United Kingdom · Technical roles · Mid-Level (2-5 years)

Security Analyst

Here is the whole job, in plain words. What it is, a real day, what you decide, how you're judged, how people get here and where they go next. Then the part no course gives you: twelve AI tutors who learn your work.

  • Experience bandMid-Level (2-5 years)
  • Direct reportsNo direct reports
  • Reports toSecurity Manager
  • UK framework levelUsually a coordinator, or early in a professional job

Also advertised as Information Security Analyst · Cyber Security Analyst · SOC Analyst (Level 2)

Built on an analysis of 43,079 real UK job descriptions · grounded in qualifications employers recognise

Start with a free Future Fluency check, tuned to Security Analyst

Ten quick questions, one per Future Fluency, asked against this role rather than a generic one. About five minutes, and no card.

Start the check, free

1What this role really is

This isn't just about watching screens; it's about being the first line of defence when something goes wrong. You'll be the one digging into alerts, figuring out what's real, and stopping threats before they cause serious damage. It's a hands-on role where you'll get to own incidents from start to finish, learning a tonne along the way.

2What you'd actually use

The tools this job runs on, and how well you'd need to know each one.

Splunk Enterprise Security (SIEM)Intermediate

Triage alerts, run custom KQL/SPL queries to investigate incidents, build basic dashboards for specific threat hunts. You'll be living in Splunk.

CrowdStrike Falcon (EDR)Intermediate

Monitor the console for endpoint alerts, isolate compromised hosts, collect forensic data, perform basic threat hunting using FQL (Falcon Query Language). This is your eyes and ears on endpoints.

Wiz / Palo Alto Prisma Cloud (CSPM)Basic

Identify and escalate cloud misconfigurations using the platform's UI, follow runbooks to remediate common findings. You'll be checking for dodgy cloud setups.

Tenable.io / Qualys VMDR (Vulnerability Management)Intermediate

Run scheduled scans, generate standard reports, assign remediation tickets to system owners based on criticality. You'll be the one making sure we know what's vulnerable.

ServiceNow (ITSM/GRC)Intermediate

Manage incident tickets, track vulnerability remediation, enter evidence for control assessments. This is where a lot of your workflow will happen.

3What you get to decide, and how that grows

Power in a job isn't your title. It's what you're allowed to decide. Here's how it grows as you move up.

The choiceComing inWhere you are nowThe step above
Incident Containment Actions (e.g., host isolation, IP blocking)Requires manager approval for all actions.Independent decision within established playbooks; escalate if outside playbook or high business impact.Independent decision; only inform manager for awareness.
Vulnerability Prioritisation & AssignmentAssigns based on manager's instructions or pre-defined criticality matrix.Prioritises based on business context and CVSS, then assigns to relevant teams. Consults manager on high-risk, ambiguous cases.Defines prioritisation framework and negotiates remediation SLAs with business units.
Security Tool Configuration Changes (e.g., SIEM rules, EDR policies)Executes changes as instructed by senior team members.Proposes and implements minor configuration changes to improve detection or reduce false positives, with peer review. Escalates major changes.Designs and implements significant changes to security tool configurations, often leading a project.
External Communication (e.g., vendor contact, law enforcement)Never communicates externally without direct supervision.Communicates with security tool vendors for support. All other external communication requires manager approval.May communicate with external parties (e.g., threat intelligence groups, peer CISOs) under guidance from Director.

4How you'll be judged

The scoreboard, honestly: the hard targets, how often each one is actually looked at, and the quiet human signals that never make it onto a dashboard.

Alert Triage Time (Critical Alerts)
How quickly you get eyes on and categorise critical security alerts.
Target · 90% of critical alerts triaged within 15 minutes

If we get 10 critical alerts on a Monday, you'd need to have looked at and categorised 9 of them within 15 minutes of them popping up. This means knowing what's a false positive and what needs immediate attention.

