Defence recruitment sits at an awkward intersection of two things that most ATS vendors haven't tried to reconcile: the need for detailed candidate data and the need to not store certain candidate data in a commercial cloud system. Add security clearance tracking, nationality restrictions, MOD framework compliance, and the requirement to handle mandates you sometimes can't describe in writing, and you have a sector that has been running on workarounds for years because no platform was built with it in mind.
This is a guide for recruiters and search firms working in UK defence and security: placing Programme Directors at Babcock, Chief Engineers at BAE Systems, Security Architects at DSTL, or building the contract desk for a Serco MOD framework appointment. The requirements vary significantly by role level and engagement type. Let's go through what actually matters.
The Scale of the Market (and Why It Matters for Software)
UK defence employs around 230,000 people directly, with an estimated 400,000 in the wider supply chain according to figures from the Defence & Security Accelerator and DSEI sector reports. That's a large, stable, mostly non-cyclical hiring market with specific needs. It's also a market where a mistake in the hiring process isn't just an HR inconvenience. A vetting failure or a nationality screening error on a sensitive contract has regulatory and potentially national security consequences.
The employer landscape is a mix of direct MOD civilian roles, large prime contractors (BAE Systems, Babcock, Qinetiq, Leonardo, Rolls-Royce Defence, Thales UK), Tier 2 and 3 supply chain businesses, and managed services contractors including Serco, Capita Defence, and Leidos. Framework recruiters operating under Crown Commercial Service agreements sit across all of these.
The executive search piece is different again. Placing a Head of Cyber at DSTL, a Programme Director on a maritime programme, or a Defence Attache-equivalent in a defence-adjacent consultancy requires a very different process from filling a framework body-shopping contract. Both need specialist software, but for completely different reasons.
Security Clearance Levels: What Recruiters Actually Need to Track
The UK national security vetting system has four levels. Most recruiters know this in broad terms, but the tracking requirements at each level are what matter for software.
BPSS, Baseline Personnel Security Standard, is the floor. It's mandatory for all government employees and most MOD contractors before they access any government site. It covers identity verification, right to work, employment history going back three years, and basic criminal record check. Every candidate in a defence pipeline needs their BPSS status tracked. It's surprisingly often the thing that delays a start date when it's not managed proactively.
Counter Terrorism Check (CTC) is the next level, required for roles with access to information assets that could be exploited by terrorist groups or for roles in close proximity to public figures. The vetting covers the past five years of financial, employment, and personal history.
Security Check (SC) is what most defence contractors think of as "standard" clearance. It covers the past ten years and is required for regular, unsupervised access to SECRET material. Many contract roles in defence programmes specify SC as a baseline requirement. SC takes anywhere from four weeks to six months depending on case complexity and UKSV workload.
Developed Vetting is the highest level, required for access to TOP SECRET material and certain extremely sensitive roles. The government's DV guidance describes a process that includes a full lifestyle check, financial scrutiny, and interviews with the candidate and people who know them. DV takes six to twelve months typically, sometimes longer. Candidates with existing DV are a genuinely scarce resource in the market.
What does a recruitment platform need to track for each of these? At minimum: clearance level held, sponsoring department or employer, issue date, whether it's current or lapsed, and any notes on transferability. That last point matters. Clearances don't automatically transfer between sponsors. A candidate with SC sponsored by DSTL isn't automatically clearable for a BAE Systems programme without the sponsoring department agreeing to transfer.
Almost no generic ATS has these fields natively. They have a text note area, and recruiters build informal conventions for recording clearance status in candidate names or custom tags. This works until someone leaves the desk and the conventions aren't documented anywhere.
The Confidentiality Problem Most Platforms Ignore
Here's a scenario that comes up regularly in defence executive search: you're managing a mandate for a senior role at a classified programme. You can't describe the role in full in your ATS because the role itself is partially classified. The candidates you're approaching are known to you personally, their clearance status is confirmed, but you can't store their full candidate profile in a commercial cloud system because the client has restrictions on third-party data storage for cleared staff.
