
Location
Hybrid – Clearwater Court, Reading
Hours
36 hours per week, Monday to Friday
Salary
Up to £50,000 per annum, depending on experience
About the Role
As a Control Tester, you will play a key role within the Information Security team at Thames Water, supporting the Control Testing & Assurance Manager in delivering cybersecurity control testing activities across multiple security domains. You will work closely with cybersecurity leadership, service owners, and control owners to ensure security controls are effectively designed, implemented, and operating as intended across the organisation. This role contributes to the Cybersecurity Control Testing & Assurance programme by assessing control effectiveness, gathering evidence, and supporting the organisation’s wider security and compliance objectives.
You will collaborate with stakeholders across the business to ensure testing activities are executed efficiently while maintaining high standards of documentation and reporting. Key responsibilities include assisting in the execution of cybersecurity control testing activities according to defined procedures and standards, supporting the development and localisation of test scripts, gathering and documenting evidence, maintaining accurate documentation, producing clear reports, escalating issues, and contributing to continuous improvement of the control testing framework.
This role supports the wider cybersecurity assurance programme through structured testing and evidence-based analysis. Candidates must be eligible to obtain security clearance to a minimum of Counter Terrorist Check (CTC) level.
Benefits
Competitive salary up to £50,000 per annum depending on experience
26 days annual leave, increasing to 30 with length of service (plus bank holidays)
Generous pension scheme through AON
Performance-related pay plan linked to company performance
Access to health and wellbeing benefits including annual health MOTs, physiotherapy, counselling, Cycle to Work scheme, shopping vouchers, and life assurance
Flexible working arrangements and meaningful career opportunities
Supportive and inclusive working environment
Experience
Experience in IT audit, IT risk, or cybersecurity control testing within an enterprise environment
Understanding of cybersecurity control frameworks and assurance methodologies
Experience working collaboratively with technical teams and business stakeholders
Ability to manage tasks independently while contributing to team objectives
About you
Strong analytical and problem-solving skills with the ability to assess control effectiveness
Strong written and verbal communication skills including clear documentation and reporting
Good planning and organisational skills with attention to detail
Technical experience and skills
Understanding of cybersecurity domains including Threat Intelligence, Vulnerability Management, Security Testing, Security Architecture, Infrastructure Protection, Application Security, Identity and Access Management, Incident Investigation & Response, and Cryptography
Familiarity with information security control frameworks such as COBIT or COSO
Ability to gather, analyse, and document evidence related to the design and operational effectiveness of security controls
Experience in maintaining structured documentation including test plans, assessment results, and reports
Desirable qualifications and experience
Experience working in a regulated environment
Experience within the water utility industry or other large, complex critical national infrastructure organisations
Desirable technical skills and qualifications
Professional certifications such as CISA, CISSP, CRISC, or ISO 27001 Lead Auditor
Thames Water




















