At a Glance
- Tasks: Join our Cyber Security team to protect vital data and enhance security measures.
- Company: DFTO, a key player in the UK's rail industry, focused on public ownership.
- Benefits: Enjoy 25 days annual leave, a generous pension scheme, and opportunities for professional growth.
- Other info: Flexible working options available to support your work-life balance.
- Why this job: Make a real impact on national security while working with cutting-edge technology.
- Qualifications: Experience in IT or Cyber Security, with knowledge of security systems and protocols.
The predicted salary is between 58000 - 58000 € per year.
DFTO is the government’s public sector rail owning group. Its purpose is to bring all currently privately-owned train operators into public ownership in advance of the creation of Great British Railways in 2027 and deliver improvements in the here and now by unifying and integrating train operations under common public ownership. DFTO has over 30,000 employees, runs over 8,500 services a day and delivers over 640 million customer journeys across its networks every year.
As part of the Cyber Security team, this role will support maintaining the security and integrity of all company data (including customer, employee, corporate and financial) by analysing the security measures of the business and determining how effective they are compared to industry standards. The role will identify and recommend changes that will improve cyber security by working with DFTO colleagues, Operator TOC’s and external stakeholders to communicate specific measures that can improve the company’s overall security posture.
The role will manage and take responsibility for keeping defined security solutions up to date, creating documentation and supporting the definition and implementation of security related processes and plans, including incident response and disaster recovery plans. Responsible for generating reports for the Cyber Security team and wider business to evaluate the efficiency of the cyber security policies in place.
Key Responsibilities:- In support to the Group Head of Cyber Security, develop relevant cyber security dashboards that provide a view of DFTO specifically, TOC cyber security metrics and an overall DFTO Group cyber security posture.
- Monitor the performance of network, system and application security solutions across the DFTO Group to identify and bring to attention breaches and potential intrusion incidents using software that detects intrusions and anomalous system behaviour.
- Forensically investigate security breaches within a defined area of responsibility to maintain compliance with internal security policies.
- If appropriate, liaise with authorities to support breach investigation and any legal process as a consequence.
- Analyse security breaches to identify the root cause, ensuring remediation activities are undertaken to protect the DFTO Group networks/data/information as required.
- Lead the day-to-day business information security requests, investigating routine security related incidents, such as malware detections, DLP violations, phishing emails and provide general cyber security support.
- Produce comprehensive reports including assessment-based findings, outcomes and propositions for current security effectiveness and further system security enhancement.
- Develop and carry out information security plans, policies and procedures.
- Monitoring use of security products data encryption and other security products and procedures.
- Appropriate administrative, physical and technical monitoring up to date safeguards are in place to protect information assets from internal and external threats e.g. up to date OS patches, AV, DLP.
- Reviewing IDS, log files for legal/regulatory compliance to detect security events/suspicious behaviour.
- Be a point of expert advice and contact for all Operators across the DFTO Group.
- This will require providing support to TOCs across the group supporting local cyber security analyst activities working in a collegiate manner with local cyber analysts as appropriate.
- Be the point of contact for DFTO TOC Analyst activity.
- As needed work with local TOC Analysts to identify, mitigate and remediate local risks and/or incidents to prevent wider spread across the DFTO group of Operators.
- Manage the shared cyber incident documentation portal, identifying common risk.
- Articulate those risks and likelihood of exploit, and mitigation required, to the Cyber Security Governance, Risk & Compliance Manager.
- Understanding of database and operating system security.
- Understanding of the latest security principles, techniques, and protocols.
- Understanding of network/endpoint security solutions.
- Able to demonstrate and articulate basic knowledge of compliance with the ISO27001, PCI DSS, GDPR, Cybersecurity and other security Standards.
- Effective team player experienced at dealing at all levels with effective influencing and negotiating skills.
- Ability to form constructive and proactive working relationships at all levels with all stakeholders, whether DFTO (including TOC’s), Network Rail or External Stakeholders.
- Effective interpersonal skills and an ability to use influence to gain buy-in to enable change to happen through others.
- A drive to deliver tangible outcomes which meet business requirements.
- Thrives with accountability and responsibility and is self-reliant.
- An ability to work well under pressure in a rapidly evolving environment.
- Current experience in an IT role, preferably within Information/Cyber Security.
- Hands on experience in security systems, including firewalls, intrusion detection systems, anti-virus software, authentication systems, log management, content filtering, etc.
- Sound technical background in current Microsoft Active Directory, VMWare, Server/PC standard builds, configuration concepts and technologies ideally to certification level.
- Experience with system, security, and network monitoring tools.
