Cyber Threat & Vulnerability Manager - Reading, Berkshire in Sonning
Cyber Threat & Vulnerability Manager - Reading, Berkshire

Cyber Threat & Vulnerability Manager - Reading, Berkshire in Sonning

Sonning Full-Time 90000 - 90000 £ / year (est.) Home office (partial)
Thames Water

At a Glance

  • Tasks: Lead cyber threat and vulnerability management to protect critical infrastructure.
  • Company: Join Thames Water, the UK's largest water and wastewater company.
  • Benefits: Competitive salary, car allowance, generous annual leave, and wellness perks.
  • Other info: Flexible working arrangements and excellent career growth opportunities.
  • Why this job: Make a real impact on cybersecurity while helping millions of customers.
  • Qualifications: Experience in managing cyber risk and strong analytical skills required.

The predicted salary is between 90000 - 90000 £ per year.

As a Cyber Threat & Vulnerability Manager, you will play a key role within the Security Operations function at Thames Water, leading the organisation's approach to identifying, assessing, and reducing cyber risk across both IT and OT environments. Working closely with cybersecurity leadership, enterprise architects, and business stakeholders, you will ensure that threat and vulnerability management (TVM) capabilities are effective, scalable, and continuously improved.

This role contributes to Thames Water's cybersecurity resilience by establishing robust vulnerability management frameworks, integrating threat intelligence into risk processes, and driving proactive security improvements. You will collaborate across the organisation to reduce risk exposure, enhance cyber maturity, and ensure compliance with industry standards while maintaining strong governance and reporting practices.

You must be able to obtain Counter Terrorist Check (CTC) Clearance to be eligible for this position.

What you'll be doing as a Cyber Threat & Vulnerability Manager:

  • Lead vulnerability management across the enterprise, ensuring frameworks for identification, categorisation, and mitigation are defined, implemented, and maintained.
  • Establish and manage the operating model for vulnerability management, ensuring alignment and adoption across the business.
  • Collaborate with stakeholders to develop threat assessment and TVM strategies aligned to organisational objectives.
  • Develop and maintain TVM documentation, including policies, standards, and procedures.
  • Integrate vulnerability management and threat intelligence tools with existing systems and infrastructure.
  • Evaluate and recommend tools, technologies, and vendors to support TVM capabilities.
  • Investigate newly identified vulnerabilities and provide risk-based mitigation and remediation guidance.
  • Coordinate with technology and business stakeholders to ensure effective patching and vulnerability remediation.
  • Maintain and evolve a cyber threat assessment methodology aligned to industry standards.
  • Perform proactive threat hunting to identify emerging risks across the technology estate.
  • Develop and maintain dashboards and reporting to track vulnerability and threat metrics.
  • Ensure compliance with relevant standards and regulations such as GDPR, NIS, and ISO 27001.
  • Monitor and optimise TVM tool performance, implementing improvements where required.
  • Provide technical leadership and guidance to junior team members.
  • Build and maintain strong relationships with vendors and service providers.
  • Stay current with emerging threats, technologies, and best practices to continuously enhance security operations.
  • Support major incident response where required as part of Security Operations.

What you should bring to the role:

  • Experience leading or managing threat and vulnerability management processes within a complex enterprise environment.
  • Strong experience in vulnerability remediation and patch management across diverse technology stacks.
  • Experience managing cyber risk across dynamic and evolving digital environments.
  • Ability to line manage and develop at least one team member towards shared objectives.
  • Strong analytical, problem-solving, and decision-making skills.
  • Experience working with third-party delivery partners and vendors.
  • Excellent communication skills with the ability to explain complex security concepts to non-technical stakeholders.
  • Strong organisational, planning, and strategic thinking capabilities.
  • Innovative mindset with a focus on continuous improvement and risk reduction.

Technical experience and skills:

  • Hands-on experience with vulnerability management tools such as Tenable and Qualys.
  • Strong understanding of TVM concepts, including threat modelling, vulnerability assessment, and OSINT.
  • Knowledge of patch management approaches across SaaS, IaaS, end-user computing, and server environments.
  • Ability to develop metrics and dashboards that demonstrate risk reduction and control effectiveness.
  • Experience aligning security practices with frameworks such as ISO 27001, NIS, and GDPR.

Desirable qualifications and experience:

  • Experience working within utilities, critical infrastructure, or large enterprise environments.
  • Experience managing vulnerabilities in operational technology (OT) environments.
  • Familiarity with legacy systems and managing risk in ageing technology estates.
  • Experience supporting cyber security programmes and transformation initiatives.

Desirable technical skills and qualifications:

  • Degree in Cyber Security, Computer Science, Information Technology, Engineering, or a related field.
  • Professional certifications such as CISSP, CISM, or CCSP.
  • TVM-specific certifications such as Certified Threat Intelligence Analyst (CTIA) or Certified Vulnerability Assessor (CVA).
  • Knowledge of penetration testing or ethical hacking practices.

What's in it for you?

