AI, data and technology

Sourcing by role

How to find a cybersecurity analyst.

Blue team, red team, and GRC are three professions sharing one label. A shortlist that mixes them is the most common failure in security recruiting.

Every CV in this field says 'security', and that word covers a SOC analyst triaging alerts at 3am, a penetration tester breaking into networks for a living, and a compliance specialist who has never touched a terminal. All three are correctly described as cybersecurity professionals. None can do the others' jobs.

Two further structures shape the search. Certifications in this field vary enormously in what they prove — some require years of experience, some require exploiting live machines, and some are multiple-choice — so reading them as an interchangeable acronym list produces shortlists that fail technical screening. And for US government-adjacent work, clearance often determines the market before any other criterion applies.

Job titles worth searching

Grouped by what the person actually does, because searching all54 at once produces a result set you cannot triage. Decide which group you need first — that decision does more for the search than any string below.

Core analyst titles

Largely interchangeable and largely uninformative. 'Security Analyst' covers everything from someone triaging alerts in a SOC to someone running an enterprise risk programme. The discipline terms below tell you what this group does not.

  • Cybersecurity Analyst
  • Information Security Analyst
  • Security Analyst
  • InfoSec Analyst
  • Cyber Defence Analyst
  • IT Security Analyst
  • Security Operations Analyst

Blue team and defensive

The largest population, and the one most job adverts actually mean. Tier structure matters here: a Tier 1 SOC analyst triages alerts on a rota, while a threat hunter proactively searches for what the tooling missed. These are different jobs at different pay, and both get called 'SOC Analyst'.

  • SOC Analyst
  • Security Operations Centre Analyst
  • Tier 1 Analyst
  • Tier 2 Analyst
  • Incident Responder
  • Threat Hunter
  • Digital Forensics Analyst
  • DFIR Analyst
  • Malware Analyst
  • Detection Engineer
  • Threat Intelligence Analyst

Red team and offensive

A genuinely separate discipline requiring demonstrable hands-on skill. Practical certifications like OSCP mean considerably more here than multiple-choice ones, because the work is provable. Defensive analysts do not cross over without deliberate retraining.

  • Penetration Tester
  • Pentester
  • Ethical Hacker
  • Red Team Operator
  • Offensive Security Engineer
  • Application Security Engineer
  • AppSec Engineer
  • Vulnerability Researcher
  • Exploit Developer
  • Bug Bounty Hunter

Governance, risk and compliance

The most commonly mislabelled group. GRC work is policy, audit, and framework implementation — closer to consulting than to engineering, and frequently done by people with no technical background. Hiring a GRC specialist into a SOC role, or the reverse, is the single most common miscast in security recruiting.

  • GRC Analyst
  • Security Compliance Analyst
  • Risk Analyst
  • IT Auditor
  • Security Auditor
  • Compliance Manager
  • Privacy Analyst
  • Data Protection Officer
  • Third Party Risk Analyst

Engineering and architecture

Builders rather than monitors. These roles design and implement controls rather than respond to alerts, and they generally require genuine software or infrastructure engineering ability. Pay is markedly higher and the pool is much smaller.

  • Security Engineer
  • Cloud Security Engineer
  • Security Architect
  • DevSecOps Engineer
  • Identity and Access Management Engineer
  • IAM Engineer
  • Network Security Engineer
  • Product Security Engineer
  • Cryptography Engineer

Leadership

Where the word 'Analyst' disappears entirely. Security leadership is frequently held by people who came through engineering or GRC rather than operations, and virtual CISO arrangements mean some experienced leaders are contracting rather than employed.

  • Security Manager
  • SOC Manager
  • Head of Information Security
  • CISO
  • Chief Information Security Officer
  • Virtual CISO
  • Director of Security
  • Security Programme Manager

Certifications, and what each actually proves

Security certifications differ more in rigour than any other field's. The distinction that matters is practical versus multiple-choice, and experience-gated versus open — because those determine whether the credential predicts anything.

