As a Cyber Threat & Vulnerability Manager, you will play a key role within the Security Operations function at Thames Water, leading the organisation’s threat intelligence, vulnerability management, and intelligence-led testing capabilities across both IT and OT environments. Working closely with cybersecurity leadership, enterprise architects, programme delivery teams, and key business stakeholders, you will ensure that Threat and Vulnerability Management (TVM) services are effective, scalable, and continuously improved.
This role contributes to Thames Water’s cyber resilience by driving a risk-based approach to vulnerability management, embedding threat intelligence into operational and strategic decision-making, and enhancing security maturity across the organisation. You will lead a team of specialists, oversee governance and tooling, and ensure that TVM capabilities align with organisational objectives, regulatory requirements, and evolving threat landscapes.
You must be able to obtain Counter Terrorist Check (CTC) Clearance to be eligible for this position.
What you’ll be doing as a Cyber Threat & Vulnerability Manager
- Lead enterprise vulnerability management, ensuring frameworks for identifying, prioritising, and remediating vulnerabilities are defined, implemented, and continuously improved.
- Manage the Cyber Threat Intelligence service, ensuring intelligence is collected, analysed, and operationalised to support risk reduction and security operations.
- Collaborate with technical and business stakeholders to align TVM activities with organisational objectives and risk appetite.
- Develop and maintain TVM documentation, including policies, standards, procedures, and governance controls.
- Integrate and optimise vulnerability management, threat intelligence, and assessment tooling across enterprise systems and workflows.
- Oversee intelligence-informed testing activities, including targeted assessments, exploit validation, and internal testing services.
- Evaluate and recommend tools, technologies, and vendors to support and enhance TVM capabilities.
- Investigate newly identified vulnerabilities and coordinate risk-based mitigation and remediation activities.
- Work closely with technology teams to ensure effective patching, remediation tracking, and resolution of blockers.
- Maintain and evolve the organisation’s cyber threat assessment methodology aligned with industry standards and risk management processes.
- Lead proactive threat hunting activities to identify emerging threats and suspicious activity across the technology estate.
- Develop and maintain dashboards, reporting, and operational metrics that demonstrate risk reduction and control effectiveness.
- Ensure compliance with relevant standards and regulations such as GDPR, NIS, and ISO 27001.
- Monitor and improve the effectiveness of TVM processes, controls, and supporting technologies.
- Provide leadership, coaching, and performance management to the TVM and testing team.
- Build and maintain strong relationships with external intelligence providers, vendors, and delivery partners.
- Stay current with emerging threats, technologies, and industry best practices to continuously enhance security operations.
- Support major incident response activities where required as part of Security Operations.
Base location – Hybrid – Clearwater Court, Reading.
Working pattern – 36 hours Monday to Friday.
What you should bring to the role
- Experience leading or managing threat and vulnerability management processes and controls within a complex enterprise environment.
- Strong experience in vulnerability remediation and patch management across diverse and evolving technology estates.
- Experience managing cyber risks within dynamic digital and operational technology environments.
- Ability to line manage and develop a team of security professionals towards shared objectives.
- Strong analytical, problem-solving, and decision-making skills.
- Experience managing third-party delivery partners, vendors, and service providers.
- Excellent communication skills with the ability to explain complex security concepts to non-technical stakeholders.
- Strong organisational, planning, and strategic thinking capabilities.
- Innovative mindset with a focus on continuous improvement and measurable risk reduction.
- Experience producing operational metrics and dashboards that demonstrate TVM effectiveness and cyber maturity improvements.
Technical experience and skills
- Hands-on experience with vulnerability management and threat intelligence tools such as Tenable and Qualys.
- Strong understanding of TVM concepts, including vulnerability assessment, threat modelling, OSINT, threat intelligence, and penetration testing.
- Knowledge of patch management approaches across SaaS, IaaS, end-user computing, server, and enterprise technology environments.
- Experience implementing risk-based approaches to vulnerability prioritisation and remediation.
- Ability to develop dashboards and reporting that demonstrate control effectiveness, risk reduction, and technical debt management.
- Experience aligning security practices with frameworks and regulations such as ISO 27001, NIS, and GDPR.
Desirable qualifications and experience
- Experience working within utilities, critical infrastructure, or large complex enterprise environments.
- Experience managing vulnerabilities and cyber risks within operational technology (OT) environments.
- Familiarity with legacy systems and managing vulnerabilities within ageing technology estates.
- Experience supporting cyber security transformation programmes and strategic cyber roadmaps.
Desirable technical skills and qualifications
- Degree in Cyber Security, Computer Science, Information Technology, Engineering, or a related field.
- Professional certifications such as CISSP, CISM, or CCSP.
- TVM-specific certifications such as Certified Threat Intelligence Analyst (CTIA) or Certified Vulnerability Assessor (CVA).
- Knowledge of penetration testing, ethical hacking, or related security assessment practices.
What’s in it for you?
- Competitive salary: Up to £90,000 per annum, depending on experience.
- Car Allowance: £5,800.
- Annual Leave: 26 days holiday per year, increasing to 30 with the length of service (plus bank holidays).
- Performance-related pay plan directly linked to company performance measures and targets
- Generous Pension Scheme through AON.
- Access to lots of benefits to help you take care of you and your family’s health and wellbeing, and your finances – from annual health MOTs and access to physiotherapy and counselling, to Cycle to Work schemes, shopping vouchers and life assurance.
Find out more about our benefits and perks (Please note different T&Cs apply if on secondment)
Who are we?
We’re the UK’s largest water and wastewater company, with more than 16 million customers relying on us every day to supply water for their taps and toilets. We want to build a better future for all, helping our customers, communities, people, and the planet to thrive. It’s a big job, and we’ve got a long way to go, so we need help from passionate and skilled people, committed to making a difference and getting us to where we want to be in the years and decades to come.
Learn more about our purpose and values
Working at Thames Water
Thames Water is a unique, rewarding, and diverse place to work, where every day you can make a difference, yet no day is the same. As part of our family, you’ll enjoy meaningful career opportunities, flexible working arrangements and excellent benefits.
If you’re looking for a sustainable and successful career where you can make a daily difference to millions of people’s lives while helping to protect the world of water for future generations, we’ll be here to support you every step of the way. Together, we can build a better future for our customers, our region, and our planet.
Real purpose, real support, real opportunities. Come and join the Thames Water family. Why choose us? Learn more.
We’re committed to being a great, diverse, and inclusive place to work. We welcome applications from everyone and want to ensure you feel supported throughout the recruitment process. If you need any adjustments, whether that’s extra time, accessible formats, or anything else, just let us know. We’re here to help and support.
When a crisis happens, we all rally around to support our customers. As part of Team Thames, you’ll have the opportunity to sign up to support our customers on the frontline as an ambassador. Full training will be given for what is undoubtedly an incredibly rewarding experience. It’s also a great opportunity to learn more about our business and meet colleagues.
Disclaimer: Due to the high volume of applications we receive, we may close the advert earlier than the advertised date, so we encourage you to apply as soon as possible to avoid disappointment.