Cyber security recruitment in the UK: a hiring manager's guide
How to scope, source, assess and retain security talent — and when contract, permanent or an associate network is the right answer.
Most security hiring problems are not sourcing problems. They are specification problems. A role that asks for a generalist architect, a hands-on detection engineer and a compliance lead in one person will stay open for six months and then be filled by whoever is available rather than whoever is right.
This guide covers how we help clients scope, source and assess security people, and how to decide between a permanent hire, a contractor and an associate.
Start by defining the outcome, not the job title
Security job titles mean very different things in different organisations. "Security engineer" can mean cloud IAM, SIEM content, application security or endpoint tooling. Before writing a specification, answer four questions:
- What will be materially different in twelve months if this person succeeds?
- Which three tasks will take up most of their first ninety days?
- What must they have done before, and what can they learn here?
- Who decides whether they are doing well, and against what measure?
The answers usually collapse a bloated ten-point requirement list into a much sharper role that is genuinely fillable.
Permanent, contract or associate?
Each shape solves a different problem, and using the wrong one is expensive.
- Permanent. For capability you need continuously: running the SOC, owning identity, maintaining the compliance calendar. Slower to hire, cheaper over years, and it builds institutional knowledge.
- Contract. For bounded, dated work with a clear deliverable: a migration, a remediation programme, covering parental leave. Faster to start, higher day rate, and the knowledge leaves with them unless handover is written into the engagement.
- Associate or fractional. For senior expertise you need in small quantities: a few days a month of interim CISO time, a board-level risk review, or specialist assurance. Often the only sensible answer for organisations too small to justify a full-time senior hire.
A common and avoidable mistake is hiring a permanent senior leader to do what is really a nine-month transformation job, then losing them when the interesting work finishes.
IR35 and contract engagements
For UK contract hires, determine status before you advertise, not after you have a preferred candidate. Get the statement of work, the deliverables and the level of supervision documented up front. Late status determinations are where contract hires collapse, and where day rates get renegotiated from a position of weakness.
Writing a specification that attracts the right people
- Lead with the problem, not the perks. Strong security people choose interesting problems and credible sponsorship.
- Be specific about the environment: cloud platforms, scale, tooling, regulatory context, team size, who the role reports to.
- Separate essential from useful. Every "essential" that is really a nice-to-have shrinks your candidate pool, and disproportionately deters good candidates who self-assess strictly.
- Drop degree and certification gates unless they are contractually required. CISSP, CISM and Cyber Essentials assessor status prove some things and not others; see our view on where certification actually helps in is Cyber Essentials worth it for enterprise?.
- Publish a salary or day rate range. Ranges filter out mismatches before either side spends time.
Assessing candidates without theatre
Trivia questions and whiteboard cryptography tell you very little. Better signals:
- A scenario walk-through drawn from your own estate. "Here is our architecture; where would you look first, and why?"
- A short written exercise: a one-page risk summary for a board audience. Most senior security work is persuasion in writing.
- A structured incident conversation about something that genuinely went wrong for them, focused on decisions, trade-offs and what they would change.
- Consistent scoring against the outcomes you defined at the start, by the same small panel across all candidates.
Keep the process to two or three stages inside two weeks. Good security candidates are usually in multiple processes, and speed is a genuine competitive advantage.
Onboarding and retention
The first ninety days set retention. Give a new hire a named sponsor, a small early deliverable that ships, access sorted before day one, and clarity on how their work is measured. Security people leave for three reasons more than any others: no mandate, no budget, and no visible progress.
Retention also depends on the shape of the work. If the role is 90% ticket queue with no time for improvement, expect to re-run the hire in eighteen months.
Building a bench before you need it
Emergency hiring is the most expensive hiring. Maintain a light relationship with a small number of trusted specialists, keep your role specifications current, and know which of your requirements could be met by an associate at short notice. That is the logic behind our scalable resourcing model — a vetted network you can draw on for weeks or months without carrying permanent cost.
Where to go next
If you are planning a security hire, we can help you scope the role, benchmark the market and source candidates through our associate network — or provide interim cover while the permanent search runs. See our services, browse open vacancies, or talk to us about your hiring plan.