Cyber Security Operations Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+4 more
Job description
The Cyber Security Operations Engineer for Transport for Wales (TfW) will be responsible for the implementation, configuration, and continuous improvement of technical security controls across TfW’s cloud and on-premises platforms., * Own the design authority and lifecycle management of technical security controls across TfW platforms by defining control standards, governing technical designs, and working with architecture, engineering, and delivery teams to embed security throughout the technology lifecycle, to provide scalable, risk-aligned protection that supports secure and resilient business services.
- Drive the vulnerability management capability across TfW technology services by overseeing tooling, governance, reporting, and risk-based remediation activities with technology teams and suppliers, to reduce exposure to vulnerabilities and strengthen organisational cyber resilience.
- Develop and enhance TfW’s monitoring and detection capability by working with SOC and MSSP providers to improve visibility, coverage, and threat detection effectiveness, to enable the timely identification and response to cyber threats.
- Lead the integration strategy for security technologies by defining roadmaps, governing implementation, and optimising the use of platforms including EDR, IAM, and cloud security solutions, to deliver cohesive and effective security controls across the enterprise.
- Provide technical leadership for SIEM and SOAR capabilities by overseeing use cases, automation opportunities, and operational improvements with internal and external partners, to maximise security operations effectiveness and support intelligence-led threat detection and response.
- Drive the adoption of secure configuration standards across TfW platforms by establishing technical baselines, monitoring compliance, and supporting remediation activities, to maintain secure-by-default technology services aligned to recognised standards and organisational policy. Set and assure adherence to secure configuration standards, ensuring platforms are secure by default and aligned to recognised benchmarks and organisational policy.
- Embed secure-by-design principles across IT and Digital Services by collaborating with architects, engineers, and delivery teams throughout project and service lifecycles, to reduce security risk and improve the resilience of technology solutions.
- Lead the identification and management of technical security risks by working with system owners to assess, prioritise, remediate, and govern risk treatment activities, to support informed risk management and protect organisational assets.
- Define and maintain technical security standards, procedures, and design patterns by providing governance, assurance, and technical guidance across technology teams, to achieve consistent, compliant, and auditable implementation of security controls.
- Provide senior technical leadership during cyber security incidents by coordinating investigation, containment, recovery, and post-incident activities with relevant stakeholders, to minimise business impact and strengthen future security capabilities.
Requirements
- Professional cyber security certification such as CompTIA Security+, Microsoft Security certifications (e.g. SC-200, SC-300), ISC2 CC, CISMP, or equivalent practical experience.
- Demonstrable experience leading security engineering, operational security, or technical security improvement workstreams.
- Practical experience implementing and managing security controls across cloud and enterprise environments, including Microsoft 365, Azure, EDR, IAM, logging, SIEM, and cloud security technologies.
- Experience managing vulnerability remediation programmes, including vulnerability scanning, patch management processes, tooling, reporting, and risk-based prioritisation.
- Knowledge of cyber security principles, secure configuration standards, security monitoring, and detection practices, including working with SOC and MSSP providers.
- Ability to analyse technical security data, assess risk, and prioritise remediation activities, with an understanding of risk management and control assurance frameworks such as NCSC CAF and ISO27001.
- Experience influencing and providing technical guidance to both technical and non-technical stakeholders, including senior leaders, to support effective security and risk-based decision-making.
About the company
While not essential for this role, Welsh language skills would make a great addition to your application.
TfWsupport anyone who wants to learn Welsh or improve their skills. We offer online learning, classroom courses and funding attendance at local community courses.
We’re changing the way the transport industry looks. By celebrating and embracing differences, we’re building a workforce that represents Wales. We need talented people from all backgrounds and cultures to bring their perspectives and experiences. Diverse teams make better decisions and drive innovation. Join us in transforming the way Wales travels.”, Transport for Wales is changing the way Wales travels, making sustainable transport the first choice. We’re building a multimodal integrated transport network called the T Network, making it easier for people to travel by train, bus, walking, wheeling and cycling.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Loading talks and stories from around this role…