Threat Intelligence Lead
Job in
Glasgow, Glasgow City Area, G1, Scotland, UK
Listed on 2026-09-14
Listing for:
Iberdrola
Part Time
position Listed on 2026-09-14
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Job Description & How to Apply Below
Permanent, Hybrid (2-3 days per week in office)
Help us create a better future, quickerSP Energy Networks (SPEN) has kicked off an ambitious security transformation programme to transparently reduce risk, achieve compliance with NIS regulations and deliver a cyber resilient business, and the Cyber Threat Intelligence Lead will be essential in achieving our goals.
This role will be integrated into an active and ambitious global cyber security function, contributing to SPEN’s cyber security purpose of delivering cyber resilient OT and IT, to enable a safe and reliable electricity supply to customers.
What you’ll be doing
In this role you will be responsible for monitoring the threat landscape, analysing emerging risks, and delivering timely intelligence that supports Security Operations Centre (SOC) activities, incident response, threat hunting, detection engineering, risk management and the wider business. You will assess adversary tactics, techniques and procedures (TTPs), develop intelligence led recommendations, and ensure that threat intelligence is effectively integrated into wider security operations, vulnerability management and risk management programmes.
A key part of the role is to collect process, analyse and disseminate threat assessments and indicators. You will develop a strong understanding of the networks and systems within our environment to contextualise threat intelligence to support control implementation, detection coverage and ensuring our defences are aligned to real-world adversary tradecraft. You will help transform intelligence into actionable decisions, strengthen monitoring capabilities and drive improvement across the detection and response lifecycle.
There will also be the chance to research new and specialist techniques, working cross industry, and helping to shape our OT LAB.You will be accountable for liaising and curating long term relationships with stakeholders to understand, document, prioritise, and communicate intelligence requirements. You will collaborate with threat detection, security monitoring, and incident response teams, providing subject matter expertise, sharing knowledge and developing/ coordinating intelligence sharing with trust groups.
You will communicate the threat landscape and recommended actions to senior leadership, ensuring that the key threats to the business are understood from a top-down approach.
Other parts of the role involve identifying and supporting the integration of threat intelligence sources, commercial or other, to ensure the organisation has robust coverage of the threat landscape they face.
What you’ll bring
The successful candidate will contribute to compliance with CAF and NIS requirements by providing intelligence driven analysis, evidence, reporting and operational support. You will also help improve alert fidelity, triage quality, and threat detection effectiveness by translating intelligence into practical detection requirements and investigative use cases.
This is an opportunity for an experienced cyber security professional with a background in threat intelligence, SOC operations or detection analysis. You should have a strong understanding of attacker tactics and techniques, analytical frameworks, experience working with SIEM or SOAR technologies, threat hunting methodologies and a strong knowledge of the MITRE ATT&CK framework across both Enterprise and ICS environments. Experience supporting regulatory and security frameworks such as CAF, NIS, NCSC guidance, or similar will be highly beneficial.
Knowledge of OT security principles, ICS environments, IEC 62443, networking fundamentals, and detection engineering would be…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×