Cyber Resilience Testing Lead - Reading, Berkshire in Earley

Cyber Resilience Testing Lead - Reading, Berkshire in Earley

Earley Full-Time 68000 - 78000 € / year (est.) No home office possible
Thames Water

At a Glance

  • Tasks: Lead cyber resilience testing and vulnerability management for IT and OT environments.
  • Company: Join Thames Water, the UK's largest water and wastewater company.
  • Benefits: Competitive salary, generous annual leave, pension scheme, and health perks.
  • Other info: Flexible working arrangements and opportunities for career growth.
  • Why this job: Make a real impact on cybersecurity while protecting vital water resources.
  • Qualifications: Experience in cybersecurity and vulnerability management is essential.

The predicted salary is between 68000 - 78000 € per year.

As a Cyber Resilience Testing Lead, you will play a key role within the Information Security team at Thames Water, supporting the Head of Cyber Resilience in delivering technical cyber resilience testing and vulnerability management activities across both IT and OT environments. Working closely with cybersecurity leadership, service owners, and technical teams, you will help ensure vulnerabilities are effectively identified, assessed, remediated, and evidenced across the organisation.

This role contributes to Thames Water’s cyber resilience programme by providing technical assurance of defensive capabilities, supporting resilience testing initiatives, and ensuring vulnerability management processes are robust and effective. You will collaborate with stakeholders across the business to ensure testing and remediation activities are executed efficiently while maintaining high standards of documentation, reporting, and governance.

Security Clearance: CTC (Counter Terrorist Check) clearance is essential. You must currently hold or be able to attain CTC clearance for this role.

What you’ll be doing as a Cyber Resilience Testing Lead:

  • Lead the technical validation of vulnerabilities, including severity assessment, exploitability analysis, and business impact evaluation across IT and OT environments.
  • Perform advanced triage of vulnerabilities using industry-standard methodologies such as CVSS.
  • Act as the technical escalation point for complex or disputed remediation plans, advising on compensating controls and risk acceptance.
  • Maintain and update the central vulnerability register, ensuring accurate tracking from identification through to remediation.
  • Assign ownership of vulnerabilities and track remediation progress to completion.
  • Collect and validate remediation evidence, ensuring audit-ready documentation.
  • Prepare reports and dashboards to support oversight by Cyber Resilience leadership.
  • Design and maintain the annual penetration testing and red/purple team testing schedule.
  • Review and validate testing outputs, including exploit paths and findings, ensuring technical accuracy.
  • Translate testing findings into actionable remediation plans in collaboration with SOC, architecture, engineering, and OT teams.
  • Support the coordination of penetration testing, red/purple teaming, and cyber stress testing activities.
  • Provide subject matter expertise during cyber incidents, supporting technical investigation and response.
  • Maintain readiness for regulatory compliance, ensuring testing and vulnerability evidence meets audit requirements.
  • Support broader cyber resilience initiatives through operational and administrative activities.
  • Maintain accurate records and contribute to reporting and regulatory submissions.

What you should bring to the role:

  • Experience in cybersecurity, vulnerability management, or related technical security roles.
  • Strong understanding of offensive security methodologies, including MITRE ATT&CK.
  • Ability to analyse penetration testing reports in depth and translate findings into control improvements.
  • Experience tracking vulnerability remediation and coordinating with stakeholders to ensure timely resolution.
  • Experience working within critical infrastructure, utilities, or public sector environments.
  • Strong organisational skills with the ability to manage multiple priorities and maintain accurate records.
  • Excellent communication and interpersonal skills to engage technical and non-technical stakeholders.
  • Ability to build strong working relationships and operate as a self-starter.

Technical experience and skills:

  • Familiarity with vulnerability management tools such as ServiceNow, Tenable, or similar platforms.
  • Knowledge of cybersecurity frameworks and standards such as ISO 27001, NIST, and CIS Controls.
  • Proficiency in reporting and data analysis tools such as Excel, Power BI, or equivalent.
  • Ability to validate vulnerabilities, interpret testing results, and support remediation planning.

Desirable qualifications and experience:

  • Broader knowledge and experience within cybersecurity or information security.
  • Experience with ICS/OT security testing, including PLCs, HMIs, and industrial protocols such as Modbus, DNP3, and OPC-UA.
  • Experience producing technical dashboards reflecting vulnerability management and resilience maturity.
  • Experience working with vendors or delivery partners on testing or remediation activities.
  • Experience supporting penetration testing, red/purple teaming, or cyber stress testing programmes.
  • Experience supporting regulatory compliance aligned to industry standards (e.g., SEMD, CAF).

Desirable technical skills and qualifications:

  • Bachelor’s degree in Computer Science, IT, Cyber Security, or a related field (or equivalent experience).
  • Professional certifications such as CompTIA Security+, CySA+, or similar (CISSP/CISM desirable but not essential).

What’s in it for you?

  • Competitive salary between £68,000 and £78,000 per annum, depending on experience.
  • Annual Leave - 26 days holiday per year, increasing to 30 with the length of service (plus bank holidays).
  • Generous Pension Scheme through AON.
  • Performance-related pay plan directly linked to company performance measures and targets.
  • Access to lots of benefits to help you take care of you and your family’s health and wellbeing, and your finances – from annual health MOTs and access to physiotherapy and counselling, to Cycle to Work schemes, shopping vouchers and life assurance.

Thames Water is a unique, rewarding, and diverse place to work, where every day you can make a difference, yet no day is the same. As part of our family, you’ll enjoy meaningful career opportunities, flexible working arrangements and excellent benefits. If you’re looking for a sustainable and successful career where you can make a daily difference to millions of people’s lives while helping to protect the world of water for future generations, we’ll be here to support you every step of the way.

Cyber Resilience Testing Lead - Reading, Berkshire in Earley employer: Thames Water

Thames Water is an exceptional employer, offering a dynamic and inclusive work environment where you can make a tangible impact on millions of lives. With competitive salaries, generous annual leave, and a robust pension scheme, employees benefit from a strong focus on health and wellbeing, alongside meaningful career development opportunities. Located in Reading, the company fosters a culture of collaboration and support, ensuring that every team member feels valued and empowered to contribute to a sustainable future.

Thames Water

Contact Detail:

Thames Water Recruiting Team

StudySmarter Expert Advice🤫

We think this is how you could land Cyber Resilience Testing Lead - Reading, Berkshire in Earley

Tip Number 1

Network like a pro! Reach out to folks in the cybersecurity field, especially those at Thames Water. A friendly chat can open doors and give you insights that a job description just can't.

Tip Number 2

Prepare for the interview by brushing up on your technical skills. Be ready to discuss vulnerability management and offensive security methodologies. Show us you know your stuff!

Tip Number 3

Don’t forget to showcase your soft skills! Communication is key in this role, so be prepared to demonstrate how you can engage both technical and non-technical stakeholders effectively.

Tip Number 4

Apply through our website! It’s the best way to ensure your application gets seen. Plus, it shows you’re genuinely interested in being part of the Thames Water family.

We think you need these skills to ace Cyber Resilience Testing Lead - Reading, Berkshire in Earley

Cybersecurity
Vulnerability Management
Technical Assurance
Penetration Testing
Exploitability Analysis
Risk Assessment
MITRE ATT&CK

Some tips for your application 🫡

Tailor Your Application:Make sure to customise your CV and cover letter for the Cyber Resilience Testing Lead role. Highlight your experience in cybersecurity and vulnerability management, and show how your skills align with what we're looking for at Thames Water.

Showcase Your Technical Skills:Don’t hold back on detailing your technical expertise! Mention any familiarity with vulnerability management tools or frameworks like ISO 27001 and NIST. We want to see how you can contribute to our cyber resilience programme.

Be Clear and Concise:When writing your application, keep it clear and to the point. Use bullet points where possible to make it easy for us to read through your qualifications and experiences. We appreciate straightforward communication!

Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way to ensure your application gets to us quickly and efficiently. Plus, you’ll find all the details about the role and our company there!

How to prepare for a job interview at Thames Water

Know Your Cybersecurity Basics

Before heading into the interview, make sure you brush up on your cybersecurity fundamentals. Understand key concepts like vulnerability management, penetration testing, and the MITRE ATT&CK framework. This will not only help you answer technical questions confidently but also show that you're genuinely interested in the field.

Prepare Real-World Examples

Think of specific instances from your past experience where you've successfully managed vulnerabilities or led a testing initiative. Be ready to discuss the challenges you faced, how you approached them, and the outcomes. This will demonstrate your practical knowledge and problem-solving skills.

Familiarise Yourself with Their Tools

Since the role mentions familiarity with tools like ServiceNow and Tenable, it’s a good idea to have a basic understanding of these platforms. If you’ve used similar tools, be prepared to discuss your experience and how it relates to the job at Thames Water.

Ask Insightful Questions

At the end of the interview, don’t forget to ask questions! Inquire about their current cyber resilience initiatives or how they measure the success of their vulnerability management processes. This shows your enthusiasm for the role and helps you gauge if the company is the right fit for you.