BUSINESS ANALYST - OUTSIDE IR35
Role Overview
We are looking for an experienced Technical Cyber Business Analyst to support the development of a mature Cyber Exposure Management / Threat & Vulnerability Management (TVM) capability.
The successful candidate will work closely with technical Cyber SMEs, Security Operations, Product Groups, Cyber Assurance and Architecture teams, translating technical workshops and security requirements into clear capabilities, operating models, processes, RACIs, requirements and measurable outcomes.
This is not a hands-on engineering position; however, the role requires a strong technical understanding of modern cyber security environments and the ability to engage credibly with technical SMEs without relying on them to perform the core Business Analysis.
The programme covers seven key Cyber Exposure domains:
- Platforms
- Operating Systems
- Code
- Repositories
- Software Bill of Materials (SBOM)
- Identity & Entitlements
- Suppliers / Third Parties
Key Responsibilities
- Lead structured workshops with Cyber Security and Technology SMEs to understand current capabilities, processes, controls and technical requirements.
- Translate technical discussions into clearly defined business and technical requirements, capabilities, operating models and measurable outcomes.
- Map current-state and future-state processes across Cyber Exposure and Vulnerability Management.
- Define RACIs, ownership models, hand-offs, escalation paths and cross-functional responsibilities between Security Operations, Product Groups, Cyber Assurance and other technology teams.
- Identify capability gaps, dependencies, integration requirements and areas for process improvement.
- Support the design and maturity assessment of Cyber Exposure capabilities across the seven core domains.
- Develop processes around areas such as:
- Vulnerability remediation
- False-positive management
- Exposure validation
- Security testing
- Secret scanning
- Security findings and remediation
- Support the development of capability roadmaps and priorities towards an effective enterprise-wide Exposure Management model.
- Ensure requirements and processes can be translated into tangible, measurable security outcomes.
Key Experience
- Strong experience as a Cyber Security / Technical Business Analyst, ideally within Cyber Exposure, Security Assurance or Vulnerability Management programmes.
- Proven ability to translate complex security capabilities into requirements, processes, operating models and RACIs.
- Knowledge across areas such as:
- Threat & Vulnerability Management (TVM)
- Attack Surface Management
- Exposure Management
- Endpoint Security
- Cloud Security
- Security Configuration / Hardening
- Good technical understanding of SSDLC, DevSecOps and modern security tooling.
- Experience working across Security Operations, Engineering, Product, Architecture and Cyber Assurance functions.
- Strong requirements engineering and process engineering experience.
- Ability to independently plan and facilitate technical stakeholder workshops.
- Experience mapping complex dependencies and processes across multiple technology and security teams.
- Understanding of how SOC/Security Operations and Product/Engineering teams interact when identifying, prioritising and remediating security exposures.
- Strong capability and outcome-driven approach, with experience assessing maturity, gaps, priorities and integration requirements.
Highly Desirable
- Knowledge or practical experience of Continuous Threat Exposure Management (CTEM).
- Experience supporting enterprise-wide Cyber Exposure or Vulnerability Management transformation programmes.
- Understanding of SBOM, software supply-chain security, code/repository security, identity exposure and third-party/supplier security.
Ideal Profile
This role would suit a technically credible Cyber Business Analyst who can sit between deep technical Cyber SMEs and business/process stakeholders.
You will not be expected to be the deepest technical specialist in every security domain, but you must understand the technology sufficiently to challenge SMEs, structure technical discussions and convert those discussions into an actionable Cyber Exposure operating model, requirements and roadmap.