- Recognised industry security certification such as CISMP, CompTIA CySA+, Security+ or equivalent is desirable.
- Experience in providing written and verbal presentations across all levels of a company.
- Demonstrate their knowledge and understanding of basic financial/technical information.
- Hands on experience of problem-solving and ability to stay calm under pressure.
- ITIL Foundation certification desirable.
This role reports to the Group Head of Cyber Security, and will work closely with DFTO business units, and external TOC stakeholders. The postholder will provide essential support to colleagues and will be working at the core in shaping DFTO’s IT security landscape as the organisation expands its public ownership footprint and delivers secured services across the Group.
Vacancy Details:- Duration: Permanent
- Location: London Waterloo/Hybrid
- Salary: up to £58,000
- Closing date: 2nd June 2026
- Annual Leave: Starting at 25 days and rising to an additional day per year of service completed within the first 5 completed years up to a maximum of 5 additional (30 days).
- DC Pension Scheme: 10% Employer contribution, 5% Employee contribution.
- Opportunities to learn and network across the wider industry.
We are an inclusive employer of choice and we welcome applications from everyone! We encourage our colleagues to work flexibly, as we know traditional working patterns don't always fit. If you want to consider working flexibly, just let us know and we'll do our best to help and invest in your career with us, whilst you have a healthy work life balance.
If you have any questions or reasonable adjustments, please contact Name.Jason.blakemore@dftoperator.co.uk. Please do not email any CV's to us, your application must be made by clicking the 'Apply' button.
Cyber Security Analyst in London employer: DfT Operator
DFTO is an exceptional employer, offering a dynamic work environment where over 30,000 employees contribute to the future of public rail services in the UK. With a strong commitment to employee growth, DFTO provides extensive training opportunities, a generous benefits package including up to 30 days of annual leave and a robust pension scheme, all while fostering a culture of inclusivity and flexibility that prioritises work-life balance. Join us at our London Waterloo location to be part of a transformative journey in the rail industry, where your contributions will directly impact millions of customer journeys each year.
StudySmarter Expert Advice🤫
We think this is how you could land Cyber Security Analyst in London
✨Tip Number 1
Network like a pro! Attend industry events, webinars, or local meetups related to cyber security. It's a great way to meet people in the field and get your name out there. Plus, you never know who might have a lead on a job!
✨Tip Number 2
Don’t underestimate the power of LinkedIn! Make sure your profile is up-to-date and showcases your skills and experiences. Engage with posts, join relevant groups, and connect with professionals in the cyber security space. It’s all about visibility!
✨Tip Number 3
Prepare for interviews by practising common cyber security questions. Think about how you can demonstrate your problem-solving skills and technical knowledge. Mock interviews with friends or mentors can really help boost your confidence!
✨Tip Number 4
Apply through our website! We want to see your application, and it’s the best way to ensure it gets into the right hands. Don’t forget to tailor your application to highlight how your skills align with the role of Cyber Security Analyst at DFTO.
We think you need these skills to ace Cyber Security Analyst in London
Some tips for your application 🫡
Tailor Your CV:Make sure your CV is tailored to the Cyber Security Analyst role. Highlight relevant experience and skills that match the job description, like your knowledge of security principles and hands-on experience with security systems.
Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you're passionate about cyber security and how your background makes you a great fit for DFTO. Don’t forget to mention any specific projects or achievements that relate to the role.
Showcase Your Technical Skills:In your application, be sure to showcase your technical skills, especially those mentioned in the job description like experience with firewalls, intrusion detection systems, and compliance standards. This will help us see your fit for the role right away.
Apply Through Our Website:Remember, the best way to apply is through our website! It ensures your application gets to the right place and helps us keep track of all candidates. Plus, it’s super easy to do!
How to prepare for a job interview at DfT Operator
✨Know Your Cyber Security Basics
Make sure you brush up on the latest security principles, techniques, and protocols. Be ready to discuss your understanding of compliance with standards like ISO27001 and GDPR, as these are crucial for the role.
✨Showcase Your Technical Skills
Prepare to talk about your hands-on experience with security systems such as firewalls and intrusion detection systems. Highlight any relevant certifications like CompTIA CySA+ or Security+, as they can set you apart from other candidates.
✨Demonstrate Problem-Solving Abilities
Be ready to share examples of how you've tackled security incidents in the past. Discuss your approach to investigating breaches and how you stay calm under pressure, as this role will require quick thinking and effective decision-making.
✨Build Rapport with Stakeholders
Since you'll be working closely with various teams, practice your interpersonal skills. Think of ways to demonstrate how you've successfully influenced others in previous roles, as forming constructive relationships is key to success in this position.