> Markdown version of [/jobs/ext/1492138-cyber-incident-operations-lead](https://www.wearedevelopers.com/jobs/ext/1492138-cyber-incident-operations-lead). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Incident Operations Lead - **Company:** Scottish Power - **Location:** Glasgow, UK - **Experience:** Expert - **Salary:** £59,000.0 - £74,000.0 - **Contract:** Temporary to permanent - **Skills:** Cyber Security, Digital Forensics, Intrusion Detection and Prevention, Mitre Att&ck, SC Clearance, Information Technology, Cybercrime, Operational Systems, Cyber Warfare - **Published:** July 30, 2026 - **Apply:** https://uk.indeed.com/viewjob?jk=ac8fcefb77a78733 ## About the Role The successful candidate will bring significant experience in cyber incident response, security operations or digital forensics, with a strong track record of leading multidisciplinary teams through major incidents. You will have experience operating within regulated or critical infrastructure environments and an understanding of the unique challenges associated with OT and IT systems. Knowledge of threat-led detection engineering, adversary frameworks such as MITRE ATT&CK and ICS ATT&CK, and cyber threat modelling methodologies will be highly valued. You will be comfortable engaging with senior stakeholders, translating technical incidents into business and regulatory impact, and providing clear decision-making support during high-pressure situations. Experience managing MSSP relationships, contributing to crisis communications and executive-level reporting, and driving continuous improvement through post-incident reviews will be important for success in the role. Professional certifications such as GCIH, GCFA, GNFA, CREST Incident Manager, ICS515 or ICS418 are desirable but not essential, alongside knowledge of IEC 62443 and cyber security frameworks relevant to critical national infrastructure. The ability to achieve SC Clearance is essential. This is an excellent opportunity for a cyber security professional who combines deep technical expertise with strong leadership capability and thrives in fast-paced, high-consequence environments. In return, you will have the opportunity to influence cyber resilience at an organisational level, shape strategic incident response capability and play a key role in protecting critical operations. Candidates must speak english to a native level/proficiently. ## Description We are looking for an experienced Incident Response Lead to play a critical role in strengthening and evolving SPR's cyber defence capability across complex IT and Operational Technology (OT) environments. Working closely with the Incident Response Manager, you will ensure the organisation is prepared to detect, analyse and respond to cyber threats by bringing together incident response, threat intelligence and detection engineering into a cohesive and proactive operational strategy. What You'll Be Doing In this highly influential role, you will lead the full cyber incident lifecycle, from readiness and threat detection through investigation, containment, eradication, recovery and post-incident improvement. You will ensure that threat intelligence directly informs detection capabilities and response decisions, while lessons learned from incidents are translated into stronger controls, enhanced detection logic, improved playbooks and wider cyber resilience initiatives. As the lead during high-impact cyber incidents, you will coordinate multidisciplinary teams across IT, OT, managed security providers, vendors and corporate stakeholders, ensuring incidents are managed safely, effectively and in line with regulatory requirements, industry frameworks and organisational priorities. You will maintain operational readiness through regular exercises, scenario planning and continuous improvement of incident response processes and procedures. Acting as deputy to the Incident Response Manager when required, you will represent Cyber Operations during major incidents and provide expert insight into governance, executive reporting, crisis communications and cyber strategy. Your contribution will be key in ensuring incident response outcomes drive measurable improvements across the organisation's broader cyber defence ecosystem. ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [UK Business Culture and Etiquette](https://www.wearedevelopers.com/magazine/326-uk-business-culture-and-etiquette) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)