Services Approach About
About
Careers Contact
Open roles · Engineering

Security Analyst

Find the weaknesses in systems that hold money, health records and identity, before someone else does.

Apply for this role We reply to every applicant, usually within two working days.

About the role

You will join a small senior crew embedded inside a client organisation, usually a bank, telco, health system or energy operator. You will work in their repository, on their CI, in their on-call rotation. The systems are consequential and the constraints are real: regulatory scrutiny, legacy integration, and a business that cannot tolerate a bad release.

You will work as part of the delivery crew rather than as an external auditor. That means finding real issues early, explaining them in terms the team can act on, and helping fix them — not producing a report that nobody reads.

The team you join

You will work inside the delivery crew rather than as an outside auditor, with a line into the client's own security function.

What you will do

  • Threat model new services and integrations before they are built.
  • Review code and infrastructure for security weaknesses, and pair on the fixes.
  • Run and interpret security testing against applications and APIs.
  • Advise on authentication, authorisation, secrets handling and data protection.
  • Help teams meet regulatory security obligations without theatre.

Minimum qualifications

  • Four or more years in application or infrastructure security.
  • Hands-on testing ability, not only policy and compliance knowledge.
  • The ability to read code in at least one mainstream language.
  • Clear written communication: a finding nobody understands is not fixed.
  • Judgement about severity, so the team spends effort where it matters.

Preferred qualifications

  • Experience with NDPR, GDPR or PCI-DSS obligations.
  • Cloud security experience, particularly AWS or Azure.
  • Recognised certification such as OSCP, CISSP or equivalent practical evidence.

Your first three months

  1. Threat model the system as it actually is, not as documented.
  2. Land the first set of fixes yourself, pairing with the engineers.
  3. Establish which risks are accepted and by whom, in writing.
  4. By month three, be consulted before designs are agreed rather than after.

Compensation and benefits

Rates are agreed per engagement and depend on scope and seniority. We discuss numbers openly on the first call, before you spend time on a practical.

  • Rates are agreed per engagement and discussed openly on the first call, before you spend time on a practical.
  • Remote across Africa, with on-site weeks where the engagement calls for them.
  • Work embedded inside regulated institutions, on systems with real consequences, alongside senior engineers who review your work and expect you to review theirs.
  • Small crews and direct access to partners, with no layers between you and the decisions.
  • Long relationships. We would rather work with the same capable people across engagements than hire for a single project.
  • Straight answers. We tell you what we can and cannot offer before you commit, and we do not promise what we cannot deliver.

How we interview

The whole process is normally two to three weeks, and we work around your current job.

  1. Application review. A partner reads every application. You hear back either way, usually within two working days.
  2. Intro call, 45 minutes. Your background, what you want next, and honest answers about the work, the rate and the constraints.
  3. Practical session, 4 to 6 hours. A realistic problem close to what the role actually involves, scheduled around you and sized to respect your time.
  4. Practical review, 60 minutes. We walk through what you built, why, and what you would change with more time.
  5. Partner conversation, 45 minutes. Scope, expectations, terms, and your questions.
  6. Decision, normally within two working days of the last conversation.

How to apply

Send an application through the form. A partner reads every one, and you will hear back either way. If you are unsure whether you qualify, apply anyway and say what you are unsure about.

We will tell you what we can and cannot offer before you commit to anything.

Apply for this role

OneCluster hires on the work you can do. We welcome applications regardless of gender, ethnicity, religion, disability, age, or where you went to school, and we will make reasonable adjustments at any stage of this process if you tell us what would help.