Phishing Report Resolution Rate
The percentage of user-reported phishing emails you analyse and close out.
Target · 95% closed within 1 hour

Someone reports a dodgy email. You need to quickly check if it's malicious, block it if it is, and confirm with the user that it's safe (or not). Doing this for 19 out of 20 reports within an hour shows you're on top of it.

Vulnerability Remediation Ticket Processing
The number of vulnerability tickets you process, assign, and track through to resolution.
Target · Process 20+ tickets per week

Our scanning tools find a bunch of vulnerabilities. You'll take those, create tickets for the right teams (like Engineering or IT Ops), and make sure they're actually getting fixed. Hitting 20 means you're keeping the backlog moving.

Mean Time to Contain (MTTC) for Incidents
The average time it takes from identifying a confirmed incident to containing it (stopping the spread).
Target · Reduce by 10% quarter-over-quarter

Last quarter, it took us an average of 45 minutes to contain a confirmed malware incident. This quarter, we're aiming for 40 minutes. Your quick actions directly contribute to this.

Incident Documentation Quality
How clear, comprehensive, and accurate your incident reports and post-mortems are.
  • Your incident reports are easy for anyone to understand, even non-technical folks. They clearly outline what happened, what you did, and what needs to happen next. Other teams can pick up your documentation and know exactly where things stand. Your manager rarely needs to ask for clarification.
Proactive Communication During Incidents
How well you keep relevant teams and your manager updated during an active incident.
  • You're not just working in a silo. You're sending timely updates to the IT team, your manager, and anyone else who needs to know, even if it's just to say 'still investigating, no new info yet.' People feel informed, not left in the dark. You'll typically use our incident management platform for this, but sometimes a quick Slack message is needed.
Collaboration with IT & Engineering
Your ability to work effectively with other technical teams to resolve security issues.
  • When you hand over a remediation task to IT Ops or Engineering, they understand what you need them to do and why it's important. You're seen as someone who helps them solve problems, not just creates more work. They'll actually come to you for advice sometimes, which is a good sign.
Threat Hunting Initiative
Your willingness to proactively search for threats, not just react to alerts.
  • You're not just waiting for the SIEM to tell you something. You're regularly looking for suspicious patterns, trying out new queries, and digging into unusual logs even when there isn't an active alert. You might find something before it becomes a full-blown incident, which is gold.

5Would you like it

The honest version. What people enjoy, and what grinds them down.

What people enjoy
Problem Solving & Investigation

You'll spend a good chunk of your day acting like a digital detective, piecing together clues from logs, alerts, and system data to understand what's happening. Every incident is a new puzzle to solve.

An alert fires about unusual activity on a server. You'll dive into the logs, check network connections, look at process trees, and figure out if it's a legitimate admin task or something more sinister.

Protecting & Defending

There's a real sense of purpose in this role. You're directly contributing to the safety and security of our systems and data, preventing harm to the business and our customers.

Successfully containing a ransomware attempt before it encrypts critical systems, knowing your quick actions saved the company from massive disruption and cost.

Technical Mastery & Learning

You'll constantly be learning about new threats, new tools, and new ways to secure systems. This role demands that you stay sharp and expand your technical skills.

Researching a newly discovered vulnerability (CVE), understanding its impact, and then figuring out how to detect and mitigate it within our environment.

What frustrates people
  • Alert fatigue: Drowning in thousands of low-fidelity alerts, making it hard to spot the real threats.
  • Chasing other teams: Constantly following up on remediation tickets that aren't getting fixed fast enough.
  • Repetitive tasks: Some initial incident triage can feel a bit like Groundhog Day.
  • False positives: Spending time investigating something that turns out to be harmless, which can be frustrating.
  • Legacy systems: Having to secure older, clunkier systems that are harder to patch or monitor.
What this role does not give you
  • A predictable 9-to-5 routine – incidents don't care about your schedule.
  • Complete control over all security decisions – you'll need to influence and collaborate.
  • A role where you build new features – you're protecting what's already there (and sometimes helping build securely).
  • An environment free from ambiguity – you'll often make decisions with incomplete information.

