post is eligible for a Digital, Data and Technology (DDT) capability based pay (CBP) allowance.
Full-time (Permanent)
Lead Infrastructure Engineer - DfE - G7
£56,353. This post is eligible for a Digital, Data and Technology (DDT) capability based pay (CBP) allowance.
Full-time (Permanent)
Lead Infrastructure Engineer - DfE - G7
National: £56,353 London: £60,373. This post is eligible for a Digital, Data and Technology (DDT) capability based pay (CBP) allowance.
Full-time (Permanent)
Senior Infrastructure Engineer - DfE - SEO
National: £41,458 London: £45,492 This post is eligible for a Digital, Data and Technology (DDT) capability based pay (CBP) allowance.
Full-time (Permanent)
Specialist Network Senior Infrastructure Engineer - DfE - SEO
National: £41,458 London: £45,492 This post is eligible for a Digital, Data and Technology (DDT) capability based pay (CBP) allowance.
Full-time (Permanent)
Head of Cyber Security - DfE - G6
National: £8,623 - £75,778 London: £72,182 - £80,260 and an additional £6,000 market supplement allowance may be available
Full-time (Permanent)
Enterprise Architect Cloud Solutions - MHCLG - G6
£77,257 - £83,230 (London), £70,644 - £76,608 (National) An additional digital allowance may be payable depending on the level of assessed capability up to £11,335
Full-time (Permanent)
DDaT Architecture & Engineering Principal - MoD - G6
£70,540
Full-time (Permanent)
AIX Group Head RCO - MoD - G6
£70,540 plus digital allowance may attract up to £18,000 based on results of your additional skills assessment.
Full-time (Permanent)
Lead Test Engineer - HMRC - G7
£56,344 - £62,590
Full-time (Permanent)
Lead Interaction Designer - DBT - G7
London: £59,450 to £66,338 / National: £55,836 - £62,823 (including allowance)
Full-time (Permanent)
Senior Software Engineer - DVLA - SEO
£42,848 Plus an additional allowance up to £14,552
Full-time (Permanent)
Java Developer - HO - SEO
London: £48,720 - £52,130 National: £44,720 - £47,850 You may be eligible for an additional non-pensionable allowance with a value of up to £12,680.
Full-time (Permanent)
Microsoft 365 and SharePoint Developer - HO - SEO
National: £44,720 - £47,850. London: £48,720 - £52,130 You may be eligible for an additional non-pensionable allowance with a value of up to £12,680
Full-time (Permanent)
DDAT Technical Architect - MoD - SEO
£44,590 This post may be eligible for a Digital Skills Allowance of up to £11,400 per annum.
Full-time (Permanent)
Lead Technical Architect - DWP - G6
£72,664 - £89,995
Full-time (Permanent)
Technical Architect - HMRC - SEO
£44,110 - £47,664
Full-time (Permanent)
Defence Business Services (DBS) Solution Architect - MoD - HEO
£36,530
Full-time (Permanent)
Lead Technical Architect - HMRC - G6
National (£68,966-£76,979) London (£75,950-£84,854)
Full-time (Permanent)
Technical Architect - HSE - G7
£60,760 - £65,776
Full-time (Permanent)
Senior Cloud DevOps Engineer - The National Archives - SEO
£53,000 plus up to £7,000 Market supplement
Full-time (Permanent)
Lead WebOps Engineer (WebOps/DevOps) - Companies House - SEO
Base salary is £41,571 with an additional DDaT allowance of £4,350 - £11,000 available.
Full-time (Permanent)
Senior Site Reliability Engineer - MoJ - G7
The national salary range is £56,532 - £64,048, London salary range is £61,201 - £69,338.
Full-time (Permanent)
Service Catalogue Manager - HM Courts and Tribunals Service - SEO
The national salary range is £41,463 - £45,276, London salary range is £47,657 - £52,040.
Full-time (Permanent)
Lead Data Architect - Planning Inspectorate - G7
£59,644 - £66,120 Eligible for DDaT Allowance - See Advert
Full-time (Permanent)
Head of Platform - Ofsted - G6
£82,324 per annum. Rising to £83,148 per annum on successful completion of probation
Full-time (Permanent)
Deputy Director: Head of Data and AI - DEFRA - SCS1
£76,000 - £100,000
Full-time (Permanent)
Business Analysts - Planning Inspectorate - HEO & SEO
Salary £36,396 - £49,462 For details on salary ranges for each grade please see section in our advert titled: Role types and Salary details
Full-time (Permanent)
Senior Data Scientist - Planning Inspectorate - SEO
£45,219 - £49,462 plus DDaT Allowance up to £12,181
Full-time (Permanent)

Subscribe to our newsletter

Sign up here