At a Glance
- Tasks: Lead the design and implementation of cyber security solutions to protect our rail services.
- Company: Join DFTO, the government’s public sector rail owning group with over 30,000 employees.
- Benefits: Enjoy a competitive salary, generous annual leave, and a strong pension scheme.
- Other info: Hybrid working available with excellent career growth opportunities.
- Why this job: Make a real impact on national rail security while working with cutting-edge technologies.
- Qualifications: Degree level education and significant experience in cyber security required.
The predicted salary is between 70000 - 70000 € per year.
About DFT Operator
DFTO is the government’s public sector rail owning group. Its purpose is to bring all currently privately-owned train operators into public ownership in advance of the creation of Great British Railways in 2027 – and deliver improvements in the here and now by unifying and integrating train operations under common public ownership. DFTO has over 30,000 employees, runs over 8,500 services a day and delivers over 640 million customer journeys across its networks every year. Major improvements are being delivered by DFTO train operators (TOCs) that are already under public ownership – these are LNER, Northern, TransPennine Express (TPE), Southern, South Western Railway (SWR), c2c, Greater Anglia and WM Trains. We work closely with the DfT but operate independently with our own governance and leadership teams. Our priority is ensuring efficient, dependable rail services for everyone.
Primary Purpose of Job
This role is responsible for leading the design, implementation, continual improvement and monitoring of cyber security solutions across DFTO and supporting Group Operators to protect the business from security threat whilst adhering to industry cyber security standards. As a subject matter expert in multiple cyber security technologies the post holder will be responsible for the management, maintenance and improvement of cyber security across multiple platforms, networks and applications. The key focus being to ensure the DFTO Group is protected from cyber and information security risk. The post holder will act as a point of contact for the cyber security technical teams across the DFTO Group as well as being responsible for supporting central DTFO colleagues. This position will ensure robust, scalable, and high-quality IT services that support the DFTO group’s strategic objectives.
Key Responsibilities
- Support the DFTO Group Head of Cyber Security to oversee the delivery and support of cyber security applications and platforms.
- Manage the continued review, research, and development of current security controls, ensuring their effectiveness and efficiency.
- Contribute to the Cyber Security Risk Register working with business and solution owners to identify, mitigate, treat and remediate risk in accordance with the DFTO Group risk appetite, ensuring alignment to industry best practice.
- Proactively identify weaknesses in hardware, software and applications through vulnerability assessments, penetration testing, and managing any required remediation processes.
- Providing security patch deployment methodologies to all core infrastructures.
- Monitor networks and systems for critical security breaches, using software that detects intrusions and anomalous system behaviour.
- Ensures cyber security requirements are met and service quality maintained when introducing new security services.
- Provide expert technical guidance when developing and carry out information security plans, policies and procedures.
- Manage the technical installation and monitoring use of security products, including data encryption and other security products and procedures.
- Actively ensure appropriate administrative, physical and technical up to date safeguards are in place to protect information assets from internal and external threats e.g. vulnerability patching, AV, Firewalls, DLP.
- Participate in peer reviews of deliverables and carries out formal and informal reviews of technical designs, standards, documentation and/or implementations.
- Lead cyber security projects as assigned, following a recognised methodology, through specification, testing, implementation and documentation, including ongoing support strategy.
- Provide expert technical guidance across the DFTO Group when investigating security breaches.
- Provide support for any incident response, including steps to minimize the impact and then conducting a technical and forensic investigation into how the breach happened and the extent of the damage.
- Manage the development of technical solutions and new security tools to help mitigate security vulnerabilities and automate repeatable tasks.
- Produce comprehensive reports including assessment-based findings, outcomes and propositions for current security effectiveness and further system security enhancement.
- Support awareness training on cyber security standards, policies and best practices.
Key Competencies
- Detailed technical knowledge of application and operating system security.
- Thorough understanding of the latest security principles, techniques, and protocols.
- A deep understanding and best practice mitigation of current OWASP Top Ten Risks (and remain current as these change).
- Strong understanding of network and endpoint security solutions, including File Integrity Monitoring, Data Loss Prevention, and Data Encryption.
- Knowledge of achieving and maintaining compliance with the ISO27001, GDPR, Cybersecurity and other security Standards.
- Effective team player experienced at dealing at all levels with effective influencing and negotiating skills.
- Ability to form constructive and proactive working relationships at all levels with all stakeholders whether internal or external.
- Good project management skills: able to demonstrate ability to deliver projects to time, budget and objectives in partnership with stakeholders.
- Good communications and presentation skills both verbal and written.
- Good level of numeracy and sound analytical skills, problem-solving skills and ability to stay calm under pressure.
- Thrives with accountability and responsibility and is self-reliant.
- An ability to work well under pressure in a rapidly evolving environment.
Knowledge, Skills, Experience & Technical Qualifications
- Educated to degree level or equivalent.
- Significant current experience in a Cyber Security Technical Support role, that includes relevant experience in information security.