6Who you work with

Your work is pretty critical, actually. You're directly responsible for reducing our exposure to cyber threats by quickly identifying and shutting down attacks. Get it right, and we avoid downtime, data breaches, and a lot of very public embarrassment. Get it wrong, and the consequences can be pretty severe, from financial losses to a damaged reputation. Honestly, you're a frontline defender.

Inside the business
  • IT Operations Team (for system changes and patching)
  • Engineering Teams (for application security issues)
  • Service Desk (for user-reported issues)
  • Data Protection Officer (for privacy-related incidents)
  • Your immediate Security Team (for collaboration and knowledge sharing)
Outside the business
  • Security tool vendors (for support and troubleshooting)
  • Threat intelligence providers (for staying updated on new threats)

7What you need before you start

Not a wish list. The things you would be expected to already have.

  • At least 2-3 years of hands-on experience in a Security Operations Centre (SOC), incident response, or similar security analyst role.
  • Demonstrable experience with at least one major SIEM platform (e.g., Splunk, Microsoft Sentinel, Elastic SIEM) for alert triage and investigation.
  • Practical experience with an Endpoint Detection & Response (EDR) solution (e.g., CrowdStrike, SentinelOne, Defender for Endpoint).
  • A solid grasp of networking fundamentals (TCP/IP, DNS, routing, firewalls) and how they apply to security.
  • Familiarity with common scripting languages like Python or PowerShell for automating tasks or analysing data (or a strong willingness to learn).
  • Experience with cloud environments (AWS, Azure, or GCP) from a security perspective, even if it's just identifying misconfigurations.
  • A genuine passion for cybersecurity and a drive to continuously learn and improve.

8What to practise next

Where the job is going, and what to do about it starting this week.

Advanced Threat Hunting Techniques

Always important, but evolving constantly. Moving beyond basic IoC matching to more sophisticated behavioural analysis and anomaly detection. You'll be expected to find the 'unknown unknowns'.

Hypothesis-Driven Hunting · Statistical Anomaly Detection · Graph Analysis for Relationships · Malware Analysis Fundamentals

  • This week: Explore open-source threat hunting guides and methodologies.
  • This month: Dedicate a few hours each week to 'free play' in our SIEM, looking for unusual patterns without a specific alert.
  • Month 2: Take an online course or attend a workshop on a specific threat hunting methodology.
  • Month 3: Present a small threat hunting exercise and its findings to your team.

Quick win: Start subscribing to advanced threat intelligence blogs and newsletters. Understanding what others are hunting for will give you ideas for our environment.

9Staying current once you are in

What people here do to keep up
  • Regularly participate in security conferences (e.g., BSides, Infosec Europe) or local meetups to network and learn about new threats.
  • Contribute to open-source security projects or bug bounty programmes to hone your skills.
  • Maintain an active home lab for experimenting with new tools and techniques in a safe environment.
  • Subscribe to leading cybersecurity blogs, podcasts, and threat intelligence feeds to stay informed.
  • Pursue further certifications that align with your career goals and our technical stack.

10How the AI economy is changing work like this

Before we ask anything of you, here's what we can already say about AI and work of this kind:

The new skill this role is being asked for: Prompt Engineering & LLM Integration for Security

Critical within 6 months – honestly, this is already happening. AI-powered tools are changing how we analyse data and respond to incidents. Analysts who can effectively 'talk' to these tools will be significantly more productive.

We'll only ever tell you what we can actually back up. No hype, no scare tactics.

Your PlanIllustration

Built for Security Analyst

5 units that map to this job, from the qualifications that cover it.

