Security Business Analyst at UK Research & Innovation, Swindon/Remote, 6 Months, £Contract Rate

Contract Description

UK Research and Innovation (UKRI) is the national funding agency investing in science and research in the UK.

 

UKRI invests £8 billion of taxpayers' money each year into research and innovation and the people who make it happen. They work across a huge range of fields - from biodiversity conservation to quantum computing, and from space telescopes to innovative health care. They give everyone the opportunity to contribute and to benefit, bringing together people and organisations nationally and globally to create, develop and deploy new ideas and technologies.

 

Job Purpose:

 

The Cyber Resilience (CR) project is a coordinated programme of initiatives aimed at strengthening UKRI's ability to withstand and respond to an increasingly complex cyber threat landscape. It focuses on enhancing existing defensive capabilities, reducing the risk of attack and compromise, and transitioning UKRI from a reactive to a proactive security posture. Building on the foundations established through the Security: Foundations & Digital Resilience (ST&DR) programme, the project seeks to protect against financial and reputational harm while ensuring compliance with the UK Government Cyber Security Strategy 2022 -2030. Overall, it delivers targeted, proportionate improvements aligned to identified threats and supports UKRI's ambition to operate as a resilient, high-reliability organisation.

 

The programme consists of ten workstreams that collectively advance cyber resilience across key areas, including threat intelligence, third-party risk management, phishing and email security, cloud security, and incident response. These initiatives include deploying threat intelligence tooling, strengthening phishing detection and spoofing protections, enhancing cloud security through CASB, CSPM, and CNAPP capabilities, and improving oversight of third-party risks.

 

The project also introduces measures to strengthen organisational readiness and recovery, such as defining a Minimal Viable Organisation, implementing incident response exercises and lessons learned processes, and procuring immutable backup solutions to support business continuity. Together, these workstreams enhance existing capabilities while introducing new controls that materially improve UKRI's cyber resilience.

 

As a Security Business Analyst, your main responsibilities will be:

 

  • Current state and gap analysis - Assessment of existing cyber security capabilities (from ST&DR and current operations) against target resilience outcomes, identifying gaps across areas such as threat intelligence, cloud security, and incident response.
  • Requirements definition and traceability - Clear, prioritised business and technical requirements for each workstream (e.g. CASB, CSPM, CNAPP, phishing controls), with traceability to identified risks, threats, and compliance obligations.
  • Process mapping and optimisation - Documented "as-is " and "to-be " processes for key cyber activities (e.g. incident response, third-party risk management, phishing handling), ensuring improved efficiency and a shift toward proactive security practices.
  • Stakeholder needs analysis and alignment - Capturing and reconciling requirements from security teams, IT, suppliers, and leadership to ensure solutions meet operational needs and organisational objectives.
  • Business case support and benefits definition - Contribution to defining measurable outcomes (e.g. risk reduction, improved detection times, resilience improvements), linking deliverables to business value and strategic goals.
  • Acceptance criteria and validation artefacts - Definition of success criteria, user acceptance requirements, and support for testing and validation to ensure delivered capabilities meet intended cyber resilience outcomes

 

Essential:

 

  • Process analysis and design - Skilled in mapping and improving "as-is " and "to-be " processes, particularly across security operations, incident response, and third-party risk management.
  • Cyber security and risk awareness - Solid understanding of cyber resilience concepts, threat landscapes, and controls (e.g. cloud security, phishing, incident response) to interpret requirements in a risk-based context.
  • Requirements elicitation and analysis - Ability to gather, structure, and prioritise complex business and technical requirements across multiple workstreams, ensuring alignment to threats and strategic objectives.
  • Stakeholder engagement and facilitation - Strong communication and facilitation skills to work effectively with technical teams, senior stakeholders, and suppliers, translating between business needs and technical solutions.
  • Data analysis and insight generation - Capability to interpret security data, metrics, and risk information to support decision-making, benefits definition, and performance tracking.
  • Change and governance understanding - Awareness of organisational change, governance frameworks, and compliance requirements (e.g. UK Government Cyber Security Strategy), ensuring solutions are adoptable, controlled, and sustainable.

 

Please be aware that this role can only be worked within the UK and not Overseas.

 

Disability Confident 

 

As a member of the Disability Confident Scheme, UKRI guarantees to interview all candidates who have a disability and who meet all the essential criteria for the vacancy. In cases where we have a high volume of candidates who have a disability who meet all the essential criteria, we will interview the best candidates from within that group. This scheme encourages candidates with a disability and/or neurodivergence to apply. In exceptional circumstances, we may also need to apply the desirable criteria in our shortlisting process which may include holding active security clearance.

 

Armed Forces Commitment

 

UKRI guarantees to interview veterans or spouses / partners of military personnel who meet all the essential criteria for the vacancy. In cases where we have a high volume of ex-military candidates / military spouses or partners, who meet all of the essential criteria, we will interview the best candidates from within that group. In exceptional circumstances, we may also need to apply the desirable criteria in our shortlisting process which may include holding active security clearance.

 

In applying for this role, you acknowledge the following this role falls in scope of the Off Payroll Working in the Public Sector legislation. Any rates of payment quoted will reflect the gross rate per day for the assignment and will be subject to appropriate taxes and statutory costs. As such the payment to the intermediary and your income resulting from this contract will be different.