Rodeo
Get started

Transport for Wales

Cyber Security Operations Engineer (0833)

Pontypridd
Posted about 20 hours ago
Sign up to applySee more jobs like this

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

The Role

The Cyber Security Operations Engineer for Transport for Wales (TfW) will be responsible for the implementation, configuration, and continuous improvement of technical security controls across TfW's cloud and on-premises platforms.

Role Responsibilities

  • Own the design authority and lifecycle management of technical security controls across TfW platforms by defining control standards, governing technical designs, and working with architecture, engineering, and delivery teams to embed security throughout the technology lifecycle, to provide scalable, risk-aligned protection that supports secure and resilient business services.
  • Drive the vulnerability management capability across TfW technology services by overseeing tooling, governance, reporting, and risk-based remediation activities with technology teams and suppliers, to reduce exposure to vulnerabilities and strengthen organisational cyber resilience.
  • Develop and enhance TfW's monitoring and detection capability by working with SOC and MSSP providers to improve visibility, coverage, and threat detection effectiveness, to enable the timely identification and response to cyber threats.
  • Lead the integration strategy for security technologies by defining roadmaps, governing implementation, and optimising the use of platforms including EDR, IAM, and cloud security solutions, to deliver cohesive and effective security controls across the enterprise.
  • Provide technical leadership for SIEM and SOAR capabilities by overseeing use cases, automation opportunities, and operational improvements with internal and external partners, to maximise security operations effectiveness and support intelligence-led threat detection and response.
  • Drive the adoption of secure configuration standards across TfW platforms by establishing technical baselines, monitoring compliance, and supporting remediation activities, to maintain secure-by-default technology services aligned to recognised standards and organisational policy. Set and assure adherence to secure configuration standards, ensuring platforms are secure by default and aligned to recognised benchmarks and organisational policy.
  • Embed secure-by-design principles across IT and Digital Services by collaborating with architects, engineers, and delivery teams throughout project and service lifecycles, to reduce security risk and improve the resilience of technology solutions.
  • Lead the identification and management of technical security risks by working with system owners to assess, prioritise, remediate, and govern risk treatment activities, to support informed risk management and protect organisational assets.
  • Define and maintain technical security standards, procedures, and design patterns by providing governance, assurance, and technical guidance across technology teams, to achieve consistent, compliant, and auditable implementation of security controls.
  • Provide senior technical leadership during cyber security incidents by coordinating investigation, containment, recovery, and post-incident activities with relevant stakeholders, to minimise business impact and strengthen future security capabilities.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

Who We're Looking For

  • Professional cyber security certification such as CompTIA Security+, Microsoft Security certifications (e.g. SC-200, SC-300), ISC2 CC, CISMP, or equivalent practical experience.
  • Demonstrable experience leading security engineering, operational security, or technical security improvement workstreams.
  • Practical experience implementing and managing security controls across cloud and enterprise environments, including Microsoft 365, Azure, EDR, IAM, logging, SIEM, and cloud security technologies.
  • Experience managing vulnerability remediation programmes, including vulnerability scanning, patch management processes, tooling, reporting, and risk-based prioritisation.
  • Knowledge of cyber security principles, secure configuration standards, security monitoring, and detection practices, including working with SOC and MSSP providers.
  • Ability to analyse technical security data, assess risk, and prioritise remediation activities, with an understanding of risk management and control assurance frameworks such as NCSC CAF and ISO27001.
  • Experience influencing and providing technical guidance to both technical and non-technical stakeholders, including senior leaders, to support effective security and risk-based decision-making.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

Welsh Language Skills

While not essential for this role, Welsh language skills would make a great addition to your application.

TfW support anyone who wants to learn Welsh or improve their skills. We offer online learning, classroom courses and funding attendance at local community courses.

Equal Opportunities

We're changing the way the transport industry looks. By celebrating and embracing differences, we're building a workforce that represents Wales. We need talented people from all backgrounds and cultures to bring their perspectives and experiences. Diverse teams make better decisions and drive innovation. Join us in transforming the way Wales travels.

Who We Are

Transport for Wales is changing the way Wales travels, making sustainable transport the first choice. We're building a multimodal integrated transport network called the T Network, making it easier for people to travel by train, bus, walking, wheeling and cycling.

Next steps

See attached Job Description for further details and how to apply. If you want to find out more about what we're doing in Wales, see our Annual Report.

We're a Disability Confident Leader. Let us know about any reasonable adjustments you may need in the recruitment process and as part of the role if you are successful.

This advert will close at 23:59 on the day of the application closing date stated above. However, we reserve the right to close this vacancy early if we receive enough applications. We encourage you to submit your application as early as possible.

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Skills

Vulnerability Management
SIEM
SOAR
EDR
IAM
Cloud Security
Incident Response
Secure Configuration
Risk Management
Technical Leadership
Security Engineering
SOC Management
Azure
Microsoft 365
NCSC CAF
ISO27001

Location

Pontypridd, Wales, United Kingdom

Sign up to applySee more jobs like this