  1. Incident Response, Investigations and ForensicsQualifi Ltd · covers 6 of 15 standardsLevel 4
  2. Incident response and disaster recoveryNCFE · covers 5 of 15 standardsLevel 3
  3. Incident Response and ManagementSFJ Awards · covers 4 of 15 standardsLevel 4
  4. Investigations and Incident ResponseQualifi Ltd · covers 4 of 15 standardsLevel 3
  5. Carrying out Information Security Incident Management activitiesPearson Education Ltd · covers 3 of 15 standardsLevel 3
These are the real units behind this job, in the order they rank for it. Nothing here is marked done, because this plan has not been started by anyone yet. Yours would fill in as you go.

The rising capability

Zavmo analysis

What's rising in its place

This is where the work is heading, and the higher pay with it. Get fluent here and the shift stops being a threat and starts being your edge.

Prompt Engineering & LLM Integration for Security

Critical within 6 months – honestly, this is already happening. AI-powered tools are changing how we analyse data and respond to incidents. Analysts who can effectively 'talk' to these tools will be significantly more productive.

  • Context Windows & Token Limits
  • Output Validation & Hallucination Detection
  • Prompt Chaining for Complex Investigations
  • RAG (Retrieval Augmented Generation) for Internal Data

Advanced Cloud-Native Security Concepts

Important within 12 months – we're moving more and more into cloud-native architectures (containers, serverless, microservices). Understanding the security implications here is vital.

  • Container Security (Docker, Kubernetes)
  • Serverless Security (AWS Lambda, Azure Functions)
  • Cloud Identity & Access Management (IAM)
  • Infrastructure as Code (IaC) Security

What you’ll use

Skills this role draws on

Technical

  • Incident Response Lifecycle (PICERL)
  • Vulnerability Management Principles
  • Threat Modelling (Basic Concepts)
  • Network Security Fundamentals
  • Operating System Security (Windows/Linux)

The pathway

How you actually get there, here

How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.

  1. 1

    Associate Security Analyst (L1)

    1-2 years

    Skills to master

    • Mastering alert triage, basic incident handling procedures, understanding security tools, and clear documentation. Basically, getting really good at following the runbooks.

    You're ready to move on when

    • Consistently resolving routine alerts without supervision.
    • Proactively identifying areas for improvement in existing playbooks.
    • Demonstrating a strong grasp of foundational security concepts.
  2. 2

    IT Support / Network Engineer with Security Focus

    2-3 years

    Skills to master

    • Transitioning from general IT troubleshooting to security-specific problem-solving. This means understanding attack vectors, security controls, and incident response. You'd already know our infrastructure well.

    You're ready to move on when

    • Successfully completed a security-focused certification (e.g., CompTIA Security+).
    • Demonstrated a keen interest in security, perhaps by identifying and escalating security issues in your previous role.
    • Strong understanding of network architecture and operating systems.
  3. 3

    Junior Penetration Tester / Ethical Hacker

    1-2 years

    Skills to master

    • Shifting from offensive security to defensive. This involves understanding how to detect and respond to the attacks you previously simulated. Your attacker mindset is a huge asset here.

    You're ready to move on when

    • Deep understanding of attacker methodologies and tools.
    • Ability to translate offensive knowledge into defensive strategies.
    • Strong analytical and problem-solving skills.

11Where this role leads

The long view:Your career in cybersecurity here is what you make it. We're committed to providing the opportunities, training, and support for you to grow, whether you want to become a deep technical specialist or eventually lead a team. It's a challenging but incredibly rewarding field, and we're excited to see where you take it.

Pay & demand

The figure is the median for full-time employees in the ONS occupation this job title codes to (Cyber security professionals), from the April 2025 survey — about six months old when published, as ASHE always is. It is that occupation's middle, not this role's. Half earn more.

The ten Future Fluencies

Zavmo analysis

The credential is what you can do today. These are what keep you valuable.

