Overview
Cyber Security Vulnerability Lead
Location: GlasgowSalary: £57-£72K (up to 15% bonus & private healthcare)Hybrid working: 2-3 days per weekContract: Permanent
Due to the nature of the role, the successful candidate will need to be able to obtain NSV SC clearance. You will need to have lived continuously in the United Kingdom for a period of 5 years before being eligible to meet the Minimum Residency Criteria.
Help us create a better future, quicker. ScottishPower is embarking on a Cyber Security Transformation Programme. We are looking for a Cyber Security Vulnerability Lead to coordinate with our Global Cyber Fusion centre and UK ScottishPower businesses. This role will oversee the delivery, integration and operation of the tools and services provided by the UK CSIRT, Threat & Intelligence team, Vulnerability Management team and Security Engineering team.
What you’ll be doing
- The Cyber Security Vulnerability Lead will coordinate security vulnerability identification services such as Red Teaming and general penetration testing facilitation across the ScottishPower group and integration with existing business processes, defining a programme of security initiatives for inclusion in the Global Security Plan relating to the Cyber Fusion centre.
- Report to the Cyber Security Vulnerability Manager and coordinate with the Global Cyber Fusion Centre and UK ScottishPower businesses. Engage with other Group Cyber Security functions and Business Cyber Security teams.
- Provide subject matter expertise into the security strategy to maximise value from Cyber Fusion centre tools. Coordinate the strategic roadmap that defines the operating model for delivering the Cyber Fusion centre model in the UK, including security tools, resources and processes to evolve UK CFC services and maximise existing investment.
- Define a program of security initiatives, manage senior stakeholders, and work with OT security functions to deliver an integrated IT/OT security strategy.
What you’ll bring
- Significant experience of Security Operations in an organisation of similar scope and scale to ScottishPower; experience in a global organisation preferred.
- Experience as a technical lead on security control enhancement programmes.
- Experience configuring and supporting security tools and services.
- Experience leading activities relating to vulnerabilities from minor to high/critical impact levels.
- Experience managing security service providers and security software suppliers.
- Awareness of key legislation and regulation affecting IT Security in an energy utility.
- Experience and understanding of OT Security challenges and solutions.
- SME input into IT Security Operations Strategies and Product Roadmaps.
- Specialist knowledge of IT and OT Security evidenced by relevant industry qualifications (e.g. CISSP, CISM, GICSP, OSCP).
What’s in it for you
As well as a competitive salary, you can enjoy a number of benefits. With our pension scheme, we double match your contribution up to a company contribution of 10%.
ScottishPower is part of the Iberdrola Group, committed to renewable energy and a path to Net Zero. We offer diverse opportunities and invest in internal talent, providing real career opportunities within a global organisation.
We value inclusion and are committed to providing reasonable support or adjustments in our recruitment processes for candidates with disabilities, long-term conditions, mental health conditions, neurodivergence, or who require pregnancy-related support.
#J-18808-Ljbffr…
