Application Cyber Security Lead in Glasgow

Application Cyber Security Lead in Glasgow

Glasgow Full-Time 48000 - 72000 € / year (est.) No home office possible
Iberdrola

At a Glance

  • Tasks: Lead the implementation of secure software development practices across ScottishPower.
  • Company: ScottishPower is a leader in renewable energy, part of the Iberdrola Group.
  • Benefits: Enjoy 36 days annual leave, pension matching, and various health and wellness perks.
  • Other info: ScottishPower values diversity and offers support for candidates with disabilities.
  • Why this job: Join a mission-driven team focused on cybersecurity and sustainability in a global organisation.
  • Qualifications: Knowledge of Secure Software Development Life Cycle and web application security is essential.

The predicted salary is between 48000 - 72000 € per year.

The Application Cyber Security Lead will work within the Digital Transformation team, working across all ScottishPower businesses, with the objective of rolling out the Global Application Security Model, to ensure best practices for secure software development. The Application Cybersecurity Lead will coordinate and collaborate with the global business, defining projects, initiatives and standards, making sure these are adopted across the business.

A key focus of this role will be to implement and evolve the application security model, aligning it to the Global Application Cybersecurity team, ensuring standards and best practices are fully integrated into the Software Development Lifecycle. Within this role, you’ll lead on vulnerability management, promoting the adoption and execution of the global vulnerability management processes and controls. This includes:

  • Inventorying of logical components and dependencies of business solutions
  • Proactively discovering vulnerabilities
  • Coordinating the execution of scanning, pen testing, or in general the activities and services of vulnerability identification
  • Vulnerability assessment
  • Remediation and mitigation of vulnerabilities
  • Solution verification
  • Reporting
  • Contributing to the evolution of the process for vulnerability management.

Lead security assessments of commercial packages. You’ll look to continually evolve the implementation of cybersecurity, implementing new measures and optimising those already in place. You’ll act as the owner and subject matter expert for the Secure Software Development Standards, Methods and Tools, and has the overall accountability to:

  • Work with the global teams to influence, direct and understand the Iberdrola defined standards
  • Take overall accountability for the governance, oversight, and adoption of these standards within ScottishPower.
  • Lead the education, training, and awareness of standards
  • Implement governance and control mechanisms to ensure compliance

What we’re looking for

  • Detailed knowledge of the Secure Software Development Life Cycle (S-SDLC)
  • Knowledge and understanding of cybersecurity threats and associated attack techniques.
  • Design knowledge: modelling of components, data, interfaces, etc.
  • Threat analysis and modelling
  • Knowledge of web application security
  • Vulnerability discovery techniques and vulnerability lifecycle scanning and management.
  • Knowledge of application security architecture: segmentation, API Gateway, Encryption, Privileged Account Management, WAF, publishing, event collection tools and alert management.
  • Stakeholder management, with the ability to work across multiple projects and teams.

What’s in it for you

As well as a competitive salary which is reviewed annually, you can also enjoy a number of other benefits. With our pension scheme, we’ll double match your contribution up to a company contribution of 10%. At ScottishPower, we believe it’s the little things we do in life that make a big difference. From helping you look after your family’s wellbeing, save for your future and take personal steps for climate action – our benefits are designed to help you do just that - so that you have everything you need to take care of your world – today and tomorrow. That’s why our benefits include:

  • 36 days annual leave
  • Holiday purchase – perfect your work/life balance with extra annual leave
  • Share Incentive Plan and Sharesave Scheme
  • Payroll giving and charity matched funding
  • Technology Vouchers – save more and spread the cost of your technology purposes
  • Count us in – pledge to reduce carbon emissions and help fight climate change
  • Electric Vehicle Schemes – to help you transition to green/clean driving
  • Cycle to Work scheme and public transport season ticket loans
  • Options to purchase dental insurance, private medical insurance, health cash plan and annual health assessments
  • Life Assurance (4x salary)
  • Access to ‘nudge’ financial wellbeing support
  • Plus shopping, leisure, restaurant and gym discounts, and unique employee deals on travel insurance and more

