About this role
Together, we move what matters
We are at the start of something powerful. Heavy Haul Rail was created with a simple but transformative belief: the UK deserves a smarter, cleaner, more resilient freight future. And we have the opportunity to build it.
Every role in this business carries purpose. Whether you work in operational delivery, driving trains, engineering, or business support, the work you do contributes directly to reducing emissions, easing road congestion, strengthening supply chains and powering British industry. This is meaningful work, with real impact.
Who we are
Previously operating as Freightliner’s Heavy Haul business, we are now an independent company following CMA CGM Group’s acquisition of Freightliner UK’s Intermodal Logistics business in January 2026.
Heavy Haul Rail is the UK’s next-generation rail freight partner built for a sector ready to evolve. We believe it’s time to move differently. Congested roads, rising emissions, fragile supply chains. These aren’t just logistical challenges; they’re environmental and economic wake-up calls. We’re here to lead the modal shift, helping businesses transition from road to rail with confidence, clarity, and measurable impact.
We move 17 million tonnes of freight a year for customers in the industrial, energy and construction markets. The company operates 95 locomotives and over 1000 wagons. Heavy Haul Rail’s team of 950 supports customer deliveries to over 100 locations across the UK, running 250 trains per week.
Heavy Haul Rail also supports the renewal and maintenance of the rail infrastructure and supports passenger train operators and rolling stock companies, including the provision of drivers and route conducting services.
But none of this happens without us, its people.
P ur p ose of the Role
The Cyber Security Analyst is a technically focused, operational security role that combines elements of cyber security, network security and systems administration. The role supports the IT Systems Manager in ensuring that Freightliner IT services protect the confidentiality, integrity and availability of systems and data, while meeting recognised good-practice principles and applicable regulatory requirements.
The post holder is responsible for overseeing the monit oring, investigat ing, supporting and improving operational cyber security controls across the Freightliner estate. The role works closely with infrastructure, applications, ser vice de livery, project and business teams, as well as approved third parties and wider group IT functions.
Main Duties and Res p onsibilities
Security o p erations and incident res p onse
- P erform day-to-day mon i t oring and p roactive management of cyber security systems, alerts and associated co m p onents.
- Triage, investigate and co ordinate the resolution of security incidents, es cal ating material risks in line with the incident and major incident p rocesses.
- Act as a central p oint of co n t act for o p erational cyber security activity and p rovide clear u p dates to techni cal teams, stakeholders and management.
- Maintain a p p ro p riate incident re co rds, evidence, lessons learned and follow-u p actions.
Security p latforms and techni cal co n t r ols
- Co n figure, maintain and su p p ort security co n t r ols across the Freightliner estate, including firewalls, secure web gateways/ co n t ent filtering, end p oint p rotection, V P N and remote access, email security, identity and access co n t r ols, vulnerability management and security mon i t oring p latforms.
- Su p p ort secure co n figuration, o p erational health, tuning and lifecycle management of security technologies across on- p remises, cloud and SaaS environments.
- P lan, test and im p lement u p grades and service im p rovements to existing cyber security services and associated infrastructure.
- Use scri p ting and automation where a p p ro p riate to im p rove co n sistency, res p onse times, re p orting and o p erational efficiency.
Vulnerability, assurance and co m p liance
- O p erate a co n t inuous vulnerability assessment p rocess, co ordinate remediation with system owners and track risks through to closure or formal acce p tance.
- Audit systems, cloud services and a p p lications for secure co n figuration and alignment with a p p roved standards and baselines.
- Co ordinate and su p p ort annual security assessments, p enetration tests, audits and assurance activities, ensuring that findings have clear owners and remediation p lans.
- Co n t r i bute techni cal evidence and subject-matter su p p ort for security p olicies, risk assessments, co m p liance obligations and internal governance re p orting.
- Su p p ort co m p liance, assurance and accreditation activities by co llecting evidence, maintaining co n t r ol documentation and co ordinating remediation actions.
- Maintain accurate and auditable re co rds of security co n t r ols, risks, exce p tions, assessments and security-related decisions.
- Coordinate the alignment of security controls and p rocesses with the NIS T Cybersecurity Framework and a p p licable requirements under the Network and Information Systems ( NIS ) Regulations.
P rojects, guidance and documentation
- P rovide p racti cal security guidance to p rojects, techni cal teams and business a p p lication owners throughout the service lifecycle.
- Review p ro p osed techni cal changes and designs, identify cyber security risks and re co mmend p ro p ortionate co n t r ols.
- Create and maintain techni cal p rocedures, o p erational runbooks, su p p ort documentation and security training or awareness materials.
- Build effective working relationshi p s across IT and the wider business and liaise with su p p liers or p artners when required .
Key Job Requirements
Essential ex p erience and knowledge
- Significant hands-on ex p erience su p p orting co m p lex IT, network or cyber security environments; ty p i cal l y gained over five years in relevant techni cal roles.
- Strong understanding of cyber security p rinci p les across infrastructure, networks, end p oints, cloud services, identity and a p p lications.
- P racti cal knowledge of TC P /I P , firewalls, V P N technologies, DNS, DHC P , certificates and SSL/TLS.
