Skip to main content
AfterDuty

Cyber Security & Compliance Analyst

Shivom Consultancy Ltd · London, Greater London

Type
Full-time
Posted
7 days ago

Overview

Your incident management, evidence handling, and risk assessment from policing transfer directly to this role.

About this role

Job Specification

Cyber Security & Compliance Analyst

Organisation: Shivom Consultancy Ltd.

Department: Technology / Security & Compliance

Job Title: Cyber Security & Compliance Analyst

Employment Type: Permanent

Contracted Hours: 37.5 hours per week

Working Arrangement: Office Based

Reporting To: Head of Business Development

SOC Code: 2135 – Cyber Security Professionals

Role Purpose

The Cyber Security & Compliance Analyst is responsible for supporting, operating and continuously improving Shivom's organisational cyber security and information security capabilities.

The role provides hands on responsibility across cyber security operations, vulnerability management, security patching, security incident management, information security governance, security policies, security awareness, audit and compliance activities.

The role is also responsible for supporting and maintaining Shivom's ISO 27001 Information Security Management System and Cyber Essentials Plus certification, ensuring that appropriate security controls, processes, documentation and evidence are maintained across the organisation.

The Cyber Security & Compliance Analyst will work closely with Technology, Operations, HR, senior management and other relevant stakeholders to identify and manage security risks and ensure that appropriate security practices are embedded throughout the organisation.

Key Responsibilities

Cyber Security Operations

The Cyber Security & Compliance Analyst will

  • Carry out and coordinate day to day cyber security activities across the organisation.
  • Monitor the security posture of corporate systems, devices and services.
  • Identify security weaknesses, risks and control failures and coordinate appropriate remediation.
  • Maintain security operational records, registers, evidence and reporting.
  • Monitor security actions through to completion and escalate significant or overdue issues.
  • Work with technical and operational teams to ensure agreed security controls are implemented and operating effectively.
  • Continuously review security operations and recommend improvements to controls, processes and tooling.

Vulnerability Management

  • Manage the identification, assessment and remediation of vulnerabilities affecting corporate devices and systems.
  • Review vulnerability findings and assess their potential impact on the organisation.
  • Prioritise vulnerabilities according to risk and severity.
  • Coordinate remediation activities with relevant technical teams and users.
  • Track identified vulnerabilities through to resolution.
  • Maintain appropriate vulnerability records and evidence.
  • Escalate significant vulnerabilities or overdue remediation activities to management.
  • Monitor recurring vulnerability issues and recommend preventative improvements.

Security Patch Management

  • Monitor the security patching status of corporate devices and relevant systems.
  • Identify devices that are missing security updates or are outside agreed compliance requirements.
  • Coordinate the deployment and remediation of outstanding security patches.
  • Track patch compliance and escalate significant exceptions.
  • Maintain evidence demonstrating the operation and effectiveness of the patch management process.
  • Identify opportunities to improve and automate patch management and compliance monitoring.

Security Incident Management

  • Maintain and operate the organisation's security incident management processes.
  • Identify, assess and triage suspected security incidents.
  • Coordinate investigation of security incidents and security events.
  • Support containment, remediation and recovery activities.
  • Escalate material incidents to appropriate management stakeholders.
  • Maintain accurate security incident records and supporting evidence.
  • Coordinate post incident reviews and lessons learned activities.
  • Identify root causes and corrective actions following security incidents.
  • Track incident related remediation actions through to completion.
  • Recommend changes to controls, policies or processes following security incidents.

Security Governance and Compliance

  • Support and maintain Shivom's cyber security and information security governance framework.
  • Monitor compliance with organisational security requirements.
  • Maintain security related records, registers, documentation and evidence.
  • Identify security and compliance gaps and coordinate corrective actions.
  • Support management with security reporting and compliance information.
  • Ensure security activities are appropriately documented and traceable.
  • Support continuous improvement of Shivom's security governance arrangements.

