About this role
Job Specification
Cyber Security & Compliance Analyst
Organisation: Shivom Consultancy Ltd.
Department: Technology / Security & Compliance
Job Title: Cyber Security & Compliance Analyst
Employment Type: Permanent
Contracted Hours: 37.5 hours per week
Working Arrangement: Office Based
Reporting To: Head of Business Development
SOC Code: 2135 – Cyber Security Professionals
Role Purpose
The Cyber Security & Compliance Analyst is responsible for supporting, operating and continuously improving Shivom's organisational cyber security and information security capabilities.
The role provides hands on responsibility across cyber security operations, vulnerability management, security patching, security incident management, information security governance, security policies, security awareness, audit and compliance activities.
The role is also responsible for supporting and maintaining Shivom's ISO 27001 Information Security Management System and Cyber Essentials Plus certification, ensuring that appropriate security controls, processes, documentation and evidence are maintained across the organisation.
The Cyber Security & Compliance Analyst will work closely with Technology, Operations, HR, senior management and other relevant stakeholders to identify and manage security risks and ensure that appropriate security practices are embedded throughout the organisation.
Key Responsibilities
Cyber Security Operations
The Cyber Security & Compliance Analyst will
- Carry out and coordinate day to day cyber security activities across the organisation.
- Monitor the security posture of corporate systems, devices and services.
- Identify security weaknesses, risks and control failures and coordinate appropriate remediation.
- Maintain security operational records, registers, evidence and reporting.
- Monitor security actions through to completion and escalate significant or overdue issues.
- Work with technical and operational teams to ensure agreed security controls are implemented and operating effectively.
- Continuously review security operations and recommend improvements to controls, processes and tooling.
Vulnerability Management
- Manage the identification, assessment and remediation of vulnerabilities affecting corporate devices and systems.
- Review vulnerability findings and assess their potential impact on the organisation.
- Prioritise vulnerabilities according to risk and severity.
- Coordinate remediation activities with relevant technical teams and users.
- Track identified vulnerabilities through to resolution.
- Maintain appropriate vulnerability records and evidence.
- Escalate significant vulnerabilities or overdue remediation activities to management.
- Monitor recurring vulnerability issues and recommend preventative improvements.
Security Patch Management
- Monitor the security patching status of corporate devices and relevant systems.
- Identify devices that are missing security updates or are outside agreed compliance requirements.
- Coordinate the deployment and remediation of outstanding security patches.
- Track patch compliance and escalate significant exceptions.
- Maintain evidence demonstrating the operation and effectiveness of the patch management process.
- Identify opportunities to improve and automate patch management and compliance monitoring.
Security Incident Management
- Maintain and operate the organisation's security incident management processes.
- Identify, assess and triage suspected security incidents.
- Coordinate investigation of security incidents and security events.
- Support containment, remediation and recovery activities.
- Escalate material incidents to appropriate management stakeholders.
- Maintain accurate security incident records and supporting evidence.
- Coordinate post incident reviews and lessons learned activities.
- Identify root causes and corrective actions following security incidents.
- Track incident related remediation actions through to completion.
- Recommend changes to controls, policies or processes following security incidents.
Security Governance and Compliance
- Support and maintain Shivom's cyber security and information security governance framework.
- Monitor compliance with organisational security requirements.
- Maintain security related records, registers, documentation and evidence.
- Identify security and compliance gaps and coordinate corrective actions.
- Support management with security reporting and compliance information.
- Ensure security activities are appropriately documented and traceable.
- Support continuous improvement of Shivom's security governance arrangements.
ISO 27001 and Information Security Management System
- Support the operation, maintenance and continuous improvement of Shivom's ISO 27001 Information Security Management System.
- Maintain relevant ISMS policies, procedures, registers, records and supporting evidence.
- Support security risk assessments and risk treatment activities.
- Maintain and monitor security control evidence.
- Support the maintenance of the Statement of Applicability where applicable.
- Coordinate actions arising from ISO 27001 control reviews.
- Support the internal security audit programme.
- Prepare for external certification and surveillance audits.
- Coordinate the provision of evidence to auditors.
- Record, manage and track audit findings, observations and corrective actions.
- Support management review and continuous improvement activities relating to the ISMS.
Cyber Essentials Plus
- Coordinate activities required to maintain Shivom's Cyber Essentials and Cyber Essentials Plus certification.
- Monitor compliance with relevant technical security requirements.
- Prepare the organisation for Cyber Essentials Plus assessments.
- Coordinate evidence gathering and technical readiness activities.
- Work with relevant technical teams to identify and remediate gaps.
- Liaise with authorised assessors where required.
- Track findings and remediation activities through to completion.
- Maintain appropriate records relating to certification and ongoing compliance.
Security Audits and Assurance
- Coordinate and support internal and external cyber security and information security audits.
- Prepare documentation and evidence required for security audits and assessments.
- Coordinate responses to auditor queries and evidence requests.
- Record audit findings, observations and improvement opportunities.
- Coordinate corrective and remediation activities.
- Track audit actions through to satisfactory completion.
- Support customer and third party security assurance activities where required.
- Assist with security questionnaires and information security assurance requests.
- Maintain an appropriate audit trail demonstrating the operation of security controls.
Security Policies, Standards and Processes
- Develop, document, review and maintain information security policies and procedures.
- Translate security and compliance requirements into practical operational processes.
- Maintain detailed security processes covering areas such as vulnerability management, patching, incident management, security audits and compliance.
- Ensure processes clearly define activities, responsibilities, escalation routes and evidence requirements.
- Review policies and procedures periodically to ensure they remain appropriate and effective.
- Communicate changes to security policies and processes to relevant employees.
- Monitor compliance with security policies and identify areas requiring improvement.
- Support the development of new security controls and processes as organisational requirements evolve.
Security Operations Automation
- Identify opportunities to automate repetitive security and compliance activities.
- Design and implement automation to improve the efficiency and consistency of security operations.
- Develop automated workflows for security monitoring, reporting, alerts and notifications where appropriate.
About cyber security & digital forensics roles for ex-police
Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.
See all cyber security & digital forensics jobs in London →Why this fits a police background — match score 65/100
- Evidence & case files
- Incident command & response
- Investigative casework
- Surveillance & covert work
- Risk & threat assessment
What cyber security & digital forensics roles pay ex-police
Advertised UK ranges, editorial estimates reviewed July 2026
| Digital forensics analyst | £32,000–£45,000 |
| DFIR consultant | £45,000–£65,000 |
| Senior forensics / IR specialist | £60,000–£80,000 |
| Threat-intelligence specialist | £55,000–£80,000 |