A qualification proves you can do the job as it's defined today. These ten are what decide whether you're still the obvious person for it in five years. They're the capabilities employers are now writing into senior roles faster than people are learning them. Zavmo weaves them through whatever you study, so you come out with both: the credential and the fluency.

The highlighted ones are the Fluencies your role leans on hardest, from how Security Analyst is actually changing. In about two minutes, the free confidence check asks where you stand on each of the ten. That's the whole check, and it's what makes the plan yours rather than generic.

12The team that's yours

No two people are taught the same way. This is one-to-one, not one-to-many.

Zavmo is a hyper-personalised AI learning platform. Twelve virtual tutors, each with a different way of teaching, and one orchestration agent that picks the right one for the moment. So every single lesson is shaped around you, your role, and the way you learn. Not a course everyone sits through. A conversation built for you, and no one else.

…and nine more, matched to you after your first chat. Meet all twelve

13What it feels like

A conversation, not a course

Because your tutor knows your role, your projects and your last session, learning sounds like this. And it's different for every single person:

Incident Response, Investigations and ForensicsLevel 4

Applied to your work in Security Analyst

This unit aims to equip learners with an understanding of incident response as a business function, including the operation of Computer Emergency Response Teams (CERTs) and aligned task forces for business continuity, disaster recovery, and crisis management. Learners will also understand how major computer incidents are formally investigated, including evidence gathering and analysis, and the relevant legal and ethical considerations.

How the thinking builds
  1. Remember
  2. Understand
  3. Apply
  4. Analyse
  5. Evaluate
  6. Create
An illustration of a Zavmo lesson, built from this role’s own route. The unit, its objective and every criterion above are the awarding body’s own words, not an example.

One to one, not one to many

No two people run this the same way

A course is written once and handed to everyone. This is assembled around you, and keeps changing as it learns you. Five things it reads, and what each one changes.

  1. Your actual work Every lesson is taught against a live piece of your own work, not a worked example from a textbook.
  2. What you already know The first conversation finds your starting point, so you skip what you can already do and spend the time on what you cannot.
  3. The conditions you learn under Not a learning-styles quiz. The evidence does not support those. The dimensions the research does back, read once and used to shape the plan.
  4. How far you got last time It picks up mid-thought. The tutor knows what you said, what you struggled with, and what it asked you to try.
  5. Which tutor suits the moment Twelve of them, each for a different kind of thinking. The one who walks you through a first idea is not the one who stress-tests it.

See how you learn, free. Eight questions, no sign-up. A directional taster; the diagnostic inside Zavmo goes deeper and keeps adapting.

DemonstrateIllustration

Evidenced on your work in Security Analyst

You do not finish by watching something. You finish by showing it on the work you already do, against the measures this job is judged on.

  • Alert Triage Time (Critical Alerts)How quickly you get eyes on and categorise critical security alerts.If we get 10 critical alerts on a Monday, you'd need to have looked at and categorised 9 of them within 15 minutes of them popping up. This means knowing what's a false positive and what needs immediate attention.90% of critical alerts triaged within 15 minutes
  • Phishing Report Resolution RateThe percentage of user-reported phishing emails you analyse and close out.Someone reports a dodgy email. You need to quickly check if it's malicious, block it if it is, and confirm with the user that it's safe (or not). Doing this for 19 out of 20 reports within an hour shows you're on top of it.95% closed within 1 hour
  • Vulnerability Remediation Ticket ProcessingThe number of vulnerability tickets you process, assign, and track through to resolution.Our scanning tools find a bunch of vulnerabilities. You'll take those, create tickets for the right teams (like Engineering or IT Ops), and make sure they're actually getting fixed. Hitting 20 means you're keeping the backlog moving.Process 20+ tickets per week
  • Mean Time to Contain (MTTC) for IncidentsThe average time it takes from identifying a confirmed incident to containing it (stopping the spread).Last quarter, it took us an average of 45 minutes to contain a confirmed malware incident. This quarter, we're aiming for 40 minutes. Your quick actions directly contribute to this.Reduce by 10% quarter-over-quarter
These are this job's own measures, with its own targets. Nothing is marked evidenced, because nobody has started this yet. Yours would fill in from the work you bring.

