An application made for this job — a tailored resume and cover letter that speak straight to the posting.
SP Energy Networks (SPEN) in Glasgow is seeking an Incident Response Lead to strengthen our cyber security capabilities by developing, maintaining, and improving incident playbooks, runbooks, and procedures across OT and IT environments. You will collaborate with incident responders, detection engineers, and wider cyber teams to ensure playbooks are clear, repeatable, and aligned with best practice.
The role covers the full incident lifecycle, including post-incident reviews and exercises to
Incident Response Lead
Scottish Power HQ, Glasgow
Flexible & Hybrid working pattern
Negotiable rate, Inside IR35, PAYE and UMB options available
Help us create a better future, quicker
SP Energy Networks (SPEN) has kicked off an ambitious security transformation programme to transparently reduce risk, achieve compliance with NIS regulations and deliver a cyber resilient business and the Incident Response Lead is essential in achieving our goals.
This role will be integrated into an active and ambitious global cyber security function, contributing to SPEN’s cyber security purpose of delivering cyber resilient OT and IT, to enable a safe and reliable electricity supply to customers.
You will play a central role in strengthening SPEN’s incident response capability by developing, maintaining, and continuously improving cyber security playbooks, procedures, and associated documentation. You’ll work closely with incident responders, detection engineers, and wider cyber teams to ensure processes are clear, repeatable, and aligned with best practice.
You’ll support the full incident lifecycle - from preparation through to post incident review - ensuring lessons learned are captured, documented, and fed into future improvements. As part of this, you will contribute to the maturity of SPEN’s cyber response framework, ensuring playbooks are operationally effective, compliant with NIS regulations, and tailored to our evolving OT and IT environments.
You will also be responsible for developing and delivering an incident response exercise plan covering a range of scenarios designed to test team readiness, validate playbooks, and ensure operational effectiveness. These exercises may include tabletop scenarios, technical simulations, cross team coordination drills, and lessons learned reviews that contribute directly to capability uplift.
Building strong working relationships across the business will be key. You’ll engage with operational, engineering, legal, risk, communications, and technology stakeholders to understand their requirements, coordinate incident response activities when required, and ensure that documentation and processes reflect real world operational needs.
You will also have the opportunity to help shape the wider strategy of the Incident Response function - identifying capability gaps, contributing to team roadmaps, supporting cross industry collaboration, and driving continual service improvement within SPEN’s cyber resilience programme.