> Markdown version of [/jobs/ext/1392476-security-validation-analyst](https://www.wearedevelopers.com/jobs/ext/1392476-security-validation-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Validation Analyst - **Company:** Zellis - **Location:** Almondsbury, UK (Remote available) - **Experience:** Starter - **Contract:** Permanent contract - **Skills:** Adobe InDesign, Artificial Intelligence, Software System Penetration Testing, JIRA, Microsoft Azure, Software as a Service, Cloud Computing, Cloud Computing Security, Code Coverage, CompTIA Security+, Cyber Security, Data-Flow Analysis, Microsoft Security Essentials, Open Web Application Security, Comptia Pentest+ CE, Secure Coding, Security Information and Event Management, Software Vulnerability Management, Alwayson, Microsoft Power Automate, Mitre Att&ck, Zendesk, Servicenow - **Published:** July 23, 2026 - **Apply:** https://uk.indeed.com/viewjob?jk=cccd38d3b6475e3a ## About the Role * Hands-on experience in security validation, vulnerability management or technical security testing. * An understanding of penetration testing, attack simulation or security control validation. * Familiarity with technical security assessments, threat modelling and secure-by-design principles. * Working knowledge of the Microsoft security suite (e.g. Defender, Sentinel, Entra) and common security testing tooling. * Ability to interpret technical findings and convey risk and remediation clearly. * A genuine appetite for applying AI and automation to expand and accelerate security validation. * Excellent analytical, written and verbal communication skills, * A recognised qualification in a relevant discipline, or equivalent training, together with around 1-2 years' hands-on experience in security testing, vulnerability management or a technical security role. * Practical experience with vulnerability management tooling and remediation tracking. * An understanding of common frameworks and methodologies (e.g. MITRE ATT&CK, OWASP, NIST CSF). * Working knowledge of cloud and on-premise environments (Microsoft Azure preferred) and common security tooling (e.g. SIEM, EDR/XDR). * Confident user of AI productivity and security tooling (e.g. Microsoft Copilot, Claude) to accelerate testing and analysis. * Experience with business and ITSM tooling such as ServiceNow, Azure DevOps, Zendesk and Jira would be advantageous., * A relevant certification such as CompTIA Security+, CompTIA PenTest+ or eJPT (held or working towards); progress towards OSCP, CREST (CPSA / CRT) or CEH would be an advantage. * Experience in a regulated, data-rich or SaaS environment - ideally payroll, HR, financial services or similar. * Familiarity with cloud security testing (Azure preferred) and secure development practices. Personal Attributes / Competencies * Technically curious and rigorous, with an attacker's mindset and a defender's discipline. * Evidence-led and objective, able to substantiate findings clearly. * Proactive and accountable, taking ownership of findings through to remediation. * Strong prioritisation skills, able to manage multiple assessments and deadlines. * A clear communicator across technical and business audiences. * Collaborative team player, keen to share knowledge and learn from senior colleagues. * Curious and improvement-minded, keen to apply new tools and automation to work smarter. * Adaptable and comfortable working in a fast-paced, evolving environment. ## Description The Security Validation Analyst helps prove that the Group's security controls work as intended across Zellis Group, which comprises Zellis, Moorepay, Benifex and Hastee. Working as part of the security validation team, the role provides hands-on support for security testing, vulnerability management and technical security assessments - helping to find weaknesses before attackers do and providing evidence-based assurance that the Group is protected against current and emerging threats. Reporting to the Cyber Security Validation Manager, this is a practical, technically focused role spanning penetration testing support, vulnerability management, technical assessments, solution threat modelling and security architecture review. The analyst partners with engineering, architecture and operations teams across all of the Group's brands and business units to ensure security is embedded from the outset, weaknesses are identified and prioritised, and remediation is tracked through to closure. The role takes a strong "AI first" approach, using approved AI tooling (such as Microsoft Copilot and Claude) to expand test coverage, accelerate analysis and reporting, and help shift the Group from periodic, point-in-time testing towards continuous, evidence-led validation of its security posture., Security Validation & Testing * Support the Group's security testing and attestation activity, including penetration testing, attack simulation and breach-and-attack simulation. * Help validate the effectiveness of security controls and detections, providing evidence that they work as intended. * Support the coordination of third-party testing partners, helping to capture clear, actionable findings. Vulnerability Management * Run and triage vulnerability scans across the Group's estate, helping to set risk and priority levels for identified vulnerabilities. * Track remediation through to closure with engineering and operations teams, escalating where timelines or risk thresholds are breached. * Contribute to vulnerability and validation reporting across the Group's business units. Technical Assessments & Threat Modelling * Support technical security assessments of new and existing systems, identifying weaknesses and recommending proportionate controls. * Contribute to solution threat modelling and data-flow analysis to identify threats, vulnerabilities and countermeasures early in design. * Help maintain visibility of the Group's assets and attack surface to inform testing priorities. Security Architecture Review & Advisory * Contribute to security architecture reviews and secure-by-design advice across change and project activity. * Act as a technical security liaison for business units, supporting engineering, architecture and product teams. * Help ensure security is considered and designed into systems and processes through a secure development lifecycle. AI, Automation & Continuous Assurance * Take a strong "AI first" approach, using AI and automation to expand test coverage, analyse results and reduce manual effort. * Use approved AI tooling (such as Microsoft Copilot and Claude) to accelerate assessment, reporting and remediation guidance. * Support the shift from point-in-time testing towards continuous control validation and always-on assurance. Reporting & Collaboration * Provide clear, timely reporting on validation outcomes, risks and trends to the Cyber Security Validation Manager and stakeholders. * Translate technical findings into clear, risk-based actions for both technical and non-technical audiences. * Share knowledge and good practice across the security team and the wider business. ## Related Videos - [The AI Agent Path to Prod: Building for Reliability](https://www.wearedevelopers.com/videos/1523-the-ai-agent-path-to-prod-building-for-reliability) - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) - [It's a (testing) trap! - Common testing pitfalls and how to solve them](https://www.wearedevelopers.com/videos/1193-it-s-a-testing-trap-common-testing-pitfalls-and-how-to-solve-them) - [Integrate your Cognitive Assistant with 3rd-party DBs and software](https://www.wearedevelopers.com/videos/249-integrate-your-cognitive-assistant-with-3rd-party-dbs-and-software) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)