The Security Validation Analyst helps prove that the Group’s security controls work as intended across Zellis Group, which comprises Zellis, Moorepay, Benifex and Hastee. Working as part of the security validation team, the role provides hands-on support for security testing, vulnerability management and technical security assessments – helping to find weaknesses before attackers do and providing evidence-based assurance that the Group is protected against current and emerging threats.
Reporting to the Cyber Security Validation Manager, this is a practical, technically focused role spanning penetration testing support, vulnerability management, technical assessments, solution threat modelling and security architecture review. The analyst partners with engineering, architecture and operations teams across all of the Group’s brands and business units to ensure security is embedded from the outset, weaknesses are identified and prioritised, and remediation is tracked through to closure.
The role takes a strong “AI first” approach, using approved AI tooling (such as Microsoft Copilot and Claude) to expand test coverage, accelerate analysis and reporting, and help shift the Group from periodic, point-in-time testing towards continuous, evidence-led validation of its security posture.
Key responsibilities
Security Validation & Testing
- Support the Group’s security testing and attestation activity, including penetration testing, attack simulation and breach-and-attack simulation.
- Help validate the effectiveness of security controls and detections, providing evidence that they work as intended.
- Support the coordination of third-party testing partners, helping to capture clear, actionable findings.
Vulnerability Management
- Run and triage vulnerability scans across the Group’s estate, helping to set risk and priority levels for identified vulnerabilities.
- Track remediation through to closure with engineering and operations teams, escalating where timelines or risk thresholds are breached.
- Contribute to vulnerability and validation reporting across the Group’s business units.
Technical Assessments & Threat Modelling
- Support technical security assessments of new and existing systems, identifying weaknesses and recommending proportionate controls.
- Contribute to solution threat modelling and data-flow analysis to identify threats, vulnerabilities and countermeasures early in design.
- Help maintain visibility of the Group’s assets and attack surface to inform testing priorities.
Security Architecture Review & Advisory
- Contribute to security architecture reviews and secure-by-design advice across change and project activity.
- Act as a technical security liaison for business units, supporting engineering, architecture and product teams.
- Help ensure security is considered and designed into systems and processes through a secure development lifecycle.
AI, Automation & Continuous Assurance
- Take a strong “AI first” approach, using AI and automation to expand test coverage, analyse results and reduce manual effort.
- Use approved AI tooling (such as Microsoft Copilot and Claude) to accelerate assessment, reporting and remediation guidance.
- Support the shift from point-in-time testing towards continuous control validation and always-on assurance.
Reporting & Collaboration
- Provide clear, timely reporting on validation outcomes, risks and trends to the Cyber Security Validation Manager and stakeholders.
- Translate technical findings into clear, risk-based actions for both technical and non-technical audiences.
- Share knowledge and good practice across the security team and the wider business.
- Hands-on experience in security validation, vulnerability management or technical security testing.
- An understanding of penetration testing, attack simulation or security control validation.
- Familiarity with technical security assessments, threat modelling and secure-by-design principles.
- Working knowledge of the Microsoft security suite (e.g. Defender, Sentinel, Entra) and common security testing tooling.
- Ability to interpret technical findings and convey risk and remediation clearly.
- A genuine appetite for applying AI and automation to expand and accelerate security validation.
- Excellent analytical, written and verbal communication skills
Essential Functional / Technical Skills
- A recognised qualification in a relevant discipline, or equivalent training, together with around 1–2 years’ hands-on experience in security testing, vulnerability management or a technical security role.
- Practical experience with vulnerability management tooling and remediation tracking.
- An understanding of common frameworks and methodologies (e.g. MITRE ATT&CK, OWASP, NIST CSF).
- Working knowledge of cloud and on-premise environments (Microsoft Azure preferred) and common security tooling (e.g. SIEM, EDR/XDR).
- Confident user of AI productivity and security tooling (e.g. Microsoft Copilot, Claude) to accelerate testing and analysis.
- Experience with business and ITSM tooling such as ServiceNow, Azure DevOps, Zendesk and Jira would be advantageous.
Desirable Qualifications & Certifications
- A relevant certification such as CompTIA Security+, CompTIA PenTest+ or eJPT (held or working towards); progress towards OSCP, CREST (CPSA / CRT) or CEH would be an advantage.
- Experience in a regulated, data-rich or SaaS environment – ideally payroll, HR, financial services or similar.
- Familiarity with cloud security testing (Azure preferred) and secure development practices.
Personal Attributes / Competencies
- Technically curious and rigorous, with an attacker’s mindset and a defender’s discipline.
- Evidence-led and objective, able to substantiate findings clearly.
- Proactive and accountable, taking ownership of findings through to remediation.
- Strong prioritisation skills, able to manage multiple assessments and deadlines.
- A clear communicator across technical and business audiences.
- Collaborative team player, keen to share knowledge and learn from senior colleagues.
- Curious and improvement-minded, keen to apply new tools and automation to work smarter.
- Adaptable and comfortable working in a fast-paced, evolving environment.
At Zellis Group (Zellis, Moorepay, Benifex, and Hastee) we power exceptional employee experiences by creating AI-enabled products and services within HR, workforce management, payroll, and benefits. Our vision is to be the clear leader in pay, reward, analytics, and people experiences. With over 3,500 colleagues across the UK, Europe, India and the Philippines, we have a significant ambition for growth (organically and through M&A).
Our vision is to be the clear leader in pay, reward, analytics, and people experiences. We're passionate about creating an environment where people want to join, belong to, and be part of a progressive organisation. Our values, which were defined with input from of our colleagues, we live and breathe every day:
- Unstoppable together.
- Always learning.
- Make it count.
- Think scale.
Our people are critical to our ongoing success; we’re proud of our inclusive culture that gives you the platform to grow, challenge the status quo and play a crucial role in further enhancing our market position as the leading provider of HR & Payroll software and services. With Zellis you’ll have the chance to stretch and challenge yourself in an environment that’s varied, flexible and hugely supportive.
We also love to reward and recognise our brilliant colleagues. As part of your benefits package, you’ll receive:
- A competitive base salary, cash car allowance and bonus package.
- 25 days annual leave, plus your birthday off and the opportunity to buy additional holiday.
- Private medical insurance.
- Life assurance 4x salary.
- Enhanced pension scheme with company contributions up to 8.5%.
- A huge range of additional flexible benefits across financial & personal wellbeing, lifestyle & leisure.