At a Glance
- Tasks: Identify and reduce cyber risks to protect essential water services.
- Company: Join a leading Cyber Security team dedicated to safeguarding millions.
- Benefits: Competitive salary, generous leave, performance bonuses, and wellness support.
- Other info: Hybrid working model with opportunities for professional growth.
- Why this job: Make a real impact in cyber security while working with cutting-edge technology.
- Qualifications: Experience in vulnerability management and understanding of cyber security concepts.
The predicted salary is between 65000 - 65000 £ per year.
We’re looking for a Cyber Threat & Vulnerability Analyst to join our Cyber Security team, helping protect the systems that deliver essential water services to millions of customers every day. You’ll play a key role in identifying, assessing, and reducing cyber risk across a large and complex technology estate, making sure vulnerabilities are understood, prioritised, and fixed before they can be exploited. It’s a hands‑on role where you’ll work closely with technical teams and business stakeholders to keep our services safe, resilient, and running smoothly.
What you’ll be doing as a Cyber Threat & Vulnerability Analyst:
- Support end‑to‑end vulnerability management across IT and operational technology environments
- Help shape and improve threat and vulnerability management processes, frameworks, and ways of working
- Work with technical and business teams to prioritise and remediate vulnerabilities based on risk
- Investigate new vulnerabilities and recommend clear, practical mitigation actions
- Support integration of vulnerability scanning tools into existing systems and processes
- Build and maintain dashboards that show cyber risk, trends, and remediation progress in a clear way
- Contribute to threat assessments and support proactive threat hunting activities
- Help ensure alignment with standards such as General Data Protection Regulation, Payment Card Industry Data Security Standard, Network and Information Systems Regulations, and International Organisation for Standardisation 27001
- Monitor vulnerability management tools and processes, identifying ways to improve effectiveness and reduce risk
Base location: Reading – Clearwater Court
Working pattern or hours: 36 hours Monday to Friday, hybrid working
Necessary requirements for the role:
- Must be eligible to obtain Counter Terrorist Check security clearance
What you should bring to the role:
- Experience supporting vulnerability management, patching, or cyber risk reduction in a complex environment
- Understanding of cyber security concepts, including vulnerability management and threat assessment approaches
- Ability to work with technical teams to support remediation of security issues
- Experience or understanding of security tooling such as vulnerability scanners or similar technologies
- Ability to communicate technical issues clearly to both technical and non‑technical audiences
- Aware of how security risks are managed across different technology environments (for example cloud, servers, end‑user devices, or operational systems)
- A relevant cyber security qualification or industry certification such as Certified Information Systems Security Professional, Certified Information Security Manager, or Certified Cloud Security Professional
Extra qualities that would be a great fit for our team:
- Experience working with large enterprise or critical infrastructure environments
- Familiarity with threat intelligence or threat modelling approaches
- Experience supporting or improving security processes and governance
- Exposure to operational technology or legacy infrastructure environments
- Additional cyber security certifications such as Certified Threat Intelligence Analyst, Certified Vulnerability Assessor, Offensive Security Certified Professional, or similar
What’s in it for you:
- Competitive salary up to £65,000 per annum depending on experience
- Annual leave – 26 days holiday per year increasing to 30 with the length of service (plus bank holidays)
- Performance‑related pay plan directly linked to company performance measures and targets
- Generous Pension Scheme through AON
- Access to a range of benefits to support health, wellbeing, and finances – including annual health MOTs, physiotherapy and counselling, Cycle to Work schemes, shopping vouchers and life assurance
Cyber Threat & Vulnerability Analyst employer: Thames Water
Join our dynamic Cyber Security team in Reading, where you'll play a vital role in safeguarding essential water services for millions. We offer a supportive work culture that prioritises employee growth through continuous learning and development opportunities, alongside a competitive salary and generous benefits package, including a robust pension scheme and health support initiatives. Experience the unique advantage of working in a hybrid environment that fosters collaboration while allowing flexibility.
StudySmarter Expert Advice🤫
We think this is how you could land Cyber Threat & Vulnerability Analyst
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Thames Water, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through Thames Water
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Thames Water. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace Cyber Threat & Vulnerability Analyst
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Thames Water insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Thames Water that you’re committed to staying ahead in the game.
How to prepare for a job interview at Thames Water
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at Thames Water to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Thames Water.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.