Cyber Resilience Testing Lead in Reading

Cyber Resilience Testing Lead in Reading

Reading Full-Time 68000 - 78000 £ / year (est.) No working from home possible
C

At a Glance

  • Tasks: Lead cyber resilience testing and vulnerability management for IT and OT environments.
  • Company: Join Thames Water's dynamic Information Security team.
  • Benefits: Competitive salary, generous leave, pension scheme, and wellness benefits.
  • Other info: Hybrid working model with excellent career growth opportunities.
  • Why this job: Make a real impact on cybersecurity while developing your skills in a supportive environment.
  • Qualifications: Experience in cybersecurity and vulnerability management is essential.

The predicted salary is between 68000 - 78000 £ per year.

As a Cyber Resilience Testing Lead, you will play a key role within the Information Security team at Thames Water, supporting the Head of Cyber Resilience in delivering technical cyber resilience testing and vulnerability management activities across both IT and OT environments. Working closely with cybersecurity leadership, service owners, and technical teams, you will help ensure vulnerabilities are effectively identified, assessed, remediated, and evidenced across the organisation. This role contributes to Thames Water’s cyber resilience programme by providing technical assurance of defensive capabilities, supporting resilience testing initiatives, and ensuring vulnerability management processes are robust and effective. You will collaborate with stakeholders across the business to ensure testing and remediation activities are executed efficiently while maintaining high standards of documentation, reporting, and governance.

Security Clearance: CTC (Counter Terrorist Check) clearance is essential. You must currently hold or be able to attain CTC clearance for this role.

What you’ll be doing:

  • Lead the technical validation of vulnerabilities, including severity assessment, exploitability analysis, and business impact evaluation across IT and OT environments.
  • Perform advanced triage of vulnerabilities using industry-standard methodologies such as CVSS.
  • Act as the technical escalation point for complex or disputed remediation plans, advising on compensating controls and risk acceptance.
  • Maintain and update the central vulnerability register, ensuring accurate tracking from identification through to remediation.
  • Assign ownership of vulnerabilities and track remediation progress to completion.
  • Collect and validate remediation evidence, ensuring audit-ready documentation.
  • Prepare reports and dashboards to support oversight by Cyber Resilience leadership.
  • Design and maintain the annual penetration testing and red/purple team testing schedule.
  • Review and validate testing outputs, including exploit paths and findings, ensuring technical accuracy.
  • Translate testing findings into actionable remediation plans in collaboration with SOC, architecture, engineering, and OT teams.
  • Support the coordination of penetration testing, red/purple teaming, and cyber stress testing activities.
  • Provide subject matter expertise during cyber incidents, supporting technical investigation and response.
  • Maintain readiness for regulatory compliance, ensuring testing and vulnerability evidence meets audit requirements.
  • Support broader cyber resilience initiatives through operational and administrative activities.
  • Maintain accurate records and contribute to reporting and regulatory submissions.

Base location: Hybrid – Clearwater Court, Reading. Working pattern: 36 hours Monday to Friday.

What you should bring to the role:

  • Experience in cybersecurity, vulnerability management, or related technical security roles.
  • Strong understanding of offensive security methodologies, including MITRE ATT&CK.
  • Ability to analyse penetration testing reports in depth and translate findings into control improvements.
  • Experience tracking vulnerability remediation and coordinating with stakeholders to ensure timely resolution.
  • Experience working within critical infrastructure, utilities, or public sector environments.
  • Strong organisational skills with the ability to manage multiple priorities and maintain accurate records.
  • Excellent communication and interpersonal skills to engage technical and non-technical stakeholders.
  • Ability to build strong working relationships and operate as a self-starter.

Technical experience and skills:

  • Familiarity with vulnerability management tools such as ServiceNow, Tenable, or similar platforms.
  • Knowledge of cybersecurity frameworks and standards such as ISO 27001, NIST, and CIS Controls.
  • Proficiency in reporting and data analysis tools such as Excel, Power BI, or equivalent.
  • Ability to validate vulnerabilities, interpret testing results, and support remediation planning.

