Lead OT Cyber Security & Monitoring Engineer
Warwick, Warwickshire, CV34, England, UK
Listed on 2026-09-03
-
IT/Tech
Cybersecurity, Systems Engineer, Network Security
About Us
National Grid Electricity Transmission (NGET) is at the heart of energy in the UK. The electricity that our network provides gets the nation to work, powers schools and brings energy to life. Our network connects the nation, so it’s essential that it’s continually evolving, advancing, and improving. In NGET we are passionate about both operating safely and providing highly reliable quality of supply for our customers.
We are seeking a Lead OT Security Engineer to strengthen the cyber security monitoring capability across National Grid Electricity Transmission's OT environment. You will provide technical leadership to enhance OT cyber detection, monitoring and alerting capabilities, working closely with the CSOC, CSIRT, operational teams, engineering stakeholders and strategic suppliers to improve visibility of cyber risk across critical operational systems.
This role is based in Warwick for 2 days per week and can be combined with hybrid working from home.
Job PurposeWe're passionate about operating our network safely and providing highly reliable quality of supply for our customers. At the heart of achieving these outcomes is the effective monitoring, detection and response to cyber threats across our Operational Technology (OT) estate.
The role acts as the OT subject matter expert for monitoring and alerting activities, providing operational context, asset knowledge and engineering insight to help enterprise cyber security teams assess, prioritise and respond to security events affecting OT environments. Working across both OT and cyber security communities, the role will help shape detection capabilities, improve monitoring effectiveness and strengthen cyber resilience across the electricity transmission network.
The role will also support the development of OT monitoring strategy, detection engineering, security roadmaps and incident response readiness, ensuring monitoring solutions and longer‑term capability plans remain effective against evolving threats while supporting the safe and reliable operation of critical operational systems.
What You'll Do- Lead the development and continuous improvement of OT cyber monitoring, detection, and alerting capabilities across operational environments.
- Develop and influence OT security strategies, roadmaps, and capability plans, aligning operational risks, threat intelligence, regulatory requirements, and engineering priorities.
- Provide expert OT cyber security guidance and risk-based recommendations to engineering, operational, cyber security, and supplier stakeholders.
- Act as the key liaison between OT operations and enterprise cyber security teams, ensuring OT‑specific risks and operational considerations are reflected in security processes.
- Apply specialist knowledge of OT monitoring technologies, industrial control systems, and cyber threat detection to improve visibility and resilience across critical assets.
- Drive the development of detection use cases, alert tuning, monitoring enhancements, reporting, and performance metrics to strengthen security assurance and effectiveness.
- Support cyber incident response and preparedness activities, providing OT expertise for investigations, recovery, exercises, and continuous improvement initiatives.
- Coach and mentor colleagues, promoting knowledge sharing and consistency across OT cyber security and engineering teams.
- Collaborate with industry partners and suppliers to enhance monitoring, detection, incident response, and long‑term cyber resilience capabilities.
- Proven experience in cyber security operations, threat detection, and incident response within Operational Technology (OT), industrial control systems, or regulated Critical National Infrastructure (CNI) environments.
- Strong understanding of OT environments, incident response life cycles, cyber threats, and the challenges of securing critical infrastructure.
- Experience investigating cyber security incidents and supporting response, recovery, and resilience activities in OT or industrial environments.
- Knowledge of security monitoring, intrusion detection, network monitoring, and OT security platforms such as Dragos or equivalent.
- Understanding of…
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: