Security Incident Management Analyst - MUST HAVE SC CLEARANCE - Inverness or Preston - 6 months+

Security Incident Management Analyst - MUST HAVE SC CLEARANCE - Inverness or Preston - 6 months+/RATE: £500 per day inside IR35

One of our Blue Chip Clients is urgently looking for a Security Incident Management Analyst.

Please note this role is to start end of September/early October.

Please find some details below:

CONTRACTOR MUST BE SC CLEARED (active) AND BE A SOLE UK NATIONAL

The candidate hasn't been outside the UK for more than 28 consecutive days during the last 5 years

Location: Inverness or Preston | 5 days onsite

MUST BE PAYE THROUGH UMBRELLA

Role Description:

About the role you're considering

The Security Incident Management Analyst operates within the Operational Integrator (OI) function in a multi-supplier (SIAM) environment, supporting the governance and coordination of security incident management activities across suppliers.

The role assists in ensuring security incidents are identified, tracked, escalated, and reported in accordance with client policies and agreed service levels. Working closely with suppliers, service management teams, and security stakeholders, the consultant supports incident visibility, reporting, governance activities, and audit readiness.

This is a governance and coordination role and does not perform Security Operations Centre (SOC) monitoring, threat hunting, incident response, or technical remediation activities.

Key Responsibilities:

Incident Tracking & Coordination

  • Support the monitoring of security incidents throughout their life cycle
  • Ensure incident records are maintained and updated by suppliers
  • Track incident progress from identification through to closure
  • Escalate overdue, recurring, or high-impact incidents through agreed governance channels

Supplier Engagement (SIAM Model)

  • Coordinate with suppliers to obtain incident updates and status reports
  • Support the collection and validation of supplier incident reporting
  • Ensure incident data standards and reporting requirements are applied consistently
  • Identify gaps in ownership, reporting, or evidence

Incident Reporting & Visibility

  • Produce routine security incident reports and dashboards
  • Assist in monitoring:
    • Incident volumes
    • Resolution performance
    • SLA compliance
    • Escalation trends
  • Support governance forums through accurate reporting and status updates

Governance & Process Compliance

  • Support adherence to agreed incident management processes
  • Ensure supplier activities align with client security policies and standards
  • Assist with documenting lessons learned and improvement actions
  • Support maintenance of incident governance documentation

Assurance & Evidence Support

  • Collect and organise incident management evidence
  • Support assurance and audit activities
  • Ensure incident records remain complete, traceable, and audit-ready
  • Assist in demonstrating process compliance and effectiveness

Your skills and experience

Essential

  • Experience in cyber security, service management, operational governance, or support roles
  • Understanding of security incident management processes
  • Awareness of:
    • Incident severity classifications
    • Escalation processes
    • Major incident management principles
  • Strong organisational and reporting skills
  • Ability to coordinate multiple stakeholders

Desirable

  • Exposure to SIAM or multi-supplier environments
  • Familiarity with incident management tooling and reporting outputs
  • Understanding of ITIL Incident Management concepts
  • Experience in regulated, government, or defence environments

Key Deliverables

  • Incident reporting packs
  • Supplier incident performance metrics
  • Incident status tracking and governance records
  • Audit-ready incident evidence
  • Inputs to governance and operational review forums

Role Definition

The role supports the governance and visibility of security incident management activities across suppliers, ensuring incidents are consistently tracked, reported, and evidenced without performing operational incident response activities.

What This Role Does/Does Not Do

Does

  • Track and coordinate incidents
  • Support governance and reporting activities
  • Validate supplier information
  • Maintain incident visibility and status reporting

Does Not

  • Operate SOC tooling
  • Perform threat hunting
  • Conduct incident response
  • Own technical remediation activities

Please send CV for full details and immediate interviews. We are a preferred supplier to the client.

Job Details

Company
Octopus Computer Associates
Location
Preston, Lancashire, United Kingdom PR0 2
Employment Type
Contract
Salary
GBP Daily
Posted