Citation Group
Security Analyst

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Job Title: Security Analyst
Line Manager: Lead Security Analyst
Citation is a £280M+ PE-backed provider of compliance, verification, and certification services to 120,000+ global clients. Our growth combines organic development with 2-3 strategic acquisitions per year, requiring rapid integration of new capabilities while maintaining exceptional client outcomes. We operate as an AI-first business, continuously exploring how emerging technologies can transform operations and services.
Role Overview
We're looking for a motivated Cyber Security Analyst to join our growing team. This is an excellent opportunity for someone with an IT or cyber security background who enjoys working with clients, solving technical challenges and helping organisations improve their cyber resilience.
You'll be responsible for delivering Cyber Essentials and Cyber Essentials Plus assessments, guiding organisations through the certification process and providing practical advice to help them achieve compliance. Alongside certification work, you'll carry out vulnerability scanning, review security findings, advise on patch management and support clients in strengthening their overall security posture.
Working within our experienced cyber security team, you'll receive ongoing training and have the opportunity to develop your skills across a range of security disciplines.
What You'll Be Doing
- Deliver Cyber Essentials and Cyber Essentials Plus assessments in line with IASME and NCSC requirements.
- Review Cyber Essentials questionnaires and supporting technical evidence.
- Provide clear, practical guidance to clients throughout the certification process.
- Conduct vulnerability scans against client environments using industry-standard tools.
- Analyse vulnerability scan results and produce clear remediation recommendations.
- Review operating systems, applications and network devices to identify missing security updates.
- Assess patch management processes and advise clients on improving their vulnerability management practices.
- Assist clients with remediation activities to help them achieve certification.
- Produce high-quality assessment reports and technical documentation.
- Maintain accurate records of assessments and certification activities.
- Keep up to date with Cyber Essentials requirements, emerging cyber threats and industry best practice.
- Work collaboratively with colleagues across the penetration testing and compliance teams.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
What We're Looking For
Essential
- Minimum of three years' experience in an IT or cyber security role within the last five years.
- Good understanding of Windows, macOS and Linux operating systems.
- Experience with Microsoft 365 administration and security features.
- Understanding of networking fundamentals including TCP/IP, DNS, firewalls and VPNs.
- Knowledge of vulnerability management and security best practices.
- Good understanding of software patching and operating system update processes.
- Excellent written and verbal communication skills.
- Strong attention to detail and problem-solving ability.
- Ability to explain technical concepts to both technical and non-technical audiences.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Desirable
- Experience using vulnerability scanning tools such as Nessus, Qualys, OpenVAS or similar.
- Cyber Essentials Assessor qualification.
- Experience delivering Cyber Essentials and/or Cyber Essentials Plus assessments.
- Security+, CISM, CISSP, ISO 27001 Lead Auditor or equivalent certifications.
- Experience with vulnerability remediation and security consultancy.
What We Offer
- Competitive salary.
- Company pension scheme.
- 25 days annual leave plus bank holidays.
- Additional day off for your birthday.
- Ongoing training and funded professional certifications, including Cyber Essentials Assessor, CREST and Cyber Scheme qualifications.
- Clear career progression within a growing cyber security consultancy.
- Exposure to a wide range of organisations across multiple industries.
- Supportive team environment with opportunities to broaden your technical skills beyond Cyber Essentials.
Why Join Us?
Our clients trust us to help protect their businesses from evolving cyber threats. We invest heavily in our people, encourage continuous learning and provide opportunities to work across compliance, vulnerability management, penetration testing and wider cyber security services.
If you're passionate about cyber security, enjoy working with clients and want to build your career within an experienced and growing team, we'd love to hear from you.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills