{"id":1484589,"url":"https://alion.io/job/salt-cyber-security-analyst","title":"Cyber Security Analyst","company":{"id":1935342,"name":"Salt","domain":"welovesalt.com","url":"https://alion.io/company/welovesalt","size_band":"201-500","is_staffing_agency":true,"employer_type":"agency","is_intermediary":false,"listed_via":null,"ats_vendor":null,"truth_index":{"grade":"C","score":63,"open_postings":1439,"ghost_share":0.613,"stale_share":0,"repost_share":0,"time_to_fill_p50_days":null,"computed_at":"2026-10-03T05:45:00Z"}},"role":"Security","role_family":"Security","seniority":"senior","employment_type":null,"work_mode":"hybrid","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["London, United Kingdom"],"countries":["GB"],"hiring_countries":[],"hiring_countries_total":0,"salary":{"min":600,"max":601,"currency":"GBP","period":"day","gross":null,"usd_annual":198750},"salary_estimate":null,"experience_years_min":8,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AWS","optional":false},{"name":"Azure","optional":false},{"name":"Azure DevOps","optional":false},{"name":"Checkmarx","optional":false},{"name":"Checkov","optional":false},{"name":"CI/CD","optional":false},{"name":"Docker","optional":false},{"name":"Fortify","optional":false},{"name":"GitHub","optional":false},{"name":"GitLab","optional":false},{"name":"IAM","optional":false},{"name":"Jenkins","optional":false},{"name":"Kubernetes","optional":false},{"name":"Microsoft Defender for Cloud","optional":false},{"name":"MITRE ATT&CK","optional":false},{"name":"OWASP","optional":false},{"name":"OWASP ASVS","optional":false},{"name":"OWASP Top 10","optional":false},{"name":"OWASP ZAP","optional":false},{"name":"Prisma Cloud","optional":false},{"name":"Snyk","optional":false},{"name":"SonarQube","optional":false},{"name":"STRIDE","optional":false},{"name":"Terraform","optional":false},{"name":"tfsec","optional":false},{"name":"Veracode","optional":false},{"name":"Wiz","optional":false},{"name":"ISO 27001","optional":true}],"status":"live","first_seen_at":"2026-05-28T00:00:00Z","employer_posted_date":"2026-05-28","last_verified_at":"2026-09-29T22:22:26Z","board_verified":false,"closed_at":null,"days_open":129,"trust":{"level":"ghost","repost_count":0,"flags":["stale","company_stale"],"days_open":128},"description":"Back to all jobs\nApplications are now closed.\nCyber Security Analyst -\nRef: JO-2605-361068\nUnited Kingdom, London \n\nEnterprise Technologies, Technology \n\nIT \n\n5,000+ Employees \n\n£600.00 - £601.00 per day \n\nEnvironment:\n\nHybrid \n\nContract Type:\n\nTemporary \n\nStarts:\n\n2026-08-03 \n\nDuration:\n\n12 months \n\nSenior Cyber Security Analyst - Application Security / DevSecOps / Secure Design/ SAST, DAST - London\nContract | 12 Months | Hybrid\n8 Days onsite per month - the rest is remote working\nInside of IR35 must use umbrella\n£600 per day\nWe are supporting a leading international organisation in the search for a Senior Cyber Security Analyst to join a high-performing security engineering and assurance team.\nThis role is ideal for a consultant with a strong background in Application Security, DevSecOps, Secure SDLC, Threat Modelling, and Cloud Security, who can work closely with engineering teams to embed security into modern software delivery environments.\nThe successful consultant will operate across cloud-native platforms, CI/CD pipelines, APIs, containers, and microservices architectures, helping drive secure-by-design principles across enterprise-scale platforms.\nKey Responsibilities\nPerform security risk assessments, secure design reviews, and threat modelling exercises for applications, APIs, and cloud platforms\nDefine and implement secure-by-design principles across software engineering and DevOps teams\nEmbed security controls into CI/CD pipelines using modern DevSecOps practices\nLead and support SAST, DAST, SCA, and container security integration activities\nConduct application and infrastructure security assessments aligned to OWASP, NIST, and industry best practices\nWork closely with development teams to triage vulnerabilities and support remediation activities\nDefine security requirements for modern application architectures including:\nAPIs\nMicroservices\nKubernetes / Containers\nCloud-native platforms\nSupport secure architecture reviews across AWS and/or Azure environments\nCollaborate with stakeholders across Security, Engineering, DevOps, Risk, and Architecture teams\nSupport vulnerability management, security governance, and secure delivery processes\nRequired Skills & Experience\nWe are looking for consultants with strong experience across several of the following areas:\nApplication Security & Secure SDLC\nOWASP Top 10 / ASVS\nSecure coding practices\nThreat modelling (STRIDE / MITRE ATT&CK)\nSecurity architecture and design reviews\nVulnerability management and remediation\nSecure Software Development Lifecycle (SSDLC)\nDevSecOps & CI/CD Security\nIntegration of security tooling into CI/CD pipelines\nExperience with:\nGitHub\nGitLab\nJenkins\nAzure DevOps\nHands-on experience with:\nSAST\nDAST\nSCA\nSecrets scanning\nContainer security\nCloud & Platform Security\nAWS and/or Azure security\nKubernetes / Docker / container security\nAPI security\nIAM / Identity Federation / SSO\nWAF and cloud-native security tooling\nInfrastructure-as-Code security (Terraform / Checkov / tfsec)\nSecurity Tooling\nExperience with tools such as:\nSonarQube\nCheckmarx\nVeracode\nFortify\nOWASP ZAP\nBurp Suite\nSnyk\nAqua\nWiz\nPrisma Cloud\nDefender for Cloud\nSentinel\nIdeal Background\n8-15+ years in Cyber Security\nStrong focus on Application Security and DevSecOps\nExperience working closely with engineering and platform teams\nStrong stakeholder engagement and communication skills\nExperience within regulated or enterprise environments preferred\nFinancial services, government, or large-scale enterprise experience highly desirable\nCertifications (desirable)\nCISSP\nSABSA\nGIAC\nISO 27001\nCloud security certifications (AWS / Azure)\n*Rates depend on experience and client requirements","description_format":"text","description_chars":3680,"description_truncated":false,"requirements":{"experience_years_min":8,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[{"name":"United Kingdom","iso":"GB","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Cybersecurity","Application Security"],"lifecycle":[{"event":"open","at":"2026-09-29T22:07:30Z"}],"visa":[],"liveness":{"score":5,"band":"cold","label":"Long shot","p_open":0.9,"p_active":0.197,"p_room":0.28,"age_days":128,"expected_fill_days":46,"reasons":["conf:79","agency","stale_co","urgency","velocity","ghost","win:tail","crowd:brand"],"computed_at":"2026-10-03T05:45:00Z"},"pay":{"stated_usd_annual":198750,"is_top_pay":true},"html_url":"https://alion.io/job/salt-cyber-security-analyst","json_url":"https://alion.io/job/salt-cyber-security-analyst.json","meta":{"generated_at":"2026-10-04T00:56:20Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":1194,"day_limit":5000,"remaining_today":3806,"minute_limit":60,"resets_at":"2026-10-05T00:00:00Z"}}}