Ministry of Housing, Communities and Local Government
Cyber Security Engineer (SOC)

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Bristol, Darlington, London, Manchester, Wolverhampton
Job Summary
We are MHCLG
Here at the Ministry of Housing, Communities & Local Government (MHCLG), we work on things that make a real difference to people’s lives. Whether it's through the homes we live in, the work of our local councils, or the communities we’re all part of, our work is at the top of the political agenda. We have ambitious and far-reaching outcomes to achieve this year and, if you’re thinking of joining us, there’s never been a more exciting time.
Join the frontline of cyber defence and help protect the systems, services and data that support communities across the UK. As a SOC Engineer, you'll play a key role in enhancing the department's security monitoring and detection capabilities across a modern multi-cloud environment spanning Microsoft Azure, Microsoft 365 and AWS. Working within the Cyber Security Operations Centre, you'll design and improve detections, onboard new data sources, develop security automations, support threat hunting activities, and help ensure visibility across critical services and platforms.
You'll work with industry-leading technologies such as Microsoft Sentinel, Defender XDR and cloud-native security tooling to strengthen the department's cyber resilience. While you'll occasionally support the investigation of security incidents and emerging threats, the primary focus of the role is to continuously improve the SOC's ability to detect, monitor and respond to cyber risks through engineering, automation and operational excellence. Whether you're refining detection logic, integrating new services, developing automation workflows, or enhancing monitoring coverage, you'll help shape the future of cyber defence within MHCLG.
Find out more about our Digital teams and what they are working on through our MHCLG Digital blog. Please note that MHCLG do not offer visa sponsorship and applicants will need a valid visa for the duration of your employment.
Job Description
This role is ideal for someone who enjoys solving complex security challenges, building detection capabilities, automating operational processes and continuously improving cyber defence within a modern cloud-first environment.
As a Cyber Security Engineer (SOC), You'll:
- Be responsible for enhancing and maintaining the department's cyber monitoring and detection capabilities across Microsoft Azure, Microsoft 365 and AWS
- Develop, tune and maintain security detections, analytics rules and alerting use cases within Microsoft Sentinel and associated security platforms
- Onboard new data sources and services into the SOC monitoring estate, ensuring effective visibility and coverage across cloud and on-premises environments
- Design and implement automation and orchestration solutions to improve SOC efficiency and reduce manual effort
- Conduct proactive threat hunting activities to identify malicious, suspicious or anomalous activity across the estate
- Continuously improve security monitoring capabilities by identifying gaps, refining detection logic and enhancing security controls
- Support the engineering, configuration and optimisation of SOC tooling, including SIEM, EDR and cloud security technologies
- Produce operational documentation, detection runbooks and technical procedures to support SOC operations
- Analyse emerging threats, vulnerabilities and attack techniques, translating intelligence into effective monitoring and detection capabilities
- Collaborate with infrastructure, cloud, platform and application teams to ensure new services are designed with appropriate security monitoring and logging requirements
- Provide technical expertise and occasional support during security investigations and incident response activities when required
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
This role is ideal for someone who enjoys solving complex security challenges, building detection capabilities, automating operational processes and continuously improving cyber defence within a modern cloud-first environment.
As a Cyber Security Engineer (SOC), You'll:
- Be responsible for enhancing and maintaining the department's cyber monitoring and detection capabilities across Microsoft Azure, Microsoft 365 and AWS
- Develop, tune and maintain security detections, analytics rules and alerting use cases within Microsoft Sentinel and associated security platforms
- Onboard new data sources and services into the SOC monitoring estate, ensuring effective visibility and coverage across cloud and on-premises environments
- Design and implement automation and orchestration solutions to improve SOC efficiency and reduce manual effort
- Conduct proactive threat hunting activities to identify malicious, suspicious or anomalous activity across the estate
- Continuously improve security monitoring capabilities by identifying gaps, refining detection logic and enhancing security controls
- Support the engineering, configuration and optimisation of SOC tooling, including SIEM, EDR and cloud security technologies
- Produce operational documentation, detection runbooks and technical procedures to support SOC operations
- Analyse emerging threats, vulnerabilities and attack techniques, translating intelligence into effective monitoring and detection capabilities
- Collaborate with infrastructure, cloud, platform and application teams to ensure new services are designed with appropriate security monitoring and logging requirements
- Provide technical expertise and occasional support during security investigations and incident response activities when required
Person specification
As a Cyber Security Engineer (SOC), You'll Have:
- 3 Years experience of monitoring, analysing and investigating security events across cloud and enterprise environments
- Experience in creating, tuning and optimising security detections, analytics rules and monitoring use cases
- Demonstrable experience of onboarding new data sources and services to improve SOC visibility and threat detection coverage
- Experience of developing automation and process improvements to enhance SOC efficiency and effectiveness
- 3 Years experience supporting SOC operations and assisting with security incident response activities
- Experience mentoring and supporting junior analysts, helping to develop cyber security capability across the team
- Experience contributing to the development of an exemplar Government Security Operations Centre through innovation, continuous improvement and operational excellence
Alongside your salary of £44,004, Ministry of Housing, Communities and Local Government contributes £12,747 towards you being a member of the Civil Service Defined Benefit Pension scheme. Find out what benefits a Civil Service Pension provides (opens in a new window).