Your passport

This isn't a certificate you file away. It's a passport to the life you're designing.

Every credit you earn and every fluency you build adds up: evidence where it counts, carried with you. Zavmo keeps the map: where you are, where you're heading, and the next step, at your pace, around your life. From Security Analyst to Senior Security Engineer (L3), and whatever you decide comes after.

Level 3 · in progressAI Fluency→ Senior Security Engineer (L3)→ your design
Where this takes you

Your career in cybersecurity here is what you make it. We're committed to providing the opportunities, training, and support for you to grow, whether you want to become a deep technical specialist or eventually lead a team. It's a challenging but incredibly rewarding field, and we're excited to see where you take it.

See Your Progress GrowIllustration
Security Analyst
  • Incident Response Lifecycle (PICERL)
  • Vulnerability Management Principles
  • Threat Modelling (Basic Concepts)
  • Network Security Fundamentals
  • Operating System Security (Windows/Linux)
This is your Mind Palace on learn.zavmo.ai. Every skill above comes from this role's own record, not an example borrowed from another job. A node lights up when you evidence it, and what you build stays yours between jobs. That is the part a course cannot do.

14The detail, folded away

Everything else the record holds

The career branches in full, how AI is already showing up in the day-to-day, and the questions people ask about this job. Here when you want them, out of the way while you decide.

Where it leads next, rung by rung

Where it leads

The career path, and where it branches

Security Analyst is a start, not a ceiling. Each step below asks for new skills and hands back more autonomy.

  1. Senior Security Engineer (L3)

    3-5 years in the Security Analyst role

    You'll move from primarily responding to incidents to designing and implementing new security controls, automating processes, and mentoring junior team members. You'll own specific security workstreams.

    • Designing and implementing new SIEM detection rules and SOAR playbooks.
    • Architecting security solutions for new applications or infrastructure.
    • Performing advanced threat hunting and malware analysis.
    • Leading security projects from conception to deployment.
Working with AI on the job

Working with AI

Where AI is starting to help

Let's be real, security analysis can be a grind. Sifting through endless logs, triaging alerts, drafting reports – it takes time. But what if you could cut down on the tedious stuff and focus on the real threats? That's where AI comes in. We're not talking about replacing you; we're talking about giving you a serious upgrade.

As a Security Analyst, you're on the front lines. AI isn't some far-off future for us; it's a tool we're actively using to make your day-to-day work faster, smarter, and frankly, more interesting. Imagine having an intelligent assistant that handles the repetitive tasks, leaving you free to do the deep investigative work that truly matters.

Automated Alert Triage

Use AI-powered SOAR (Security Orchestration, Automation, and Response) to automatically investigate, enrich, and even close low-level, benign alerts. This means fewer false positives hitting your queue, and you can focus on the genuinely suspicious stuff. Think of it as having a tireless junior analyst that never sleeps.

Anomaly Detection Acceleration

Leverage User and Entity Behaviour Analytics (UEBA) to automatically baseline 'normal' activity across our network and systems. AI will then flag truly anomalous behaviour that rule-based systems might miss, helping you spot insider threats or sophisticated attacks much faster. It's like having X-ray vision for your logs.

AI-Powered Threat Intel Briefings

Instead of manually sifting through dozens of daily threat intelligence feeds, CVE announcements, and security news, use AI tools to ingest, summarise, and prioritise this information. You'll get a concise, actionable briefing tailored to our specific environment, saving you hours of reading and helping you stay ahead of the curve.

