How to apply:
Our selection process ensures a comprehensive assessment of each applicant's qualifications, skills, and potential fit within our organisation.
The selection process for this role will be:
Stage 1: Sift of CV and Personal Statement
Stage 2: 1st Stage Interview
Stage 3: 2nd Stage Interview
You must be successful at each stage to progress to the next stage.
Stage 1: Sift
At sift, you will be assessed against the following Success Profile elements:
Behaviours you will be asked to provide a 250-word statement on the following Behaviours:
- Communicating and Influencing: Please provide an example of a time when you communicated complex information to a range of stakeholders both internal and external and adapted your approach to achieve a positive outcome.
Technical - you will be asked to provide a 250-word statement on the following Technical skill:
-
Intrusion Detection & Analysis Skill Level Practitioner: Please provide an example of a time where you identified a significant cyber security threat or suspicious activity, what prompted the investigation, what actions did you take, and what was the outcome?
Experience you will be asked to provide a CV (unlimited wordcount) and personal statement (750 words).
Please structure your Personal Statement to provide detailed evidence of each of the following:
-
Experience of Incident Management, investigation and response within a cyber role
-
Demonstratable experience working with a SIEM tool (Microsoft Sentinel, Splunk, etc), and vulnerability scanners.
-
Proven experience of managing stakeholders in a complex environment with multiple service providers.
-
Experience in interpreting threat intelligence and building alert rules considering current threat information.
Further details around what this will entail are listed on the application form.
Should a large number of applications be received, an initial sift may be conducted using the lead Success Profile element: Technical (Intrusion Detection & Analysis- Skill Level Practitioner). Candidates who pass the initial sift may be progressed to a full sift or progressed straight to assessment/interview.
The sift will take place week commencing 11/09/2026
Stage 2: 1st Stage Interview
At interview stage, you will be assessed against the following Success Profile elements:
Behaviours
-
Delivering at Pace
-
Communicating and Influencing
Technical
- Intrusion Detection & Analysis Skill Level Practitioner
-
Threat Intelligence & Threat Assessment Skill Level Practitioner
-
Secure Operations Management Skill Level Working
-
Information Risk Assessment & Risk Management Skill Level Awareness
The interviews will take place week commencing 28/09/2026
This interview will be conducted online via Microsoft Teams. Further details will be provided to you should you be selected for interview.
Stage 3: 2nd Stage Interview
At interview stage, you will be assessed against the following Success Profile elements:
Experience
- Experience of Incident Management, investigation and response within a cyber role
-
Experience of making risk-based, defensible decisions at pace.
Technical
- Threat Understanding Skill Level - Practitioner
-
Cyber Security operations Skill Level Working
The interviews will take place week commencing 12/10/2026 OR 17/10/2026 Depending on your location.
This interview will be conducted in person.
We will be offering face-to-face interview slots at each of our locations: Bristol, Swansea, Leeds, Nottingham, Newcastle, Oldham (Chadderton), Birmingham (Garretts Green) or Uxbridge.
Further details will be provided to you should you be selected for interview.
You can find out more about our hiring process, how to apply, and application and interview guidance on our careers site .
Please note that we will try to meet the dates set out in the advert. There may be occasions when these dates will change.
Further information on the selection process
We will also hold a 12 reserve list for this role, which may lead to potential opportunities beyond the role you applied for.
Should we receive a large number of applications, we may invite a shortlist of the highest performing candidates to interview. This means that some applications that meet the required standard could be placed on hold after the sift and invited to interview if the vacant position(s) remain unfilled. You will be notified if your application is being put on hold once the sift has been completed.
Appointments for this position will be made in order of merit. If you are successful in the selection process but there are no further available posts for the advertised role, you may be contacted to discuss an offer for a lower graded role (with similar experience and responsibility requirements).
If you are unsuccessful in the selection process, your application may be considered for a lower graded position if your demonstrated skills and experience meet the requirements of the alternative position. Candidates will be considered in order of merit.
Reasonable Adjustments
As a Disability Confident Leader employer, we are committed to ensuring that the recruitment process is fair, accessible and allows all candidates to perform at their best. If a person with a visible or non-visible disability is substantially disadvantaged, we have a duty to make reasonable changes to our processes.
Complete the Assistance required section in the Additional requirements page of your application form to tell us what changes or help you might need during the recruitment process. For instance, you may need wheelchair access at an interview, or if youre deaf, a Language Service Professional.
If you need a reasonable adjustment so that you can complete your application, you should contact Government Recruitment Service via [email protected] as soon as possible before the closing date to discuss your needs.
Document Accessibility
This job advert contains links to the DfT Careers website. Our website provides useful guidance and information that can support you during the application process. If you are experiencing accessibility problems with any attachments on this advert or the information on our website, please contact the email address in the 'Contact point for applicants' section.
Further Information
For more information about how we hire, and for useful tips on submitting your application for this role, visit the How We Hire page of our DfT Careers website. You can find detailed information about the recruitment process and what to expect when applying for a role.
Pre-employment Checking
If your application is successful but you have been dismissed from the Civil Service, your application could be removed at the pre-employment checking stage depending on the nature of the dismissal.
Applicants who are successful at interview will be, as part of pre-employment screening, subject to a check on the Internal Fraud Database (IFD). This check will provide information about employees who have been dismissed for fraud or dishonesty offences. This check also applies to employees who resign or otherwise leave before being dismissed for fraud or dishonesty had their employment continued. Any applicants details held on the IFD will be refused employment. A candidate is not eligible to apply for a role within the Civil Service if the application is made within a 5-year period following a dismissal for carrying out internal fraud against government.
All external applicants and current employees of accredited non-departmental public bodies (NDPBs) will be required to undergo a Social Media Check. A Social Media Check is a review of your publicly available online activity, typically across platforms like LinkedIn, Facebook, X (formerly Twitter), Instagram, and others. The purpose is to identify any public posts or content that could raise concerns for employers, such as:
-
Hate speech or discriminatory behaviour
-
Threats or acts of violence
-
Illegal activity or substance misuse
-
Sexually explicit material
-
Extremist views or affiliations
Importantly, this check does not involve hacking into your accounts or accessing private messages. It only considers content you have chosen to make public. Employers use this kind of screening to help ensure their workplace remains safe, inclusive, and aligned with company values. Its not about judging your personality or lifestyle - its about checking for potential red flags that might affect the role or company culture. If you have questions or concerns about the social media check, we would be happy to explain in more detail whats being looked at and how your data is handled securely and fairly.
For further information on National Security Vetting please visit the Demystifying Vetting website.
Feedback
Feedback will only be provided if you attend an interview or assessment.