Why ScottishPower

ScottishPower is part of the Iberdrola Group, one of the world’s largest integrated utility companies and a world leader in wind energy. With a commitment to generate all of our energy from renewable resources and a drive to create the energy infrastructure of the future, we’re at the forefront of the journey to Net Zero and investing over £6m every working day to make this happen. With diverse opportunities across our businesses and a commitment to invest in our own internal talent, ScottishPower can offer people real career opportunities that meet personal and professional goals, in a global organisation. Inclusion, diversity, and a social purpose are at the heart of everything we do. Together with our values, they bring us together into a stronger, more sustainable business with direct links to the communities we serve. It takes all kinds of people to build a large-scale business like ours, so whatever your background, you’ll fit right in. ScottishPower is committed to providing reasonable support or adjustments in our recruiting processes for candidates with disabilities, long term conditions, mental health conditions, or who are neurodivergent or require pregnancy-related support.

Application Cyber Security Lead in Glasgow employer: Iberdrola

ScottishPower is an exceptional employer, offering a dynamic work culture that prioritises employee wellbeing and professional growth. With a strong commitment to sustainability and innovation in the energy sector, employees benefit from extensive training opportunities, a generous benefits package including 36 days of annual leave, and initiatives that support a healthy work-life balance. Located at the forefront of the renewable energy transition, ScottishPower fosters an inclusive environment where diverse talents thrive, making it an ideal place for those seeking meaningful and impactful careers.

Iberdrola

Contact Detail:

Iberdrola Recruiting Team

StudySmarter Expert Advice🤫

We think this is how you could land Application Cyber Security Lead in Glasgow

Tip Number 1

Familiarise yourself with the Secure Software Development Life Cycle (S-SDLC) and be prepared to discuss how you've applied it in previous roles. Highlight any specific projects where you implemented security measures during the development process.

Tip Number 2

Showcase your knowledge of vulnerability management by discussing any tools or techniques you've used for vulnerability discovery and assessment. Be ready to explain how you prioritised vulnerabilities and managed remediation efforts.

Tip Number 3

Demonstrate your stakeholder management skills by preparing examples of how you've collaborated with cross-functional teams. Emphasise your ability to influence and direct teams towards adopting security standards and best practices.

Tip Number 4

Stay updated on the latest cybersecurity threats and trends, particularly those related to web application security. Being able to discuss recent incidents or emerging attack techniques will show your commitment to continuous learning in this field.

We think you need these skills to ace Application Cyber Security Lead in Glasgow

Secure Software Development Life Cycle (S-SDLC)
Cybersecurity Threat Analysis
Vulnerability Management
Web Application Security
Vulnerability Discovery Techniques
Application Security Architecture
Stakeholder Management

Some tips for your application 🫡

Understand the Role:Before applying, make sure you fully understand the responsibilities and requirements of the Application Cyber Security Lead position. Familiarise yourself with the Secure Software Development Life Cycle (S-SDLC) and the specific cybersecurity threats mentioned in the job description.

Tailor Your CV:Customise your CV to highlight relevant experience and skills that align with the job description. Emphasise your knowledge of application security architecture, vulnerability management, and stakeholder management, as these are key aspects of the role.

Craft a Compelling Cover Letter:Write a cover letter that showcases your passion for cybersecurity and your understanding of the company's mission. Mention specific examples from your past experiences that demonstrate your ability to implement and evolve application security models.

Highlight Continuous Learning:In your application, mention any ongoing education or certifications related to cybersecurity. This shows your commitment to staying updated on industry standards and best practices, which is crucial for the role.

How to prepare for a job interview at Iberdrola

Understand the Secure Software Development Life Cycle (S-SDLC)

Make sure you have a solid grasp of the S-SDLC and be prepared to discuss how it integrates with application security. Highlight your experience in implementing these practices in previous roles.

Showcase Your Vulnerability Management Skills

Be ready to talk about your experience with vulnerability discovery techniques and lifecycle management. Provide examples of how you've successfully identified and remediated vulnerabilities in past projects.

Demonstrate Stakeholder Management Experience

This role requires collaboration across multiple teams. Prepare to share specific instances where you've effectively managed stakeholders and influenced project outcomes, especially in a cybersecurity context.

Stay Updated on Cybersecurity Threats

Familiarise yourself with current cybersecurity threats and attack techniques. Being able to discuss recent trends or incidents will show your passion for the field and your proactive approach to security.