Executive Summary & Report Drafting

After an incident, turning complex technical details (IoCs, timelines, logs) into a clear, non-technical executive summary or initial post-mortem report can be a pain. Generative AI can draft these initial reports for you, giving you a solid starting point that you can then refine and add your expert insights to. It's a massive time-saver for documentation.

Common questions

Common questions

How do you become a Security Analyst?

Common routes in include Associate Security Analyst (L1) (1-2 years), IT Support / Network Engineer with Security Focus (2-3 years) and Junior Penetration Tester / Ethical Hacker (1-2 years). Times vary with prior experience.

Where can a Security Analyst progress to?

This role can lead on to Senior Security Engineer (L3) (3-5 years in the Security Analyst role), depending on the skills you build.

What level is a Security Analyst in the UK?

This role aligns to RQF Level 3 on the UK framework, a guide to the depth of qualification it maps to, not a hard entry bar.

What new skills matter most for a Security Analyst?

Increasingly, Prompt Engineering & LLM Integration for Security and Advanced Cloud-Native Security Concepts. These are the areas where the higher-paid, future-proof work is heading.

The honest bit

You’ve started things before

Most of them were built for a room full of people who aren’t you. A cohort moves on whether or not your week allowed it, and by the third week the thing you’re behind on becomes the reason you stop opening it.

There’s no cohort here, and no timetable to fall behind. Before anything starts, Zavmo asks when you’re sharpest and how long you can realistically sit down for, then builds the sessions around those answers. A bad fortnight changes your pace. It doesn’t put you behind.

And you only pay once you start learning. Searching and planning are free, and you can cancel any time — so the cost of finding out is an afternoon, not a year.

What it costs

Less than one coaching session. Every month.

A single career-coaching hour costs more than a month of this, and it ends when the hour does. Zavmo doesn't. It's £70 a month, about £2.30 a day, for a companion that knows a Security Analyst, works on the job you actually do, and keeps going at your pace rather than a timetable's.

  • Searching and planning stay free. You only pay when you start learning.
  • Your credits are yours. Regulated, and they don't vanish when a subscription ends.
  • Cancel any time and billing stops. No notice period, no minimum term.

Your path, personalised

You have the map. Walking it is the part we do together.

This route runs to 15 national skill standards. That is a real journey.

Zavmo shapes a learning experience as unique as you are. It fits how you learn, your pace and the work you already do. Every step stays benchmarked to recognised national standards. That’s the plan for becoming a Security Analyst: personal to you, and it still counts. The first steps are free.

Independent research finds well-designed intelligent tutoring performs nearly as well as one-to-one human tutoring: VanLehn (2011), Educational Psychologist.

A private tutor in the UK averages £35–40 an hour . Zavmo is £70/month.

A real plan on learn.zavmo.ai: Ofqual-regulated units, credits, and a three-month run at your own pace.
Start free No commitment. See your first steps free.

15Where to go from here

Other roles at Level 3

Same depth of qualification, different job. Useful if the work appeals but this particular role does not.

Other roles in Technical roles

Stay in the field you know and move sideways rather than up.

If you leave this industry

The skills you'll gain as a Security Analyst are highly transferable across almost any industry. Every company needs cybersecurity. You could move into finance, healthcare, e-commerce, or even government roles, often with a focus on specific regulatory compliance or industry threats.

Not sure this is the right direction?

Work out what you actually want from work first, then come back and see which roles fit it. Takes about ten minutes.

This role profile is © 2026Growth Engineering Technologies Ltd. Built from UK occupational standards and regulated qualification data, and written for Zavmo.

You're not behind. You're right on time. The shift is only just beginning. Your role won't look the same in two years. Be the one who leads the change, not the one it happens to. Build my plan, free Here's the first ten minutes: a 2-minute confidence check → your personalised roadmap → meet the tutors matched to you. No card, cancel any time. No card. Build your plan, see your roadmap and meet the twelve tutors matched to you. All free. When you're ready to start learning, it's £70 a month, billed monthly. Cancel any time and billing stops.