Cyber Incident Operations Lead
Listed on 2026-09-20
-
IT/Tech
Cybersecurity
Salary: £59-74K (plus up to 15% bonus, 15% pension and private healthcare)
Location: Glasgow (hybrid, 2-3 days in the office)
Permanent, Full time
Due to the nature of the role, the successful candidate will need to be able to obtain NSV SC clearance – You will need to have lived continuously in the United Kingdom for a period of 5 years before being eligible to meet the Minimum Residency Criteria
Help us create a better future, quicker
We are looking for an experienced Incident Response Lead to play a critical role in strengthening and evolving SPR’s cyber defence capability across complex IT and Operational Technology (OT) environments. Working closely with the Incident Response Manager, you will ensure the organisation is prepared to detect, analyse and respond to cyber threats by bringing together incident response, threat intelligence and detection engineering into a cohesive and proactive operational strategy.
WhatYou’ll Be Doing
In this highly influential role, you will lead the full cyber incident lifecycle, from readiness and threat detection through investigation, containment, eradication, recovery and post-incident improvement. You will ensure that threat intelligence directly informs detection capabilities and response decisions, while lessons learned from incidents are translated into stronger controls, enhanced detection logic, improved playbooks and wider cyber resilience initiatives.
As the lead during high-impact cyber incidents, you will coordinate multidisciplinary teams across IT, OT, managed security providers, vendors and corporate stakeholders, ensuring incidents are managed safely, effectively and in line with regulatory requirements, industry frameworks and organisational priorities. You will maintain operational readiness through regular exercises, scenario planning and continuous improvement of incident response processes and procedures.
Acting as deputy to the Incident Response Manager when required, you will represent Cyber Operations during major incidents and provide expert insight into governance, executive reporting, crisis communications and cyber strategy. Your contribution will be key in ensuring incident response outcomes drive measurable improvements across the organisation’s broader cyber defence ecosystem.
What You’ll BringThe successful candidate will bring significant experience in cyber incident response, security operations or digital forensics, with a strong track record of leading multidisciplinary teams through major incidents. You will have experience operating within regulated or critical infrastructure environments and an understanding of the unique challenges associated with OT and IT systems. Knowledge of threat-led detection engineering, adversary frameworks such as MITRE ATT&CK and ICS ATT&CK, and cyber threat modelling methodologies will be highly valued.
You will be comfortable engaging with senior stakeholders, translating technical incidents into business and regulatory impact, and providing clear decision‑making support during high‑pressure situations. Experience managing MSSP relationships, contributing to crisis communications and executive‑level reporting, and driving continuous improvement through post‑incident reviews will be important for success in the role.
Professional certifications such as GCIH, GCFA, GNFA, CREST Incident Manager, ICS
515 or ICS
418 are desirable but not essential, alongside knowledge of IEC 62443 and cyber security frameworks relevant to critical national infrastructure. The ability to achieve SC Clearance is essential.
This is an excellent opportunity for a cyber security professional who combines deep technical expertise with strong leadership capability and thrives in fast-paced, high-consequence…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).