- Ex p erience with vulnerability scanning, secure co n figuration assessment, remediation tracking and risk-based p rioritisation.
- Understanding of co m mon attack techniques, security mon i t oring, incident res p onse and re co g nis ed a p p lication security risks such as the OWAS P To p 10.
- Good understanding of the NIS / NIS T Cybersecurity Framework ( NIS T CSF) and its p racti cal a p p lication to identifying , p rotecting, detecting, res p onding to and recovering from cyber security risks.
- Understanding of the Network and Information Systems ( NIS ) Regulations and the techni cal , o p erational and orga nis ational measures required to su p p ort co m p liance.
- Ex p erience working towards Cyber Essentials
- Ability to p roduce and maintain security p olicies, standards, p rocedures, co n t r ol documentation and evidence for audits, assurance reviews and accreditation activities.
- Ability to inter p ret techni cal security information, investigate issues methodi cal l y and translate findings into clear, p ro p ortionate actions.
- Champions security and drives awareness throughout the company
- Willingness and ability to participate in ad hoc out-of-hours support where required .
Desirable ex p erience and qualifications
- Ex p erience admi nis t ering security ca p abilities within Microsoft Azure, Microsoft 365, Microsoft Entra ID, Microsoft Defender and/or Microsoft Sentinel.
- Ex p erience of SIEM, end p oint detection and res p onse, secure web gateway, email security, network security and p rivileged access technologies.
- Relevant current certifications such as Microsoft Security, Co m p liance and Identity, Azure, Co m p TIA Security+, CISS P , SSC P , CCNA Security or P alo Alto Networks certifications.
- ITIL Foundation certification or p racti cal ex p erience working within an IT service management framework.
- Ex p erience in a regulated, safety-criti cal , trans p ort, logistics or multi-site o p erational environment.
- Ex p erience su p p orting NIS co m p liance, security audits, assurance reviews, accreditation activities or certification p rogrammes.
Behavioural Co m p etencies
- Co mmunicates clearly and p rofessionally, including the ability to ex p lain co m p lex techni cal issues to non-techni cal co lleagues.
- Works cal mly and effectively in a fast- p aced environment, including during incidents and p eriods of o p erational p ressure.
- P rioritises work effectively, manages co m p eting demands and delivers agreed actions to deadlines.
- Uses initiative, sound judgement and a structured, methodi cal a p p roach to p roblem solving.
- De mon strates strong attention to detail while maintaining awareness of wider business and o p erational p riorities.
- Works co llaboratively as a natural team p layer and en co urages effective interaction across techni cal and business teams.
- De mon strates integrity, discretion and p ersonal ac co untability when handling sensitive information and security matters.
- Maintains a co mmitment to co n t inuous learning and kee p s techni cal knowledge current as threats and technologies evolve.
- Takes ownership, drives improvements and changes within the security field throughout the business
Why Join Us?
Here, you’re not one small part of a big machine. You’re a key contributor with national significance and real-world impact. We want our colleagues to feel proud of the work they do, connected to our mission and empowered to shape the future of this business. As part of Heavy Haul Rail, you can expect:
- Purpose that matters. Your work contributes to a cleaner, more efficient freight industry.
- Opportunity to shape what’s next. We’re new, agile and ready to do things differently, your ideas help build our future.
- A team that moves forward together. Collaboration, respect and shared ambition define how we work.
- A commitment to excellence. We deliver with pride, precision and professionalism.
- Room to grow. Your development fuels our momentum.
Our perks and benefits
Our people are our most important asset. We strive to empower our employees, ensuring they are trained and competent, fit for work, always informed, and completely engaged in our culture that places safety and wellbeing firmly at the heart of everything we do.
We are looking for the most committed and reliable individuals who possess the knowledge, skills and experience needed for their roles. In return we can offer considerable career progression, and a rewarding career in an award-winning team alongside:
- Competitive pay
- Fantastic final-salary pension scheme after an initial qualifying period
- Enhanced maternity & paternity pay
- Opportunities for ongoing training and development.
- Access to the company's life assurance scheme
- A range of benefits to make your own so you can get the most of your work and home life which will also help save you money and hassle. From reimbursement on health treatments, to savings on new cars.
Apply now
We know where we’re heading. We know why it matters. Now, it’s time to move, to make it real, together.
For queries contact [email protected]
Shaping tomorrow. Starting today
The future we want to build won’t happen on its own, we have to move it forward, together. Heavy Haul Rail has the purpose, the ambition and the opportunity to reshape how Britain moves. Whatever our roles, we are collaborators, creators and custodians of a better future. This journey starts with what we choose to do today, tomorrow and every day after that.
Our values are:
- Make Every Mile Matter : We act with intention and responsibility, knowing our work shapes a cleaner, stronger future for the UK.
- Build Boldly : We use our entrepreneurial spirit to challenge legacy thinking and design better ways forward, for our customers, our industry and each other.
- We move as one: We collaborate with trust, respect and shared momentum, because progress is a team sport.
- Deliver with certainty : We stand behind our work. We’re reliable, precise and accountable in everything we do.
- Fuelling The Future: We invest in our people and our potential, championing learning, curiosity and continuous improvement. with confidence, clarity, and measurable impact.