This puts defence recruiters in a position where the ATS can only hold a partial record, with the sensitive parts managed offline. The system becomes a contact management tool for the non-sensitive data, with a separate (often paper or encrypted local file) process for the rest.
No commercial recruitment platform solves this completely. The best you can do is a system that acknowledges the constraint: one where you can create a candidate record with limited fields visible, mark records as restricted, and manage the workflow without forcing all data into a single cloud repository.
Platforms that store everything in a US-jurisdiction cloud create an additional problem for certain defence programmes: some contracts explicitly prohibit candidate data being stored by non-UK entities. EU GDPR and UK GDPR both apply to the candidate data itself, but the programme-level data restrictions can go further. This is worth asking your ATS vendor directly: where are your servers, who can access data, and can you sign a DPA that reflects MOD contractor requirements?
Export Control and Nationality Restrictions
Export control is an area that trips up defence recruiters who haven't encountered it before. The UK Export Control Order 2008 (and its successor legislation post-Brexit) controls the export of controlled goods, software, and technology, including the technology involved in certain defence programmes. The US equivalent, ITAR (International Traffic in Arms Regulations), is equally relevant for any programme with US-origin technology or US prime contractor involvement.
What this means for recruitment: certain roles require candidates to hold specific nationality to avoid triggering export control restrictions. A role on an ITAR-controlled programme might specify "UK nationals only" or "UK and US nationals only." This isn't discrimination under the Equality Act because it's a legal requirement arising from the programme's export control obligations. But it needs to be screened and documented correctly in the recruitment process.
Most ATS platforms have a right-to-work field. Few have a nationality field that can be linked to specific programme requirements, with an audit trail showing that the nationality check was performed and the candidate was confirmed eligible for the specific role's export control restrictions. Recruiters end up managing this in notes or in a separate document, which creates gaps in the audit trail.
Crown Commercial Service Frameworks: How Framework Recruitment Actually Works
A significant proportion of defence staffing goes through Crown Commercial Service frameworks. The Technology Services framework (TS3), Digital Outcomes and Specialists (DOS), and various managed service agreements create a procurement structure where approved suppliers compete for task orders within a pre-negotiated commercial envelope.
For a recruitment agency operating on a CCS framework, the workflow is different from contingency or retained search. You're placing candidates against call-off contracts that have specific rate card constraints, IR35 status determinations (or outside-IR35 assessments), and defined deliverables. The ATS needs to track not just the candidate pipeline but the contract structure around each placement: which framework, which lot, which call-off, what rate, IR35 determination, contract start and end dates.
Framework recruitment at volume requires different software functionality from executive search at low volume. This is a genuine bifurcation in the market, and it's worth being clear about which side of it your business sits on.
What Bullhorn and Vincere Actually Offer
Bullhorn is widely used in the staffing and framework recruitment end of the defence market. Its volume management capability, time-and-materials tracking, and the compliance workflow tools it has built for the temporary staffing market make it functional for agencies running high-volume contract placements. It's not designed for clearance tracking, export control screening, or the confidentiality constraints around classified mandates, but for framework-based contingency staffing, it handles the core workflow.
Vincere is more CRM-led and better suited to search-style engagements. The candidate relationship management is stronger, the pipeline tracking is more configurable, and it handles retained search workflows better than Bullhorn does. The same gaps apply on clearance and compliance-specific features, but the underlying architecture is a better fit for boutique defence search firms doing retained work.
Neither platform has native clearance level fields with expiry tracking, sponsoring authority recording, or transferability notes. Both require customisation or workaround to handle the nationality and export control screening requirements. Both are cloud-based and store data in jurisdictions that may conflict with certain programme-level data restrictions.
The Executive Search Use Case
Defence executive search firms place senior people into programmes that have long lead times and high stakes. A Programme Director on a major defence acquisition might be hired 18 months before the programme enters full development. A Chief Systems Engineer on a naval platform might be the deciding factor in whether a bid team has the technical credibility to win a contract.
