IT Security Analyst
Role details
Job location
Tech stack
Job description
You will play a key role in identifying vulnerabilities, simulating real-world attacks, supporting incident response, and strengthening client security postures across complex and varied environments., * Conduct penetration testing across web applications, networks, cloud platforms, and infrastructure
- Perform vulnerability assessments and validate findings identified by Security and scanning tools
- Assist Security Operations team with threat analysis, triage, and escalation
- Contribute to incident response activities, including investigation, containment, and remediation support
- Produce high-quality technical reports with clear, actionable recommendations
- Engage directly with clients to explain risks, findings, and remediation strategies
- Support continuous improvement of security services, tooling, and methodologies
- Stay current with emerging threats, vulnerabilities, and attack techniques
Requirements
We are seeking a skilled, CREST-certified security professional with minimum 3 years' experience to join our growing team. This is a multi-disciplinary role within a security focused environment, combining offensive security, defensive operations, and client-facing consultancy., * Minimum 5 years UK residency
- Current CREST certification (CRT, CCT, or equivalent)
- Proven experience in penetration testing, ethical hacking, or security consultancy
- Strong understanding of network protocols, operating systems, and web technologies
- Hands-on experience with industry-standard tools (e.g. Nmap, Nessus)
- Knowledge of common attack frameworks and methodologies (e.g. OWASP)
- Familiarity with SIEM/EDR platforms and security monitoring principles
- Strong report writing and communication skills, with the ability to engage technical and non-technical audiences
- Degree computer science or equivalent
Desirable Skills
- Experience working within an MSSP, SOC, or consultancy environment
- Exposure to NCSC baseline certification
- Expose to ISMS such as ISO27001framework
- Exposure to 24/7 shift-based security operations
- Threat hunting and incident response experience
- Cloud security expertise (AWS, Azure)
- Scripting or automation skills (Python, PowerShell, Bash)
- Additional certifications (e.g. OSCP, CISSP)
Benefits & conditions
Salary : Subject to experience
Job Type: Full-time / Permanent / Shift-based (where applicable)
What We Offer
- Competitive salary and benefits package
- Shift allowances and on-call incentives (where applicable)
- Flexible and hybrid working options
- Ongoing career development
- Opportunity to work across offensive, defensive, and advisory security domains