Security Analyst

NCC Group

Greater Manchester

On-site

GBP 52,000 - 78,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Flexible Working
Generous Holiday Allowance
Medicash & Critical Illness Scheme
Pension, Life Assurance & Share Save
Community & Volunteering Programmes
Green Car Scheme
Cycle to Work Scheme
Special Time Off
Family Planning

Job summary

NCC Group is seeking a Security Analyst to join our Bug Bounty Services (BBS) Tier 1 Triage Team in Manchester. You will validate vulnerability submissions, reproduce issues, and prepare clear, actionable writeups for enterprise clients.

The role emphasizes professional communication with researchers and clients, ensuring reproducibility, scope alignment, and high-quality reports. You will join a distributed team and contribute to service improvements.

Qualifications

  • Excellent written and verbal communication skills.
  • Proven experience in web application, network, and mobile application security testing.
  • Strong knowledge in OWASP Top 10.
  • Recent professional experience with scripting languages (Python/JavaScript).
  • Vulnerability Disclosure and Bug Bounty experience.
  • Vulnerability Management experience is a plus.
  • Software QA experience is a plus.
  • Experience with SAST and DAST testing tools is a plus.

Responsibilities

  • Reproduce reported vulnerabilities to confirm validity.
  • Ensure all validated reports meet quality standards before escalation.
  • Communicate professionally with security researchers, requesting information and clarifications.
  • Communicate clearly with enterprise clients, detailing technical aspects.
  • Identify out-of-scope reports, duplicates, and low-quality AI submissions.
  • Manage client queues to meet response and validation timeframes.
  • Deliver NCC-quality vulnerability reports per client specifications.
  • Contribute to projects improving BBS tooling and processes.

Skills

Excellent communication
Web application security
OWASP Top 10
Scripting (Python/JavaScript)
Bug bounty experience
Vulnerability management
Software QA
SAST/DAST tools

Job description

Security Analyst

Department: Cyber Services and Capabilities

Employment Type: Full Time

Location: GBR Manchester Hardman Boulevard

Description

As a Bug Bounty Analyst, you will act as the first line of validation for vulnerability submissions. You will work directly with the Bug Bounty researcher community to accurately reproduce and validate submissions and provide clients with technical writeups for any actionable findings. When triaging vulnerability submissions, analysts must assess the reproducibility, the real-world security impact, and that the reported issue is in scope so that submissions can be successfully filtered prior to escalating to the client. Bug Bounty Analysts serve as a trusted intermediary between the researcher community and the client and therefore must have strong technical capabilities balanced with the ability to deliver clear, professional communication.

Key Responsibilities

Due to continued growth, NCC Group is seeking an experienced Bug Bounty Triage analyst to join the Bug Bounty Services (BBS) Practice as a Security Analyst on our Tier 1 Triage Team. As the premiere triage team in the bug bounty domain, the team's Security Analysts have the unique opportunity to directly engage with security researcher community on their findings on behalf of our Enterprise clients. The Tier 1 Triage team is fully distributed in NA, EMEA, and APAC, and this role directly reports to BBS' UK-based Triage Team Lead.

  1. Reproduce reported vulnerabilities in a controlled manner to confirm their validity.
  2. Ensure that all validated reports meet quality standards for clarity, accuracy, and reproducibility before escalation to the client.
  3. Communicate professionally and constructively with the security researcher community, requesting information and provided clarification where needed.
  4. Communicate clearly and professionally with Enterprise clients ensuring that technical details are
  5. Identify and appropriately handle out-of-scope reports, duplicates, and low-quality AI submissions.
  6. Manage client queues to meet agreed response and validation timeframes.
  7. Author and deliver NCC-quality vulnerability reports to the specifications of individual clients.
  8. Drive or contribute to projects that improve BBS' tooling, operational processes, and delivery quality.
Skills, Knowledge & Expertise
  • Excellent written and verbal communication skills.
  • Proven experience in web application, network, and mobile application security testing.
  • Strong knowledge in OWASP Top 10
  • Recent professional experience that required regular use of a programming scripting language (E.g., Python, JavaScript)
  • Vulnerability Disclosure and Bug Bounty experience.
  • Vulnerability Management experience is a plus.
  • Software QA experience is a plus.
  • Experience with SAST and DAST testing tools is a plus.
Job Benefits
  • Flexible Working: Balance your work and personal life with our flexible working options.
  • Generous Holiday Allowance: Enjoy 25 days of holiday, plus bank holidays, with the option to buy up to 5 additional days of annual leave.
  • Medicash & Critical Illness Scheme
  • Financial & Investment Benefits: Enjoy peace of mind with our Pension, Life Assurance, and Share Save Scheme.
  • Community & Volunteering Programmes: Make a difference in your community with our volunteering opportunities.
  • Green Car Scheme: Drive green and save money with our eco-friendly car scheme.
  • Cycle Scheme: Stay fit and healthy with our cycle-to-work scheme.
  • Special Time Off: Take time off for those big moments in life, like getting married/entering into a civil partnership, becoming a grandparent, and welcoming home a new pet.
  • Family Planning: Benefit from our generous maternity and paternity leave, as well as time off and support for those undergoing fertility treatments.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Bug Bounty Triage Security Analyst
Bug Bounty Triage Security Analyst

NCC Group • Greater Manchester

On-site
GBP 52,000 - 78,000
Flexible Working
Generous Holiday Allowance
Medicash & Critical Illness Scheme
+6
Senior Analyst - Tactical Intelligence
Senior Analyst - Tactical Intelligence

NCC Group plc • Manchester

Hybrid
GBP 50,000 - 70,000
Flexible Working
Generous Holiday Allowance
Medicash & Critical Illness Scheme
+6
Cyber Security Analyst
Cyber Security Analyst

Jobtailor • Birmingham

On-site
GBP 70,000 - 80,000
Annual bonus up to 10%
25 days annual leave + bank holidays
Pension contribution up to 8%
+2
Senior Security Engineer
Senior Security Engineer

NCC Group • Greater Manchester

On-site
GBP 80,000 - 105,000
Flexible working
25 days holiday + bank holidays
Medicash & Critical Illness Scheme
+4
Senior Analyst - Tactical Intelligence
Senior Analyst - Tactical Intelligence

NCC Group • Greater London

On-site
GBP 70,000 - 110,000
Flexible Working
Generous Holiday Allowance
Medicash & Critical Illness Scheme
+1
Information Security Analyst, Vulnerability Management
Information Security Analyst, Vulnerability Management

bet365 Group • Hempstalls

Hybrid
GBP 50,000 - 75,000
Eye care
Flu Vaccinations
Life Assurance
Senior Security Engineer
Senior Security Engineer

NCC Group • Manchester

On-site
GBP 65,000 - 95,000
Flexible Working
25 days holiday plus bank holidays
Pension and Life Assurance
+4
Senior Security Engineer
Senior Security Engineer

NCC Group plc • Manchester

On-site
GBP 90,000 - 120,000
Flexible Working
25 days holiday + bank holidays
Medicash & Critical Illness Scheme
+7
Embedded Researcher
Embedded Researcher

NCC Group plc • Cheltenham

Hybrid
GBP 40,000 - 60,000
Flexible Working
Generous Holiday Allowance
Financial & Investment Benefits
+3
Vulnerability Analyst
Vulnerability Analyst

Computacenter • England

On-site
GBP 45,000 - 60,000