Cyber Incident Operations Lead
Core
Lead the full cyber incident lifecycle (readiness, detection, investigation, containment, eradication, recovery, post-incident improvement) for complex IT and Operational Technology (OT) environments.
Role type
Senior IC Cyber Incident Operations Lead
Builds
Cohesive proactive operational strategy integrating incident response, threat intelligence, and detection engineering
Domain
Energy sector (Utility) + Cyber Security + Operational Technology (OT)
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Leading multidisciplinary teams through major incidents, operating in regulated/critical infrastructure environments, understanding IT/OT system challenges, threat-led detection engineering, adversary frameworks (MITRE ATT&CK, ICS ATT&CK), cyber threat modelling, crisis communications, executive reporting, MSSP relationship management, post-incident reviews
Preferred skills
GCIH, GCFA, GNFA, CREST Incident Manager, ICS515, ICS418 certifications, knowledge of IEC 62443, knowledge of cyber security frameworks for critical national infrastructure
Technologies
MITRE ATT&CK, ICS ATT&CK, IEC 62443
Responsibilities
Coordinate multidisciplinary teams (IT, OT, MSPs, vendors, stakeholders) during high-impact incidents, maintain operational readiness via exercises and scenario planning, translate technical incidents into business/regulatory impact, provide expert insight into governance and cyber strategy
Seniority
Senior, hands-on IC with leadership capability