Discover the importance of Annaizu Compliance Management in today's business landscape and how a Home Office compliance management platform can help your business streamline its compliance efforts, reduce risks, and stay ahead of regulations.
Cyber Security Professionals sponsored under SOC code 2135 protect an organisation's systems and data — spanning threat analysis, incident response, penetration testing and security architecture — and the code covers a genuinely wide range of seniority and specialism, which makes getting the salary and job description right more important than for narrower occupations.
One code, several very different jobs
A junior SOC analyst monitoring alerts and a principal security architect designing controls for a whole estate can both sit under 2135, but the going rate and realistic salary for each are worlds apart. Sponsors should benchmark against the actual seniority of the post rather than the occupation code's minimum, since underpricing a specialist role against market rate is itself a genuineness flag — check current figures on the going rates page and the general salary floor guide before setting the Certificate of Sponsorship figure.
Genuinely entry-level monitoring roles need care
The reverse mismatch is worth watching for too. SOC 2135 sits among the professional IT occupations, and the code assumes duties working at that level of complexity — analysis, judgement, escalation decisions — not purely routine, script-driven alert triage that a first-line support role could equally describe. A tier-1 SOC analyst job description that is really 'watch a dashboard and forward anything red' sits uncomfortably under a professional occupation code, and it is worth checking the role's actual duties against the current entry on GOV.UK's eligible occupations and codes list before assuming any cyber job title qualifies.
Certifications, clearance and immigration checks are separate processes
Industry certifications such as CISSP or CEH, and any security clearance vetting, are employer or client requirements rather than Home Office eligibility criteria, and neither substitutes for the standard right-to-work check every sponsor still owes every worker on day one — done through a share code, not inferred from a clearance level, as covered in the share codes guide.
When vetting timelines collide with visa timelines
Security clearance processes such as SC or DV vetting can take considerably longer than a visa application, and it is tempting to treat a candidate as effectively cleared to start once vetting is 'in progress'. Right to work doesn't work that way — the share code check has to be completed, and valid permission to work confirmed, before the person's first day, entirely independently of where their clearance sits. Sponsors running both processes in parallel should track them separately rather than letting a slow clearance decision quietly push back or blur the date the right-to-work check was actually done.
Contractor, secondment and agency-style engagement patterns
Cyber security work is often delivered through short, high-intensity engagements or secondments between client sites, which can look more like temporary working than standard employment. Where that's genuinely the case, sponsors should check whether the temporary worker route fits better than a standard Skilled Worker sponsorship, rather than stretching one licence category to cover a different working pattern. A related trap is the security consultancy that effectively places sponsored staff with end clients through a chain of contracts — Skilled Worker sponsorship requires a genuine employer-employee relationship with the sponsor itself, and an arrangement that looks more like supplying labour to a third party who actually directs the day-to-day work can fall outside what the licence permits, regardless of how the contract is worded.
Remote and follow-the-sun security operations
Many security operations centres run around the clock across time zones, with UK-based staff handing off to overseas colleagues and working shift patterns that don't map neatly onto a standard nine-to-five. None of that affects eligibility on its own, but sponsors should keep records showing the sponsored worker's actual UK-based work location and shift pattern, particularly where duties are performed partly from home — a normal work location that shifts materially from what was declared when the Certificate of Sponsorship was assigned is the kind of change worth tracking rather than assuming is immaterial.
Progression within the same code doesn't need a new job, but does need a look at pay
Cyber security careers often progress quickly — a SOC analyst can move into threat hunting or incident response leadership within a couple of years, still comfortably inside SOC 2135 the whole time. Because the code doesn't change, it's easy to assume nothing needs revisiting, but the going rate is tied to the seniority and duties of the actual post, not the code number, so a significant promotion is a natural trigger to check that pay has kept pace with what a role at that new level should be earning, alongside the standard salary floor. This matters most at renewal, when the Certificate of Sponsorship is reissued and the salary figure gets a fresh look against current rates rather than simply being carried forward from the original grant.
FAQs
Do penetration testers and SOC analysts use the same code? Both commonly fall under 2135, but confirm against the current list — GOV.UK's eligible occupations and codes page is the authoritative source, not a job title alone.
Should security clearance documents be kept in the same file as immigration records? Keep them separately but both securely — a system built for secure document management can hold both without mixing sensitive vetting material into the sponsorship compliance file a Home Office officer would review.
What about candidates who previously came through the Global Talent route? Global Talent and Skilled Worker are separate routes with different eligibility criteria and no automatic read-across; a cyber professional switching from Global Talent to sponsored employment still needs the role properly assessed against SOC 2135 and the current going rate on its own terms.
Does on-call or incident-response standby pay count towards the salary threshold? Guaranteed, contractual pay is generally what counts; ad hoc or discretionary on-call payments are less likely to, so it's worth checking which elements of a cyber professional's package are structured as guaranteed pay before relying on them to clear the threshold.