CredentialFull nameRegionWhat it tells you
Security+CompTIA Security+InternationalEntry-level and extremely common. Meets US DoD 8570 baseline requirements, which is why it appears on so many government-adjacent job adverts. Signals foundational knowledge, not capability.
CISSPCertified Information Systems Security ProfessionalInternationalRequires five years of documented experience, so it is a seniority marker rather than a skills test. Broad and managerial in emphasis — a CISSP holder is not necessarily hands-on.
OSCPOffensive Security Certified ProfessionalInternationalA 24-hour practical exam requiring actual exploitation of live machines. The most respected hands-on credential in offensive security, and genuinely hard to obtain.
GIAC / GCIH / GCIAGlobal Information Assurance Certification familyInternationalSANS-affiliated and expensive, so holders usually had employer sponsorship. GCIH and GCIA are strong signals for incident response and detection work respectively.
CISM / CISACertified Information Security Manager / AuditorInternational (ISACA)Management and audit focused. CISA in particular is a GRC and audit credential, not a technical one — a frequent source of mismatched shortlists.
CEHCertified Ethical HackerInternationalWidely held and widely discounted by practitioners, because it is multiple-choice rather than practical. Still appears in job requirements, especially government-adjacent ones.
ClearanceUS security clearanceUnited StatesSecret, Top Secret, and TS/SCI with polygraph. Sponsorship costs tens of thousands and takes months to years, so an already-cleared candidate is worth a substantial premium and is recruited constantly.
CE / NCSCCyber Essentials / NCSC certified schemesUnited KingdomUK frameworks including CHECK and CREST for penetration testing. CREST registration is the practical UK equivalent of OSCP for consultancy work.

Where security professionals actually are

This field leaves an unusually verifiable public trail. Bug bounty platforms publish researcher reputation and disclosed report histories, CVE credits are permanent and attributable to named individuals, and GitHub carries detection rules that demonstrate blue team depth directly. All three show capability rather than claims, which is precisely what technical screening struggles to establish.

The conference circuit is more accessible than in most fields. BSides events run in most major cities, are affordable, and publish speaker lists — meaning local senior practitioners are identifiable without needing to track the large international conferences. CTF competition results are public and demonstrate hands-on skill under time pressure.

One channel worth knowing: much of this community moved to Mastodon and to invite-based Discord servers, and is deliberately less visible on mainstream platforms. That is partly professional culture and partly operational security. It means conventional social search underrepresents the population, and that referrals carry more weight here than in almost any other technical field.

Boolean search strings

Written to be pasted as-is. Each one is built around an intent rather than a platform, since the useful question is what you are trying to find, not which site you happen to be on.

LinkedIn profiles, direct X-ray

Google (LinkedIn)
site:linkedin.com/in/ ("security analyst" OR "SOC analyst" OR "incident response") (CISSP OR GCIH OR OSCP) "{city}"

Security professionals maintain reasonably complete profiles, and certification acronyms often sit in the headline where they are still indexed inconsistently. As with all X-ray now, LinkedIn no longer exposes titles and locations to crawlers, so treat this as verification and headline-matching rather than filtered discovery.

Practical offensive security credentials

Google
("OSCP" OR "OSCE" OR "CRTO" OR "CREST registered") ("penetration test" OR "red team") -jobs -course -training

OSCP requires a 24-hour practical exam against live machines, so it cannot be crammed the way multiple-choice certifications can. Excluding 'course' and 'training' is essential or the results fill with providers selling the certification.

Bug bounty hunters and researchers

Google
(site:hackerone.com OR site:bugcrowd.com) ("hacktivity" OR "reputation" OR "researcher") -jobs

Bug bounty platforms publish researcher reputation and disclosed reports. This is verifiable offensive capability rather than a claim, and this population is rarely approached through conventional channels.

Detection engineers and rule authors

Google
site:github.com ("sigma rules" OR "detection-rules" OR "YARA" OR "Splunk" OR "Elastic detection") -awesome -tutorial

Detection engineering leaves a public trail. Someone contributing Sigma or YARA rules has demonstrable blue team depth that no certification list conveys.

Cleared candidates in US government work

Google
("TS/SCI" OR "Top Secret" OR "active clearance" OR "DoD 8570") ("cyber" OR "security analyst") -jobs -hiring

Clearance sponsorship costs tens of thousands and takes months, so already-cleared candidates command a premium. They are also heavily recruited, so speed matters more than string refinement.

Conference speakers and CTF competitors

Google
("speaker" OR "presented" OR "CTF" OR "capture the flag") ("DEF CON" OR "Black Hat" OR "BSides" OR "SANS") 2024..2026 -jobs

BSides events happen in most major cities and publish speaker lists. CTF placings are public and demonstrate hands-on ability directly, which is exactly what interviews struggle to establish.

GRC and audit specialists

Google
("CISA" OR "CISM" OR "ISO 27001 lead auditor") ("SOC 2" OR "NIST" OR "GDPR" OR "PCI DSS") -jobs -course

Framework names are the filter for GRC work. Someone who has run a SOC 2 audit or an ISO 27001 implementation has done something specific and verifiable, unlike a generic 'security' claim.

Security researchers publishing findings

Google
("CVE-" OR "responsible disclosure" OR "advisory") ("discovered by" OR "credited to") 2024..2026 -jobs

A CVE credit is public, permanent, and attributable. Researchers with assigned CVEs have demonstrated vulnerability discovery ability at a level no certification tests.

