Cyber Security Advisor (SIEM Engineering)
At a glance
- Band
- Band 7
- Contract
- Permanent
- Pattern
- Full-time, Part-time, Job share, Flexible working
- Posted
- 10/09/2026
- Closes
- 24/09/2026
Sponsorship verdict
This contract type is not eligible for Skilled Worker sponsorship.
NHS Trusts cannot issue a Certificate of Sponsorship for part-time, bank, locum, zero-hours, job-share or short fixed-term (under 12 months) contracts under current Home Office rules. This applies even when the wider Trust holds a Skilled Worker licence.
Role summary
This role is for a Cyber Security Advisor specializing in SIEM Engineering within NHS England's Cyber Operations. The successful candidate will be responsible for deploying and maintaining SIEM system capabilities, including data feed management and building cyber detection. They will work closely with Cyber Monitoring teams to enhance security monitoring automation and resolve tooling incidents. The role also involves mentoring junior staff and providing status reporting.
Essential criteria
- Demonstrable knowledge of technologies and technology-based solutions dealing with information security issues; ability to apply these in protecting information security across the organisation.
- Working knowledge of concept, procedures and processes of Security Information and Event Management (SIEM); ability to utilise related applications to protect organisational networks from cyber risks.
- Demonstrable knowledge of the processes, tools and techniques of information security management, ability to deploy and monitor information security systems, as well as detect, resolve and prevent violations of IT security, to protect organisational data.
Desirable criteria
- Working knowledge of modules, processes and technologies of Information Security Operation Centre (ISOC); ability to detect, response and utilise related platform and applications to perform cyber security initiatives.
- Demonstrable knowledge of and ability to investigate, troubleshoot, resolve and prevent the recurrence of incidents that interfere with the normal delivery of IT services.
- Post-graduate level degree in Cyber Security or relevant subject, or equivalent level of experience.
- Demonstrable knowledge of technologies and technology-based solutions dealing with information security issues; ability to apply these in protecting information security across the organisation.
- Working knowledge of concept, procedures and processes of Security Information and Event Management (SIEM); ability to utilise related applications to protect organisational networks from cyber risks.
- Demonstrable knowledge of the processes, tools and techniques of information security management, ability to deploy and monitor information security systems, as well as detect, resolve and prevent violations of IT security, to protect organisational data.
- Working knowledge of modules, processes and technologies of Information Security Operation Centre (ISOC); ability to detect, response and utilise related platform and applications to perform cyber security initiatives.
- Demonstrable knowledge of and ability to investigate, troubleshoot, resolve and prevent the recurrence of incidents that interfere with the normal delivery of IT services.
- Post-graduate level degree in Cyber Security or relevant subject, or equivalent level of experience.
Useful to know
Agenda for Change 2024/25 pays Band 7 at £46,148 – £52,809 a year, across England.
This advert: £59,264 – £67,818 — outside the standard scale; check for HCAS/London weighting.
Posted 1d ago · Closes in 14d
Plenty of time to prepare a strong application.
Full advert · preview
NHS England
Cyber Security Advisor (SIEM Engineering)
The closing date is 24 September 2026
Job summary
Cyber Operations purpose is to support safe care and build public trust by building NHS England's cyber resilience and enabling the wider health system to be cyber resilient, supporting Transformation Directorate's purpose of delivering the best care and outcomes for the NHS.
The Cyber Operations sub-directorate consists of four operational areas:
- Cyber Security Operations Unit (CSOU & SIO)
- Cyber Delivery Unit (CDU)
- Cyber Improvement Programme
- Chief Information Security Office Function (CISO)
This role is in the Cyber Security Operations Centre (CSOC) which is part of CSOU and provides centralised security monitoring across both NHS England and the wider health and care system in England. The CSOC teams work closely together to improve NHS cyber resilience and enable a "Defend as one" strategy across the health and care system.
The Security Advisor SIEM Engineering provides new and enhanced SIEM (Security Information and Event Management) system and tooling capability for the CSOC, including deploying feeds from data sources, building cyber detection capability, improving the automation of security monitoring and managing the SIEM environment.
Main duties of the job
The Security Advisor SIEM Engineering is responsible for:
- Deploying feeds
Join the community to read the full pack, responsibilities and person-specification in one place.
Your seat is reserved — activate it
CareerHive is included with your CareerHive Skool community membership. If you haven't claimed your account yet, join the community (or sign in with the same email you joined with) to unlock the full advert, the apply link, HiveMind AI interview & application suite, your private vault, and daily sponsorship alerts.