Where are cyber security analyst jobs actually advertised?
How SOC and analyst roles really get filled: specialist boards, cleared recruiters, MSSP internal moves, and the budget cycles that drive hiring.
Published 20 Sept 2026 · 7 min read
Why the public boards feel empty
If you're a SOC analyst, threat intel analyst, or vulnerability management analyst sending applications through LinkedIn Easy Apply and Indeed and hearing nothing, the problem often isn't your CV. A meaningful share of cyber security hiring happens through channels that never touch a general job board, or that post there only after the role has already been informally filled. Security teams are small, headcount is tightly controlled, and hiring managers who already know three people who could do the job rarely write a job advert as their first move. The advert on LinkedIn is frequently the last visible step in a process that started weeks earlier somewhere else.
This matters more in this field than in most, because a lot of analyst hiring sits behind two things that don't apply to general tech roles: security clearance and vendor/certification ecosystems.
Cleared roles don't appear on public boards at all
If you work in or near government, defence, critical national infrastructure, or contracts touching NCSC guidance, a real portion of analyst roles require SC or DV clearance in the UK (or equivalent in other jurisdictions). These roles are rarely posted on LinkedIn or Indeed, partly because the employer doesn't want to advertise that a cleared post exists, and partly because uncleared applicants are unusable anyway. Instead they move through:
- ClearedJobs.net and equivalent cleared-specific boards, where the audience is pre-filtered by clearance status.
- Clearance-specialist recruiters who hold a candidate pool of already-vetted people and match them to contracts as they come up, sometimes months before a role is public.
- Direct approach from the employer or prime contractor, because re-clearing someone who left six months ago is faster than clearing someone new.
If your clearance has lapsed, that's often the actual blocker, not your experience. Reactivating or holding clearance (even between contracts) is worth more here than almost any CV edit.
Where the rest actually gets posted
Outside cleared work, roles do reach public-facing channels, but specialist ones outperform generalist boards for anything above a graduate SOC analyst level:
- InfoSec-Jobs.com and CyberSecurityJobsite.com — smaller volume than LinkedIn but a higher proportion of roles that specify SIEM platform, EDR tooling, and tier level (Tier 1/2/3 SOC, not just "analyst"), which tells you the advert was written by someone who actually does the hiring.
- CyberSN — US-heavy but increasingly used by MSSPs and vendors with UK/EU teams, built specifically around matching security job titles rather than generic "analyst" taxonomy.
- ISC2 and ISACA career centres — tied to membership, so lower volume, but roles here often ask for CISSP, CISM, or CRISC specifically, and the audience is self-selected to hold those.
- Dice — still used for contract and MSP/MSSP security roles in the US and increasingly for remote EU-facing contract work.
- Conference job boards and noticeboards — BSides events, DEF CON's job board, and the Black Hat career fair are real hiring channels, not networking theatre. Employers who send staff to these events sometimes hold vacancies specifically to fill at or around the conference, because the applicant pool self-filters for people who are already engaged enough to attend.
- r/cybersecurity and infosec-specific Discord/Slack communities (BlueTeamVillage's Discord is one example) sometimes carry postings from smaller MSSPs and startups who can't justify a paid board listing.
The pattern across all of these is that the advert language is more specific — SIEM platform named (Splunk, Sentinel, QRadar), EDR named (CrowdStrike, SentinelOne, Defender for Endpoint), and the SOC tier stated. If you're only seeing vague "cyber security analyst" postings with no tooling mentioned, you're likely looking at recruiter-authored listings for roles that may not exist yet in the form advertised, or at agencies casting a wide net to build a CV pool against a client they haven't confirmed.
Agencies, MSSPs, and the pool problem
A lot of analyst hiring, especially at Tier 1/Tier 2 SOC level, runs through specialist infosec recruiters rather than direct employer postings: firms like La Fosse's cyber practice, Understanding Recruitment, JBC, or in-house talent teams at large MSSPs (Bridewell, NCC Group, BT Security, Orange Cyberdefense, and similar). These agencies often work on retained or exclusive contracts, meaning the role genuinely won't appear elsewhere, and they maintain live candidate pools they match against multiple similar contracts over time — which is why a recruiter you spoke to eight months ago might resurface with a role that fits.
MSSPs specifically hire in a distinct pattern worth knowing: they staff up SOC teams around new client contracts. A recruiter's pipeline can spike sharply when an MSSP wins a large managed detection and response (MDR) contract, because they need bodies on shift within weeks, not months. This hiring is rarely advertised broadly — it goes through the recruiter's existing pool first, then a targeted push, and only reaches general boards if the pool comes up short. If you want visibility into this, being registered with two or three specialist agencies that work MSSP contracts matters more than applying wider on generalist boards.
Internal movement is the biggest channel you can't see
Security teams promote and lateral-move heavily within themselves, more than most tech functions, because trust and clearance status are expensive to rebuild. A Tier 1 SOC analyst moving to Tier 2, or a SOC analyst moving into a threat intel or detection engineering role, frequently happens as an internal transfer that's never advertised outside the organisation — the requisition might legally have to be posted internally, get filled in a week, and never reach a public board at all. This is especially pronounced in MSSPs and large enterprise security functions, where headcount budget is fixed and the easiest hire is someone who already has the badge and the clearance.
The practical implication: getting into a SOC at Tier 1, even a role that looks junior for your experience, can be a faster route to a Tier 2 or engineering role six months later than waiting for that specific role to appear externally.
Timing and seasonality specific to this field
Security hiring has some patterns tied to budget and compliance cycles rather than the general graduate-scheme calendar:
- Financial year-end budget releases. Many UK organisations run April–March fiscal years; unspent security budget sometimes gets converted into headcount requisitions in Q1 (Jan–March) before it's lost, and again after new budget lands in April.
- Compliance deadlines. Hiring for analyst and GRC-adjacent roles sometimes clusters ahead of PCI-DSS reassessment, ISO 27001 surveillance audits, or a known regulatory deadline, because the organisation needs demonstrable staffing in place by the audit date, not because of headcount planning cycles.
- Post-incident hiring. A breach or a widely reported incident, even at a different company in the same sector, can trigger a defensive hiring push at organisations that weren't previously actively recruiting. This is inconsistent and impossible to plan around, but it explains sudden spikes in postings from a specific sector.
- Autumn graduate/apprenticeship cycles. If you're early career, cyber apprenticeship schemes (including those linked to NCSC's CyberFirst) and graduate SOC analyst intakes tend to open in September–October for the following year, separate from the general graduate scheme calendar.
None of this is precise enough to plan an application campaign around a single month, but it explains why a quiet August followed by a burst of postings in September isn't random.
What to actually do with this
Register with two or three specialist infosec recruiters who work MSSP and enterprise SOC contracts, not just one generalist tech recruiter. Check InfoSec-Jobs.com, CyberSN, and the ISC2/ISACA career centres directly rather than relying on LinkedIn's algorithm to surface them. If you hold or can reactivate clearance, treat that as a separate job search with its own boards and recruiters. And if you're inside a security team already, ask directly about internal Tier 2 or engineering openings before they're posted — a real portion never leave the building.
If the constraint is time rather than knowledge — you know where to look but not the hours to check InfoSec-Jobs.com, CyberSN, ISC2, and three recruiter inboxes every week alongside your current job — jobmarket.pro searches across these sources for you, reads each advert against your actual experience, and prepares the application from a single profile it doesn't invent experience into.
Or stop doing this by hand
An agent that reads each advert in full, tells you where you fit and where you do not, and prepares the application from a profile it cannot invent experience into. Free to start, no card.