Mistakes that cost the most time

  1. Treating security as one discipline

    Blue team, red team, and GRC are three different professions that share a label. A SOC analyst monitors and responds, a penetration tester attacks, and a GRC analyst writes policy and runs audits — and few people are good at more than one. The most common failure in security recruiting is a shortlist mixing all three because every CV says 'security'.

  2. Reading certifications as capability

    CISSP requires five years of experience and is broad and managerial, so it marks seniority rather than hands-on skill. CEH is multiple-choice and widely discounted by practitioners. OSCP requires actually exploiting live machines in a 24-hour exam. Treating these as an interchangeable list of acronyms produces shortlists that fail technical interviews.

  3. Ignoring the clearance question until late

    For US government and defence work, clearance is often the binding constraint. Sponsorship costs tens of thousands and takes months to years, and many roles simply cannot wait. Establish whether the role requires an existing clearance before sourcing anyone, because it changes the available market entirely.

  4. Advertising a SOC role as an analyst role

    Tier 1 SOC work is shift-based alert triage, frequently on nights and weekends, and burnout is high. Advertising it without naming the shift pattern attracts candidates who leave within months when they discover the reality. Naming it filters correctly and costs nothing.

  5. Expecting entry-level candidates to hold senior certifications

    Job adverts routinely ask for CISSP on junior roles, which is impossible — it requires five years of documented experience. This is a well-known irritant in the security community and marks the advert as written by someone outside the field, which damages response rates beyond the specific role.

  6. Missing practitioners who do not use security titles

    A great deal of security work is done by people titled Systems Administrator, DevOps Engineer, or Software Engineer who own security responsibilities. In smaller organisations there may be no security title at all. Searching only for security titles misses the people who have actually been doing the work.

Common questions

What job titles should I search for when hiring a cybersecurity analyst?
It depends entirely on which of the three security disciplines you need. For defensive work, search SOC Analyst, Incident Responder, Threat Hunter, Detection Engineer, and DFIR Analyst. For offensive work, Penetration Tester, Red Team Operator, AppSec Engineer, and Vulnerability Researcher. For governance and compliance, GRC Analyst, IT Auditor, Security Compliance Analyst, and Risk Analyst. Generic terms like Security Analyst and Information Security Analyst span all three and will produce an unusable mixed shortlist, so establish the discipline before writing any string.
Which cybersecurity certifications actually indicate capability?
The practical ones. OSCP requires exploiting live machines in a 24-hour exam and cannot be crammed, which makes it the strongest hands-on signal in offensive security. The GIAC family, particularly GCIH and GCIA, indicates genuine incident response and detection depth, and holders usually had employer sponsorship given the cost. CISSP requires five years of documented experience but is broad and managerial, so it marks seniority rather than technical skill. CEH is multiple-choice and widely discounted by practitioners. CISA and CISM are audit and management credentials, not technical ones.
What is the difference between blue team, red team, and GRC roles?
Blue team is defensive: monitoring, detecting, and responding to attacks, typically in a security operations centre. Red team is offensive: simulating attacks through penetration testing and adversary emulation to find weaknesses before real attackers do. GRC covers governance, risk, and compliance — writing policy, running audits, and implementing frameworks such as ISO 27001, SOC 2, or NIST, which is closer to consulting than to engineering. These require different skills and attract different people, and few practitioners are strong in more than one.
How much does a security clearance matter when sourcing?
For US government and defence work it frequently determines the entire available market. Sponsoring a new clearance costs tens of thousands of dollars and takes months to years depending on the level, so roles requiring cleared candidates are competing for a small, heavily recruited pool. Levels run from Secret through Top Secret to TS/SCI with polygraph, and each step narrows the population considerably. Establish whether an existing clearance is genuinely required before sourcing, because the answer changes both the timeline and the compensation expectations.
Where can I find security professionals outside LinkedIn?
The public work trail is unusually rich here. Bug bounty platforms such as HackerOne and Bugcrowd publish researcher reputation and disclosed reports, which is verifiable offensive capability rather than a claim. GitHub reveals detection engineers through Sigma and YARA rule contributions. CVE credits are public, permanent, and attributable to individuals. Conference circuits matter too — BSides events run in most major cities and publish speaker lists, and CTF competition placings demonstrate hands-on ability directly. This community is also active on Mastodon and Discord in ways that do not surface in conventional search.

The method behind the strings

Sourcing, in full.

Full Stack Recruiter devotes its first seven chapters to search: Boolean fundamentals, search engines beyond Google, research sources, contact discovery, and responsible public-source research. The titles change by role; the method under them does not.