Location
About the job
Job summary
Ofwat (The Water Services Regulation Authority) is a non-ministerial government department. We regulate the water sector in England and Wales.
Our role is to help build trust and confidence with customers, the environment and wider society. Ofwat has an ambitious strategy: Time to act, together. It matters to us that things on the ground really change so that our impact on customers, the environment and the future of water is tangible and meaningful
We are forward-thinking, creative, innovative and ambitious. We actively encourage autonomy, collaboration and innovation and there’s a real adult culture fostered by trust, flexibility and respect.
In 2023 we were awarded ‘Smarter Working Maturity’ recognition for the way that Ofwat has embraced new and modern ways of working, reflecting the spaces we provide, technology we have deployed and the culture and leadership we have embedded to empower choice and flexibility for our people.
Please read the attached “Candidate Information Pack” to find more about why you should join Ofwat.
Job description
We are seeking a talented Cyber Security Engineer to join the recently expanded Ofwat Security team. As a Cyber Security Engineer, you will be responsible for designing, implementing, and maintaining robust security measures to protect our systems, networks, and data from cyber threats. You will work closely with our IT team and across fellow Government organisations to identify vulnerabilities, develop strategies to mitigate risks, and ensure compliance with relevant security standards and regulations.
In this role you are likely to spend most of your time:
- Developing and implementing comprehensive cyber security strategies, policies, and procedures tailored to the specific needs of our organisation.
- Conducting regular security assessments, vulnerability scans, and penetration tests to identify potential weaknesses and recommend appropriate remediation measures.
- Monitoring and analysing security logs, events, and alerts to detect and respond to potential security incidents in a timely manner.
- Continuously developing and managing the SIEM solution, along with developing playbooks in a proactive and effective manner.
- Managing and maintaining security infrastructure, including firewalls, intrusion detection/prevention systems, anti-malware solutions, and other security tools.
- Collaborating with cross-functional teams to integrate security controls and best practices into the development and deployment of new systems, applications, and technologies.
- Keeping up to date with the latest cyber security threats, trends, and technologies, and proactively recommend improvements to our security posture.
- Leading incident response efforts, including investigation, containment, and recovery, and provide guidance to junior security team members.
- Assisting in the development and delivery of cyber security awareness and training programs to promote a culture of security throughout the organisation.
- Ensuring compliance with relevant security frameworks, regulations, and standards, such as ISO 27001, GDPR, and NIST Cybersecurity Framework.
Person specification
Essential Experience, Skills and Knowledge
- Proven experience in a similar role, with a focus on designing and implementing security controls in complex environments.
- Strong knowledge of network security principles, protocols, and technologies, including firewalls, VPNs, IDS/IPS, SIEM, and endpoint protection.
- Proficiency with Microsoft Security technologies.
- Experience with security assessment tools, vulnerability scanning, and penetration testing methodologies.
- Familiarity with security frameworks and standards (e.g., ISO 27001, NIST Cybersecurity Framework, CyberEssentials and CyberEssentials Plus) and ability to ensure compliance.
- In-depth understanding of current cyber security threats, attack vectors, and mitigation strategies.
- Ability to analyse and interpret security logs, events, and alerts to detect and respond to security incidents effectively.
- Strong communication and interpersonal skills, with the ability to convey complex security concepts to non-technical stakeholders.
Attributes
- Champion and Leader of Change
- Builds Trust
- Adaptable Thinker
- Delivers Outcomes
You can read more about Attributes in Ofwat’s Framework for Success
Benefits
- 25 days annual leave (increasing to max 30 with each year of service) plus bank holidays and 2.5 days privilege leave days
- access to exclusive discounts on a range of goods and services such as retail outlets, theatre tickets, holidays, insurance and gym membership;
- flexible working arrangements;
- fees paid for membership of relevant professional bodies;
- up to 3 volunteering days per year
- generous shared parental leave and pay
- cycle-to-work scheme;
- season ticket loan for travel between home and office;
- regular professional development;
- health and well-being initiatives