  • Competitive salary: Up to 90,000 per annum, depending on experience.
  • Car Allowance: 5,800.
  • Annual Leave: 26 days holiday per year, increasing to 30 with the length of service (plus bank holidays).
  • Performance-related pay plan directly linked to company performance measures and targets.
  • Generous Pension Scheme through AON.
  • Access to lots of benefits to help you take care of you and your family's health and wellbeing, and your finances from annual health MOTs and access to physiotherapy and counselling, to Cycle to Work schemes, shopping vouchers and life assurance.

Thames Water is a unique, rewarding, and diverse place to work, where every day you can make a difference, yet no day is the same. As part of our family, you'll enjoy meaningful career opportunities, flexible working arrangements and excellent benefits.

If you're looking for a sustainable and successful career where you can make a daily difference to millions of people's lives while helping to protect the world of water for future generations, we'll be here to support you every step of the way. Together, we can build a better future for our customers, our region, and our planet.

We're committed to being a great, diverse, and inclusive place to work. We welcome applications from everyone and want to ensure you feel supported throughout the recruitment process. If you need any adjustments, whether that's extra time, accessible formats, or anything else, just let us know. We're here to help and support.

Cyber Threat & Vulnerability Manager - Reading, Berkshire in Sonning employer: Thames Water

Thames Water is an exceptional employer, offering a dynamic work environment in Reading where you can make a tangible impact on the lives of millions. With a competitive salary, generous benefits including a robust pension scheme and flexible working arrangements, we prioritise employee well-being and career growth. Join us to be part of a diverse team committed to sustainability and innovation in the water sector, while enjoying meaningful opportunities for professional development.
Thames Water

Contact Detail:

Thames Water Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Cyber Threat & Vulnerability Manager - Reading, Berkshire in Sonning

✨Tip Number 1

Network like a pro! Reach out to folks in the cybersecurity field, especially those at Thames Water. Use LinkedIn to connect and engage with them; you never know who might have the inside scoop on job openings or can put in a good word for you.

✨Tip Number 2

Prepare for interviews by brushing up on your knowledge of threat and vulnerability management. Be ready to discuss your experience with tools like Tenable and Qualys, and how you've tackled vulnerabilities in past roles. Show them you're not just a fit on paper but in practice too!

✨Tip Number 3

Don’t forget to showcase your soft skills! Being able to explain complex security concepts to non-technical stakeholders is key. Think of examples where you've done this successfully and be ready to share them during your chats.

✨Tip Number 4

Apply through our website! It’s the best way to ensure your application gets seen. Plus, it shows you're genuinely interested in being part of the Thames Water family. Don’t wait too long, though – positions can close quickly!

We think you need these skills to ace Cyber Threat & Vulnerability Manager - Reading, Berkshire in Sonning

Cyber Threat Management
Vulnerability Management
Risk Assessment
Threat Intelligence Integration
Patch Management
Analytical Skills
Problem-Solving Skills
Communication Skills
Technical Leadership
ISO 27001 Compliance
GDPR Knowledge
Experience with Vulnerability Management Tools (e.g., Tenable, Qualys)
Strategic Thinking
Collaboration with Stakeholders

Some tips for your application 🫡

Tailor Your CV: Make sure your CV is tailored to the Cyber Threat & Vulnerability Manager role. Highlight your experience in vulnerability management and any relevant tools you've used, like Tenable or Qualys. We want to see how your skills align with what we're looking for!

Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about cybersecurity and how your background makes you a great fit for our team. Don't forget to mention your innovative mindset and problem-solving skills!

Showcase Your Achievements: When detailing your experience, focus on specific achievements rather than just duties. Did you reduce risk exposure or improve compliance? We love numbers and results, so quantify your successes where possible!

Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way to ensure your application gets the attention it deserves. Plus, you'll find all the info you need about the role and our company culture there!

How to prepare for a job interview at Thames Water

✨Know Your Cyber Threats

Before the interview, brush up on the latest trends in cyber threats and vulnerabilities. Familiarise yourself with tools like Tenable and Qualys, as well as industry standards such as ISO 27001 and GDPR. This will show that you're not just knowledgeable but also proactive about staying current in the field.

✨Showcase Your Leadership Skills

As a Cyber Threat & Vulnerability Manager, you'll need to demonstrate your ability to lead and develop a team. Prepare examples of how you've successfully managed teams or projects in the past, focusing on your strategic thinking and problem-solving skills. This will help you stand out as a candidate who can drive improvements and foster collaboration.

✨Communicate Clearly

You'll likely be explaining complex security concepts to non-technical stakeholders, so practice articulating your thoughts clearly and concisely. Use relatable analogies or examples to make your points more accessible. This will highlight your communication skills and your ability to bridge the gap between technical and non-technical audiences.

✨Prepare for Scenario Questions

Expect scenario-based questions that assess your decision-making and analytical skills. Think of specific situations where you've identified vulnerabilities or mitigated risks, and be ready to discuss your thought process and the outcomes. This will demonstrate your hands-on experience and your capability to handle real-world challenges in cyber security.

Cyber Threat & Vulnerability Manager - Reading, Berkshire in Sonning
Thames Water
Location: Sonning

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

>