At MHCLG we offer many benefits that range from tailored career pathways and flexible working to MyLifestyle Childcare Voucher and Cycle to Work Schemes. For more information, please click here.
Artificial intelligence
Artificial intelligence can be a useful tool to support your application, however, all examples and statements provided must be truthful, factually accurate and taken directly from your own experience. Where plagiarism has been identified (presenting the ideas and experiences of others, or generated by artificial intelligence, as your own) applications may be withdrawn and internal candidates may be subject to disciplinary action. Please see our candidate guidance (opens in a new window) for more information on appropriate and inappropriate use.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Selection process details
Application and Selection
The application process will be split into 2 stages, testing the following Success Profiles:
- Ability
- Behaviours
- Experience
- Technical
Please ensure your CV does not contain any personally identifiable information.
Note: We do not consider direct CV applications. All applications must be submitted via the provided application link.
Stage 1: Sift (CV)
Experience: Your CV should reference how you meet the criteria set out in the job description.
Most of our campaigns utilise multiple assessors and so it is possible that each of your answers would be viewed by different assessors.
In the event that we receive a large number of applications, we may conduct an initial sift using the lead sift question listed in the advert. Candidates who pass the initial sift may be progressed to a full sift, or progressed straight to interview.
Lead sift question (Technical): Describe a time when you responded to a significant cyber security threat or incident across a hybrid cloud environment using technologies such as Microsoft Sentinel, Microsoft Defender, Azure and AWS.
Stage 2: Technical Test
Ability: For the second stage, you will be invited to complete a 30 minute technical test (further details provided upon invitation). Candidates who are successful will be asked to attend an interview.
Stage 3: Interview
Behaviours: "Making Effective Decisions", "Delivering at Pace", "Changing and Improving" Experience: Experience questions will be based around the essential skills and criteria as listed in the job description. Technical: Technical questions will be based around the essential skills and criteria as listed in the job description.
Sift and Interview Dates
Sifting is envisaged to take place the week commencing 24th August 2026.
Interviews are envisaged to take place the week commencing 7th September 2026 and are currently being held remotely via videocall. This could be subject to change.
Group 1 Digital & Data Roles
MHCLG has implemented the Digital and Data capability framework for Group 1 roles. Applicants that are successful and have been offered a position will be required to complete a capability assessment after the interview.
MHCLG will honour completed capability assessments for this role from other Government Departments for existing civil servants on level transfer only. Please provide a copy of your capability assessment to the Hiring Manager when applying. If you have any queries on pay, please contact the Hiring Manager.
Each experience or technical skill is assessed between 1-3, representing working towards, at or above the job level requirements. You are awarded a proficiency level accordingly, and you will be given opportunity to annually re assess your capability and potentially increase your overall remuneration, through payment of allowances, depending on level of assessed capability.
Candidates moving from another government department have the option to retain their current basic pay if this is within our pay band for the relevant grade.
Senior Executive Officer Group 1 Digital and Data salary
The basic pay for this role will be between £47,444 - £53,575 (London), £44,004- £50,086 (National). Candidates will usually be recruited to the median of the payscale. A digital allowance may also be payable depending on the level of assessed capability, in order to meet the MHCLG overall targeted remuneration rate for the specific grade, location and capability rating. For applicants in receipt of existing allowances, we will assess each case individually, but we would seek not
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills
Location