At a Glance
- Tasks: Join our Cyber Security team to protect vital data and enhance security measures.
- Company: Be part of DFTO, the government’s public sector rail owning group with a mission for unified operations.
- Benefits: Enjoy competitive salary, generous annual leave, and a solid pension scheme.
- Other info: Great opportunities for learning and networking within the industry.
- Why this job: Make a real impact in cyber security while working in a dynamic and evolving environment.
- Qualifications: Experience in IT or Cyber Security, with knowledge of security systems and protocols.
The predicted salary is between 58000 - 58000 £ per year.
About DFT Operator DFTO is the government’s public sector rail owning group. It aims to unify train operations under common public ownership, previously owned privately, in advance of the creation of Great British Railways in 2027. DFTO runs more than 8,500 services a day and delivers over 640 million customer journeys each year, employing over 30,000 people.
Primary Purpose of the Job
As part of the Cyber Security team, the role supports maintaining the security and integrity of all company data (customer, employee, corporate and financial) by analysing security measures and determining their effectiveness against industry standards. The role identifies and recommends changes to improve cyber security, working with DFTO colleagues, Operator TOC’s and external stakeholders to communicate specific measures that can improve the company’s overall security posture. It manages and ensures security solutions stay up to date, creates documentation, and supports the definition and implementation of security related processes and plans, including incident response and disaster recovery plans. Responsible for generating reports for the Cyber Security team and the wider business to evaluate the efficiency of cyber security policies in place.
Key Responsibilities
- In support to the Group Head of Cyber Security, develop relevant cyber security dashboards that provide a view of DFTO specifically, TOC cyber security metrics and an overall DFTO Group cyber security posture.
- Monitor the performance of network, system and application security solutions across the DFTO Group to identify and bring to attention breaches and potential intrusion incidents using software that detects intrusions and anomalous system behaviour.
- Forensically investigate security breaches within a defined area of responsibility to maintain compliance with internal security policies.
- If appropriate, liaise with authorities to support breach investigation and any legal process as a consequence.
- Analyse security breaches to identify the root cause, ensuring remediation activities are undertaken to protect the DFTO Group networks, data and information as required.
- Lead the day-to-day business information security requests, investigating routine security related incidents, such as malware detections, DLP violations and phishing emails and provide general cyber security support.
- Produce comprehensive reports including assessment based findings, outcomes and propositions for current security effectiveness and further system security enhancement.
- Develop and carry out information security plans, policies and procedures.
- Monitor use of security products, data encryption and other security products and procedures.
- Ensure appropriate administrative, physical and technical safeguards are up to date to protect information assets from internal and external threats such as OS patches, AV and DLP.
- Review IDS, log files for legal and regulatory compliance to detect security events and suspicious behaviour.
Group Focussed Activities
- Serve as a point of expert advice and contact for all Operators across the DFTO Group, providing support to TOCs across the group and working in a collegiate manner with local cyber analysts as appropriate.
- Be the point of contact for DFTO TOC Analyst activity.
- Work with local TOC Analysts as needed to identify, mitigate and remediate local risks and incidents to prevent wider spread across the DFTO group of Operators.
- Manage the shared cyber incident documentation portal, identify common risk, articulate those risks and likelihood of exploit, and mitigation required to the Cyber Security Governance, Risk and Compliance Manager.
Key Competencies
- Understanding of database and operating system security.
- Understanding of the latest security principles, techniques and protocols.
- Understanding of network and endpoint security solutions.
- Basic knowledge of compliance with ISO27001, PCI DSS, GDPR and other security standards.
- Effective team player experienced at dealing at all levels with influencing and negotiating skills.
- Ability to form constructive and proactive working relationships at all levels with stakeholders, whether DFTO (including TOCs), Network Rail or external stakeholders.
- Effective interpersonal skills and an ability to use influence to gain buy‑in to enable change to happen through others.
- A drive to deliver tangible outcomes that meet business requirements.
- Thrives with accountability and responsibility and is self‑reliant.
- Ability to work well under pressure in a rapidly evolving environment.
Knowledge, Skills, Experience and Technical Qualifications
- Current experience in an IT role, preferably within Information or Cyber Security.
- Hands‑on experience in security systems such as firewalls, intrusion detection systems, anti‑virus software, authentication systems and log management.
- Sound technical background in current Microsoft Active Directory, VMWare, server and PC standard builds, configuration concepts and technologies ideally to certification level.
- Experience with system, security and network monitoring tools.
- Recognised industry security certification such as CISMP, CompTIA CySA+, Security+ or equivalent is desirable.
- Experience providing written and verbal presentations across all levels of a company.
- Demonstrated knowledge and understanding of basic financial and technical information.
- Hands‑on experience of problem‑solving and the ability to stay calm under pressure.
- ITIL Foundation certification desirable.
This role reports to the Group Head of Cyber Security, and will work closely with DFTO business units and external TOC stakeholders. The postholder will provide essential support to colleagues and will be working at the core in shaping DFTO’s IT security landscape as the organisation expands its public ownership footprint and delivers secured services across the Group.
Vacancy Details
- Duration: Permanent
- Location: London Waterloo/Hybrid
- Salary: up to £58,000
- Closing date: 2nd June 2026
- Reports To: Head of Cyber Security.
DFTO Benefits
- Annual Leave: Starting at 25 days and rising to an additional day per year of service completed within the first five years up to a maximum of 30 days.
- DC Pension Scheme: 10% Employer contribution, 5% Employee contribution.
- Opportunities to learn and network across the wider industry.
Contact
If you have any questions or require reasonable adjustments, please contact Jason.blakemore@dftoperator.co.uk
Cyber Security Analyst employer: DfT Operator
DFT Operator is an exceptional employer, offering a dynamic work environment in the heart of London Waterloo, where you can contribute to the future of public rail ownership. With a strong focus on employee growth, competitive benefits including generous annual leave and a robust pension scheme, and opportunities to collaborate with industry experts, DFTO fosters a culture of innovation and accountability. Join us to play a pivotal role in enhancing cyber security across our extensive network while enjoying a supportive and inclusive workplace.
StudySmarter Expert Advice🤫
We think this is how you could land Cyber Security Analyst
✨Tip Number 1
Network, network, network! Get out there and connect with people in the cyber security field. Attend industry events, join online forums, and don’t be shy about reaching out to professionals on LinkedIn. You never know who might have a lead on your dream job!
✨Tip Number 2
Show off your skills! Create a portfolio or GitHub repository showcasing your projects, especially those related to cyber security. This gives potential employers a tangible look at what you can do and sets you apart from the crowd.
✨Tip Number 3
Prepare for interviews like a pro! Research common cyber security interview questions and practice your responses. Be ready to discuss your experience with security systems and how you’ve handled incidents in the past. Confidence is key!
✨Tip Number 4
Apply through our website! We’re always on the lookout for talented individuals to join our team. Keep an eye on our careers page for openings and make sure to tailor your application to highlight your relevant skills and experiences.
We think you need these skills to ace Cyber Security Analyst
Some tips for your application 🫡
Tailor Your CV:Make sure your CV is tailored to the Cyber Security Analyst role. Highlight relevant experience and skills that match the job description, like your knowledge of security principles and hands-on experience with security systems.
Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you're passionate about cyber security and how your background makes you a great fit for DFTO. Don’t forget to mention any specific projects or achievements that relate to the role.
Showcase Your Technical Skills:In your application, be sure to showcase your technical skills, especially those mentioned in the job description like experience with firewalls and intrusion detection systems. This will help us see how you can contribute to our team right away.
Apply Through Our Website:We encourage you to apply through our website for a smoother process. It helps us keep track of your application and ensures you don’t miss out on any important updates from us!
How to prepare for a job interview at DfT Operator
✨Know Your Cyber Security Basics
Before the interview, brush up on your knowledge of key cyber security principles, techniques, and protocols. Be ready to discuss how you would apply these in real-world scenarios, especially in relation to the specific security measures DFTO employs.
✨Showcase Your Technical Skills
Prepare to talk about your hands-on experience with security systems like firewalls and intrusion detection systems. Bring examples of how you've used these tools to identify and mitigate risks in previous roles, as this will demonstrate your practical knowledge.
✨Understand the Company’s Mission
Familiarise yourself with DFTO's goals and the importance of cyber security in achieving them. Being able to articulate how your role as a Cyber Security Analyst can contribute to the overall security posture of the organisation will set you apart from other candidates.
✨Prepare for Scenario-Based Questions
Expect questions that ask you to solve hypothetical security incidents or breaches. Practice articulating your thought process clearly and logically, as this will showcase your problem-solving skills and ability to stay calm under pressure.