- Recognised industry security certification such as CISSP, SSCP, CEH, Security+, CASP+ or equivalent.
- Proven technical background well versed in current Microsoft Products (including Server and workstation OS, Active Directory, Office 365 and Azure), Endpoint Protection technologies, AWS cloud solutions and Email security systems.
- Proven work experience as a system security engineer or information security engineer with experience of successfully leading technical evaluations and project management of new Information Security solutions.
- Experience in building and maintaining security systems.
- Hands on experience in security systems, including firewalls, intrusion detection systems, anti-virus software, authentication systems, log management, content filtering, etc.
This role reports to the Group Head of Cyber Security and will work closely with DFTO Cyber/Information Security colleagues across business units and external TOC stakeholders. The postholder will work at the core in shaping DFTO’s IT security landscape as the organisation expands its public ownership footprint and delivers secured services across the Group.
Vacancy Details
- Duration: Permanent
- Location: London Waterloo/Hybrid
- Salary: up to £70,000
- Closing date: 2nd June 2026
- Report To: Head of Cyber Security
DFTO Benefits
- Annual Leave: Starting at 25 days and rising to an additional day per year of service completed within the first 5 completed years up to a maximum of 5 additional (30 days).
- DC Pension Scheme: 10% Employer contribution, 5% Employee contribution.
- Opportunities to learn and network across the wider industry.
Additional Information
Disclaimer: Candidates applying for this position on a secondment basis must inform their line manager prior to submitting their application. This is to ensure transparency and facilitate any necessary discussions regarding workload and responsibilities.
Contact: For reasonable adjustments, please contact Jason.blakemore@dftoperator.co.uk
Cyber Security Engineer employer: DfT Operator
DFT Operator is an exceptional employer, offering a dynamic work environment in the heart of London Waterloo, where you can contribute to the future of public rail services. With a commitment to employee growth, DFTO provides extensive training opportunities, a generous benefits package including up to 30 days of annual leave and a robust pension scheme, and a collaborative culture that values innovation and teamwork. Join us in shaping a secure and efficient rail network while enjoying the unique advantages of working within a pivotal government organisation dedicated to public service.
StudySmarter Expert Advice🤫
We think this is how you could land Cyber Security Engineer
✨Tip Number 1
Network like a pro! Get out there and connect with people in the cyber security field. Attend industry events, join online forums, or even hit up LinkedIn. The more people you know, the better your chances of landing that dream job!
✨Tip Number 2
Show off your skills! Create a portfolio showcasing your projects, certifications, and any relevant experience. This is your chance to shine and demonstrate what you can bring to the table. Don’t forget to include any hands-on work with security systems!
✨Tip Number 3
Prepare for interviews like it’s game day! Research DFTO and understand their mission and values. Be ready to discuss how your skills align with their needs, especially around cyber security solutions. Practice common interview questions to boost your confidence.
✨Tip Number 4
Apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, you’ll be one step closer to joining a team that’s making a real difference in public rail services. Don’t miss out on this opportunity!
We think you need these skills to ace Cyber Security Engineer
Some tips for your application 🫡
Tailor Your CV:Make sure your CV is tailored to the Cyber Security Engineer role. Highlight your relevant experience and skills that match the job description, especially your knowledge of security principles and technologies.
Craft a Compelling Cover Letter:Your cover letter should tell us why you're the perfect fit for this role. Share specific examples of your past achievements in cyber security and how they align with our mission at DFTO.
Showcase Your Technical Skills:Don’t forget to list your technical qualifications and certifications clearly. We want to see your expertise in areas like network security, compliance standards, and any relevant tools you've worked with.
Apply Through Our Website:For the best chance of success, make sure you apply through our website. This way, your application will go directly to us, and we can review it promptly!
How to prepare for a job interview at DfT Operator
✨Know Your Cyber Security Basics
Before the interview, brush up on your knowledge of key cyber security principles and protocols. Be ready to discuss the latest trends in security, such as the OWASP Top Ten Risks, and how they apply to the role. This shows you’re not just familiar with the basics but also engaged with current developments in the field.
✨Demonstrate Problem-Solving Skills
Prepare to share specific examples of how you've identified and mitigated security risks in previous roles. Use the STAR method (Situation, Task, Action, Result) to structure your answers. This will help you illustrate your analytical skills and ability to stay calm under pressure, which are crucial for a Cyber Security Engineer.
✨Familiarise Yourself with DFTO's Mission
Understand DFTO’s goals and how cyber security fits into their mission of improving rail services. Be ready to discuss how your expertise can contribute to their objectives, especially in protecting sensitive information and ensuring compliance with industry standards like ISO27001 and GDPR.
✨Ask Insightful Questions
Prepare thoughtful questions about the team dynamics, current challenges in cyber security at DFTO, and how success is measured in this role. This not only shows your interest in the position but also helps you gauge if the company culture aligns with your values and work style.