At this level, the candidates are known. They're part of a network that the search firm has built over years. The value isn't in finding names on a LinkedIn search, it's in knowing which Programme Director has the specific combination of MBDA missile system experience, senior stakeholder management credibility, and the right clearance level and sponsoring authority to move quickly into the role.
That means the software requirement is relationship-led CRM first, pipeline management second. A platform that maintains rich candidate histories across multiple mandates, tracks clearance status and history, and allows configurable compliance milestones to be attached to each search is the right fit. The volume is low. The depth per candidate is high.
Yena's architecture maps to this. The candidate record is the primary entity, with mandates and relationships connecting to it rather than the reverse. For a firm that places the same senior defence leader in three roles over ten years, and needs to see the full relationship history across all three engagements, this matters. See how Yena compares to Bullhorn if you're currently making this evaluation.
To be direct: Yena is for boutique search firms doing 8-20 retained executive searches per month in defence and security. It's not the right tool for a 50-person framework staffing agency running 200 active contractors through CCS agreements. Those businesses need different software, and Bullhorn or a specialist MSP platform is probably the right answer.
European Defence: NATO Suppliers and the European Defence Fund
UK defence recruitment has traditionally been focused on the domestic MOD market, but the European dimension has grown significantly. UK companies remain eligible for many NATO programme roles post-Brexit, and the European Defence Fund, established in 2021 with a budget of around €8 billion for 2021-2027, has created new programme structures with multinational contractor requirements.
Eurofighter programme management, MBDA missile system development, and OCCAR-managed programmes all involve candidate populations that move across UK, German, French, Italian, and Spanish contractors. Nationality requirements get complex when a programme involves multiple ITAR-related technology transfers across national boundaries.
For firms placing into multinational defence programmes, the software needs to handle multi-jurisdiction right-to-work verification, multiple clearance systems (not just UK national security vetting but equivalents in other NATO nations), and the ability to track candidate language requirements that are mandatory for programme documentation or client-facing roles.
Building a Compliant Process: What Needs to Be Documented
Regardless of which platform you use, the audit trail requirements in defence recruitment are non-negotiable. A placement that goes wrong, or a vetting failure that surfaces post-hire, will trigger a review of the recruitment process. You need to be able to demonstrate, with timestamps and records, that you conducted the screening you said you did.
The minimum documentation set for any defence executive placement should include: right to work verification (with document type and reference number), BPSS confirmation, clearance level verification with sponsoring authority details, nationality confirmation with export control eligibility note where required, references obtained with contact details, and any programme-specific vetting requirements relevant to the role.
A platform with configurable compliance checklists, where each item must be completed and dated before a candidate can move to offer stage, reduces the risk of a gap in your process. It also makes it much easier to demonstrate compliance if you're ever asked to.
The Practical Questions to Ask Any ATS Vendor
If you're evaluating software for a defence-focused practice, these are the questions that separate platforms that understand the market from ones that don't:
- Can you store clearance level, sponsoring authority, issue date, and expiry per candidate as structured fields, not just notes?
- Can you restrict visibility of specific candidate records or mandate details to named users only?
- Where is candidate data stored, and can you sign a DPA that covers MOD contractor data handling requirements?
- Can you build configurable compliance checklists that enforce a specific screening sequence before a candidate advances to offer?
- Does the platform maintain a full candidate relationship history across multiple mandates, showing all previous engagements, client feedback, and placement history?
- Can you track IR35 determinations and contract structure alongside candidate records for framework placements?
No platform currently answers all of these perfectly. The question is which gaps your specific business model can accommodate with a defined workaround, and which ones represent genuine process or compliance risk.
Placing senior defence and security executives on retained mandates?
Yena is built for boutique executive search firms where deep candidate relationship management and compliance milestone tracking matter more than volume throughput. Configurable screening checklists, full relationship history across mandates, and a candidate-first CRM architecture. Setup in under 24 hours.
Start Free Trial