> Markdown version of [/jobs/ext/3082406-security-incident-management-analyst](https://www.wearedevelopers.com/jobs/ext/3082406-security-incident-management-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Incident Management Analyst - **Company:** Hays plc - **Location:** Manchester, UK - **Contract:** Temporary to permanent - **Skills:** Cyber Security, Issue Tracking Systems - **Published:** September 26, 2026 - **Apply:** https://www.jobs.service.gov.uk/jobs/6ab3eff41da77e3407da46a7/apply ## About the Role * Experience in cyber security, service management, operational governance, or support roles * Understanding of security incident management processes * Awareness of: * Incident severity classifications * Escalation processes * Major incident management principles * Strong organisational and reporting skills * Ability to coordinate multiple stakeholders Desirable * Exposure to SIAM or multi-supplier environments * Familiarity with incident management tooling and reporting outputs * Understanding of ITIL Incident Management concepts * Experience in regulated, government, or defence environments Key Deliverables * Incident reporting packs * Supplier incident performance metrics * Incident status tracking and governance records * Audit-ready incident evidence * Inputs to governance and operational review forums ## Description The Security Incident Management Analyst operates within the Operational Integrator (OI) function in a multi-supplier (SIAM) environment, supporting the governance and coordination of security incident management activities across suppliers. The role assists in ensuring security incidents are identified, tracked, escalated, and reported in accordance with client policies and agreed service levels. Working closely with suppliers, service management teams, and security stakeholders, the consultant supports incident visibility, reporting, governance activities, and audit readiness. This is a governance and coordination role and does not perform Security Operations Centre (SOC) monitoring, threat hunting, incident response, or technical remediation activities. If you are successfully offered this position, you will go through a series of pre-employment checks, including identity, nationality (single or dual) or immigration status, employment history going back 3 continuous years, and unspent criminal record check (known as Disclosure and Barring Service) Key Responsibilities: Incident Tracking & Coordination * Support the monitoring of security incidents throughout their lifecycle * Ensure incident records are maintained and updated by suppliers * Track incident progress from identification through to closure * Escalate overdue, recurring, or high-impact incidents through agreed governance channels Supplier Engagement (SIAM Model) * Coordinate with suppliers to obtain incident updates and status reports * Support the collection and validation of supplier incident reporting * Ensure incident data standards and reporting requirements are applied consistently * Identify gaps in ownership, reporting, or evidence Incident Reporting & Visibility * Produce routine security incident reports and dashboards * Assist in monitoring: * Incident volumes * Resolution performance * SLA compliance * Escalation trends * Support governance forums through accurate reporting and status updates Governance & Process Compliance * Support adherence to agreed incident management processes * Ensure supplier activities align with client security policies and standards * Assist with documenting lessons learned and improvement actions * Support maintenance of incident governance documentation Assurance & Evidence Support * Collect and organise incident management evidence * Support assurance and audit activities * Ensure incident records remain complete, traceable, and audit-ready * Assist in demonstrating process compliance and effectiveness ## Related Videos - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Recruiting in 2025: Will AI Help or Take Over?](https://www.wearedevelopers.com/videos/1301-recruiting-in-2025-will-ai-help-or-take-over) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [7 tips for releasing on a Friday afternoon: YouTrack to the rescue](https://www.wearedevelopers.com/videos/204-7-tips-for-releasing-on-a-friday-afternoon-youtrack-to-the-rescue) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [The Geometry of Incidents: Connecting User Impact to Architecture](https://www.wearedevelopers.com/magazine/764-the-geometry-of-incidents-connecting-user-impact-to-architecture) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Data Engineer Salary UK](https://www.wearedevelopers.com/magazine/253-data-engineer-salary-uk)