KEYSTONE CYBER

Home Disciplines Security analysts

ANALYSIS & ASSURANCE

Security analyst recruitment

Security analyst is the broadest title in cyber and the most loosely used. We start by working out what the role actually needs to do, because the title alone will not tell either of us.

What the title usually means

Across the briefs we take, security analyst covers at least four different jobs: vulnerability management and remediation chasing, identity and access reviews, risk assessment and control testing, and generalist first-line security in a small team. Some employers also use it for what is plainly a SOC analyst role.

We ask what the person will own in their first quarter. That question resolves the ambiguity faster than any job description, and it stops us shortlisting a risk analyst for a job that turns out to be scanner triage.

What we place

Vulnerability managementScanning, prioritisation against business context, and the harder half — driving remediation through other teams.
Identity & accessAccess reviews, joiner-mover-leaver process, privilege creep, IAM tooling.
Risk & control testingControl assessment, gap analysis and evidence gathering — often adjacent to GRC.
Generalist first-lineThe broad analyst who covers everything in a team of one or two, usually a first security hire.
Threat intelligenceCollection, analysis and reporting — most common in banking and large enterprise.
Security awarenessPhishing simulation, training programmes, behaviour change. Frequently underrated.

How we screen

The differentiator at analyst level is rarely technical depth — it is judgement and the ability to get other people to act. A vulnerability analyst who can produce a 400-page scan report is common. One who can walk into an infrastructure team meeting and leave with agreed remediation dates is not.

So we probe for evidence of things moving: a control that got implemented, a backlog that came down, an access review that stuck. Candidates who can only describe what they found, never what changed, get flagged as such in our notes to you.

Career direction, and why it matters to you

Security analysts move on. Two to three years is typical before they specialise into engineering, offensive security or governance. That is not disloyalty, it is how the discipline works, and the employers who retain analysts longest are the ones who mapped a route before hiring. We raise it at briefing because it changes who says yes.

Common questions

How is a security analyst different from a SOC analyst?

A SOC analyst works alerts in a monitoring function. A security analyst is broader — vulnerability management, access reviews, risk assessment, control testing, sometimes all four. If you want someone watching a SIEM, see our SOC analyst page instead.

We are hiring our first security person. What should the role be?

Almost always a broad security analyst rather than a specialist. A first hire needs to triage risk across the whole estate, and specialists narrow too early. We will push back on a brief that over-specialises a first hire.

Do you place vulnerability management specialists?

Yes, and it is one of the more common briefs we take. The scarce part is not running the scanner, it is the person who can prioritise findings against business context and get remediation actually done by other teams.

Can security analysts move into other cyber disciplines?

Frequently, and it is worth planning for. Analysts move into engineering, GRC or offensive security within two to three years. Hiring one without a route onward tends to mean rehiring.

Related disciplines

Talk to us about your search

A short conversation is usually enough to tell you whether we can help.