
Location
Hybrid – Clearwater Court, Reading
Hours
36 hours per week, Monday to Friday
Salary
Up to £72,000 per annum depending on experience
About the Role
As a Security Penetration Tester at Thames Water, you will support the design, implementation, and maintenance of Threat & Vulnerability Management (TVM) solutions, controls, and processes across the organisation. You will collaborate closely with Digital teams to ensure appropriate mitigation and remediation of vulnerabilities detected across our IT estate. This role requires a strong understanding of TVM concepts, technologies, and best practices, alongside the ability to work effectively with cross-functional teams.
Your responsibilities will include helping to develop an internal penetration testing function, conducting network and application penetration tests, code and security reviews, and identifying vulnerabilities through proof-of-concept testing. You will support enterprise-wide vulnerability management by ensuring frameworks for identification, categorisation, and mitigation are implemented and maintained. Additionally, you will contribute to the creation and operation of the vulnerability management model, develop and maintain penetration testing documentation, policies, and procedures, and integrate cybersecurity solutions with existing systems.
You will evaluate and recommend technologies, investigate new vulnerabilities, liaise with stakeholders on patching and vulnerability management, maintain a cyber threat assessment methodology aligned with industry standards, support proactive threat hunting, develop dashboards with threat and vulnerability metrics, and ensure compliance with relevant standards such as GDPR, NIS, and ISO 27001.
Thames Water is the UK’s largest water and wastewater company, serving over 16 million customers. We are committed to building a better future for our customers, communities, people, and the planet. Join us to make a meaningful impact while advancing your career in a supportive and diverse environment.
Experience
- Strong knowledge of manual penetration testing techniques
- Confident with operating systems and tools such as Tenable, Burp Suite, Kali Linux
- Experience remediating vulnerabilities and patch management in complex business environments
- Experience in penetration testing within an enterprise environment
- Ability to prepare detailed reports and present findings to key stakeholders
- Exposure to cyber risk remediation in dynamic digital estates
About you
- Excellent communication and collaboration skills
- Committed to maintaining high standards of security, compliance, and user experience
- Proactive and able to support threat hunting and vulnerability management activities
- Able to work effectively with cross-functional teams and stakeholders
Qualifications
- Cyber security industry certifications such as CSTM, CRT, OSCP, or CTL
- Understanding of patch management techniques across diverse technology stacks (e.g. SaaS, IaaS, End-User Computing, Server Estate)
- Knowledge of TVM concepts, technologies, and best practices including OSINT tools, vulnerability assessment, and threat modelling
- Must currently hold or be able to attain CTC (Counter Terrorist Check) security clearance
Thames Water




