Desirable qualifications and experience:

  • Broader knowledge and experience within cybersecurity or information security.
  • Experience with ICT/OT security testing, including PLCs, HMIs, and industrial protocols such as Modbus, DNP3, and OPC-UA.
  • Experience producing technical dashboards reflecting vulnerability management and resilience maturity.
  • Experience working with vendors or delivery partners on testing or remediation activities.
  • Experience supporting penetration testing, red/purple teaming, or cyber stress testing programmes.
  • Experience supporting regulatory compliance aligned to industry standards (e.g., SEMD, CAF).

Desirable technical skills and qualifications:

  • Bachelor’s degree in Computer Science, IT, Cyber Security, or a related field (or equivalent experience).
  • Professional certifications such as CompTIA Security+, CySA+, or similar (CISSP/CISM desirable but not essential).

What’s in it for you?

  • Competitive salary between £68,000 and £78,000 per annum, depending on experience.
  • Annual Leave – 26 days holiday per year, increasing to 30 with the length of service. (plus bank holidays)
  • Generous Pension Scheme through AON.
  • Performance-related pay plan directly linked to company performance measures and targets.
  • Access to lots of benefits to help you take care of you and your family’s health and wellbeing, and your finances – from annual health MOTs and access to physiotherapy and counselling, to Cycle to Work schemes, shopping vouchers, and life assurance.

Cyber Resilience Testing Lead in Reading employer: Cyber UK

Thames Water is an exceptional employer, offering a dynamic work environment that prioritises employee growth and well-being. As a Cyber Resilience Testing Lead, you will benefit from a competitive salary, generous annual leave, and a robust pension scheme, all while contributing to critical cyber resilience initiatives in a supportive and collaborative culture. With opportunities for professional development and a focus on maintaining high standards of security, Thames Water is committed to fostering a rewarding career path for its employees.

C

Contact Details:

Cyber UK Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Cyber Resilience Testing Lead in Reading

Tip Number 1

Network like a pro! Reach out to folks in the cybersecurity field, especially those at Thames Water. Use LinkedIn or industry events to connect and chat about your passion for cyber resilience. You never know who might have the inside scoop on job openings!

Tip Number 2

Prepare for interviews by brushing up on your technical skills. Be ready to discuss vulnerability management and offensive security methodologies. Practise explaining complex concepts in simple terms – it shows you can communicate with both techies and non-techies!

Tip Number 3

Showcase your experience with real-world examples. When discussing your past roles, highlight specific projects where you led vulnerability assessments or collaborated with teams on remediation plans. This will demonstrate your hands-on expertise and problem-solving skills.

Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets noticed. Plus, it shows you’re genuinely interested in joining the team at Thames Water. Let’s get you that Cyber Resilience Testing Lead role!

We think you need these skills to ace Cyber Resilience Testing Lead in Reading

Cybersecurity
Vulnerability Management
Technical Assurance
Penetration Testing
Red/Purple Team Testing
Exploitability Analysis
Risk Assessment

Some tips for your application 🫡

Tailor Your CV:Make sure your CV is tailored to the Cyber Resilience Testing Lead role. Highlight your experience in cybersecurity and vulnerability management, and don’t forget to mention any relevant tools or methodologies you’ve used.

Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you're the perfect fit for this role. Mention specific experiences that align with the job description and show your enthusiasm for working with Thames Water.

Showcase Your Technical Skills:In your application, be sure to showcase your technical skills and experience with vulnerability management tools. Mention any certifications you hold and how they relate to the responsibilities of the role.

Apply Through Our Website:We encourage you to apply through our website for a smoother application process. It’s the best way to ensure your application gets the attention it deserves!

How to prepare for a job interview at Cyber UK

Know Your Cybersecurity Stuff

Make sure you brush up on your knowledge of offensive security methodologies, especially MITRE ATT&CK. Be ready to discuss how you've applied these in past roles, particularly in vulnerability management and remediation.

Showcase Your Communication Skills

As a Cyber Resilience Testing Lead, you'll need to engage with both technical and non-technical stakeholders. Prepare examples of how you've successfully communicated complex technical information in an understandable way.

Demonstrate Your Organisational Skills

Be prepared to talk about how you manage multiple priorities and keep accurate records. Share specific instances where your organisational skills led to successful outcomes in vulnerability tracking or remediation efforts.

Familiarise Yourself with Tools and Frameworks

Get comfortable with the tools mentioned in the job description, like ServiceNow and Tenable. Also, be ready to discuss cybersecurity frameworks such as ISO 27001 and NIST, and how you've used them in your previous roles.