ISO 27001 and Information Security Management System

  • Support the operation, maintenance and continuous improvement of Shivom's ISO 27001 Information Security Management System.
  • Maintain relevant ISMS policies, procedures, registers, records and supporting evidence.
  • Support security risk assessments and risk treatment activities.
  • Maintain and monitor security control evidence.
  • Support the maintenance of the Statement of Applicability where applicable.
  • Coordinate actions arising from ISO 27001 control reviews.
  • Support the internal security audit programme.
  • Prepare for external certification and surveillance audits.
  • Coordinate the provision of evidence to auditors.
  • Record, manage and track audit findings, observations and corrective actions.
  • Support management review and continuous improvement activities relating to the ISMS.

Cyber Essentials Plus

  • Coordinate activities required to maintain Shivom's Cyber Essentials and Cyber Essentials Plus certification.
  • Monitor compliance with relevant technical security requirements.
  • Prepare the organisation for Cyber Essentials Plus assessments.
  • Coordinate evidence gathering and technical readiness activities.
  • Work with relevant technical teams to identify and remediate gaps.
  • Liaise with authorised assessors where required.
  • Track findings and remediation activities through to completion.
  • Maintain appropriate records relating to certification and ongoing compliance.

Security Audits and Assurance

  • Coordinate and support internal and external cyber security and information security audits.
  • Prepare documentation and evidence required for security audits and assessments.
  • Coordinate responses to auditor queries and evidence requests.
  • Record audit findings, observations and improvement opportunities.
  • Coordinate corrective and remediation activities.
  • Track audit actions through to satisfactory completion.
  • Support customer and third party security assurance activities where required.
  • Assist with security questionnaires and information security assurance requests.
  • Maintain an appropriate audit trail demonstrating the operation of security controls.

Security Policies, Standards and Processes

  • Develop, document, review and maintain information security policies and procedures.
  • Translate security and compliance requirements into practical operational processes.
  • Maintain detailed security processes covering areas such as vulnerability management, patching, incident management, security audits and compliance.
  • Ensure processes clearly define activities, responsibilities, escalation routes and evidence requirements.
  • Review policies and procedures periodically to ensure they remain appropriate and effective.
  • Communicate changes to security policies and processes to relevant employees.
  • Monitor compliance with security policies and identify areas requiring improvement.
  • Support the development of new security controls and processes as organisational requirements evolve.

Security Operations Automation

  • Identify opportunities to automate repetitive security and compliance activities.
  • Design and implement automation to improve the efficiency and consistency of security operations.
  • Develop automated workflows for security monitoring, reporting, alerts and notifications where appropriate.

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in London

Why this fits a police background — match score 65/100

  • Evidence & case files
  • Incident command & response
  • Investigative casework
  • Surveillance & covert work
  • Risk & threat assessment

What cyber security & digital forensics roles pay ex-police

Advertised UK ranges, editorial estimates reviewed July 2026

Digital forensics analyst£32,000–£45,000
DFIR consultant£45,000–£65,000
Senior forensics / IR specialist£60,000–£80,000
Threat-intelligence specialist£55,000–£80,000
Full cyber security & digital forensics salary guide →

More cyber security & digital forensics jobs for ex-police

  • Full-time

    Your investigative mindset and evidence-handling discipline from policing transfer directly to digital forensics and incident response.

    Posted 3 days ago

  • Full-time

    £61,440 – £69,120Estimated

    Your risk assessment and analytical skills from policing transfer directly to cyber assurance.

    Posted 5 days ago

  • Director - Risk Management

    SHI International · London

    Full-time

    Your threat assessment and multi-agency command experience directly transfer to building enterprise risk frameworks and governance.

    Posted 5 days ago

  • GRC Manager - 6 month FTC

    Trayport · London

    Full-time

    Your experience managing risk, policy, and regulatory compliance under frameworks like PACE transfers directly to GRC.

    Posted 5 days ago