CareerPlanSign in

Cyber Incident Operations Lead

United Kingdom, Glasgow💼 Full-time💰 $59,000–$59,000🗓 2026-07-28 → 2026-09-26

Core

Lead the full cyber incident lifecycle (readiness, detection, investigation, containment, eradication, recovery, post-incident improvement) for complex IT and Operational Technology (OT) environments.

Role type

Senior IC Cyber Incident Operations Lead

Builds

Cohesive proactive operational strategy integrating incident response, threat intelligence, and detection engineering

Domain

Energy sector (Utility) + Cyber Security + Operational Technology (OT)

Deliverable

production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work

Required skills

Leading multidisciplinary teams through major incidents, operating in regulated/critical infrastructure environments, understanding IT/OT system challenges, threat-led detection engineering, adversary frameworks (MITRE ATT&CK, ICS ATT&CK), cyber threat modelling, crisis communications, executive reporting, MSSP relationship management, post-incident reviews

Preferred skills

GCIH, GCFA, GNFA, CREST Incident Manager, ICS515, ICS418 certifications, knowledge of IEC 62443, knowledge of cyber security frameworks for critical national infrastructure

Technologies

MITRE ATT&CK, ICS ATT&CK, IEC 62443

Responsibilities

Coordinate multidisciplinary teams (IT, OT, MSPs, vendors, stakeholders) during high-impact incidents, maintain operational readiness via exercises and scenario planning, translate technical incidents into business/regulatory impact, provide expert insight into governance and cyber strategy

Seniority

Senior, hands-on IC with leadership capability

Sourced via workday · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.