At a Glance
- Tasks: Lead the design and delivery of impactful cyber incident exercises for UK clients.
- Company: Join Intelance, a forward-thinking advisory firm in the cyber security space.
- Benefits: Flexible remote work, competitive day rates, and support from a skilled team.
- Other info: Opportunity to influence service methods and develop your professional network.
- Why this job: Shape the future of cyber incident response while working with senior stakeholders.
- Qualifications: 3+ years in cyber incident exercises and strong communication skills required.
The predicted salary is between 63000 - 77000 £ per year.
Intelance is a UK advisory and assurance firm building a formal Cyber Incident Exercising service aligned with the NCSC CIE Technical Standard.
We are appointing an experienced Team Lead as an associate contractor to lead the design, delivery and assurance of organisationally significant tabletop and live play exercises for UK clients.
This is an associate panel role.
Assignments will be agreed separately through a clear scope, timetable and day rate.
The role includes remote design work, facilitated sessions and travel to client sites across the UK.
- Tasks
- Lead the complete Design, Develop, Conduct and Evaluate life cycle for cyber incident exercises.
- Scope exercises with clients and agree objectives, participants, assumptions, dependencies, safety controls and success measures.
- Design credible threat led scenarios using current threat intelligence, relevant tactics, techniques and procedures and frameworks such as MITRE ATT&CK.
- Lead both tabletop and live play exercises for organisationally significant cyber incidents.
- Develop injects, timelines, participant materials, exercise control plans, observation records and communications.
- Facilitate exercises for Board, management and operational participants.
- Direct the exercise control function, manage pace and adapt delivery safely in response to player actions.
- Coordinate technical, legal, regulatory, communications and business continuity stakeholders.
- Lead debriefs, identify clear lessons and produce concise reports with practical actions.
- Maintain client case studies, references, feedback and scheme evidence.
- Coach other Intelance facilitators and help maintain a defined, repeatable CIE delivery method.
- Apply relevant UK incident reporting and escalation knowledge, including the NCSC, law enforcement, Action Fraud and the Information Commissioner's Office.
Requirements
Essential
- At least three years of experience delivering cyber incident exercises for external clients where exercising formed a key part of the role, or evidence of having passed the IASME CIE Team Lead test.
- Direct experience of both tabletop and live play exercises for organisationally significant incidents.
- Delivery experience at two or more levels: Board, management and operational.
- Physically based in the UK and able to travel to client locations.
- Proven experience leading exercise scoping, scenario development, inject design, exercise control, facilitation, debriefing and reporting.
- Strong knowledge of cyber incident response plans, incident management, business continuity and crisis communications.
- Able to use threat intelligence and real world tactics, techniques and procedures to build credible scenarios.
- Working knowledge of UK cyber incident reporting, law enforcement, Action Fraud, the Information Commissioner's Office and relevant legal or regulatory duties.
- Able to provide client case studies, sample outputs and references. Anonymised material is acceptable initially.
- Strong written and spoken communication across technical and senior business audiences.
- Clear understanding of safe exercise delivery, confidentiality and conflicts of interest.
Desirable
- Previous work against the NCSC CIE Technical Standard.
- NCSC Exercise in a Box, NIST SP 800 84 or equivalent exercise methodology experience.
- Experience in regulated industries, public sector, critical infrastructure or complex supply chains.
- Incident response, crisis management, threat intelligence or digital forensics qualifications.
- Experience building or leading a repeatable cyber exercising service.
Benefits
- Take a leading role in building Intelance's NCSC aligned Cyber Incident Exercising capability.
- Lead clearly scoped UK client exercises with senior stakeholder access.
- Flexible project based associate work with remote design and agreed client site delivery.
- A written scope, timetable and agreed day rate before each assignment.
- Support from Intelance's wider cyber assurance, architecture, ISO and governance team.
- Access to structured delivery templates, secure collaboration and quality controls.
- Opportunity to shape the service method, exercise library and facilitator capability.
Shortlisted candidates will be asked for evidence and references.
Anonymised case studies and redacted sample outputs are sufficient at application stage.
Do not send confidential client material.
#J-18808-Ljbffr
Cyber Incident Exercising Team Lead (NCSC CIE Scheme), Associate employer: Intelance Digital Enablement Services Ltd
Intelance is an exceptional employer, offering a dynamic work environment where M&A Integration Leads can thrive through diverse, high-profile deal work. With a focus on long-term engagement and a roll-on/roll-off model, employees benefit from continuous learning and exposure to complex global integration programmes, all while collaborating with senior architects and leadership in the heart of London. The company fosters a culture of innovation and support, ensuring that every team member has the opportunity for meaningful growth and development.
Contact Details:
Intelance Digital Enablement Services Ltd Recruitment Team
StudySmarter Expert Advice🤫
We think this is how you could land Cyber Incident Exercising Team Lead (NCSC CIE Scheme), Associate
✨Get Active on Cybersecurity Forums
Join platforms like Stack Exchange and Reddit’s r/cybersecurity to hang out with industry pros, learn the latest, and share your insights. This will not only boost your visibility but also help you connect with potential clients who might need your freelance services.
✨Show Off Your Skills with Public Projects
Create a few open-source projects or contribute to existing ones that showcase your cybersecurity skills. Use GitHub to display your work, as this is an excellent way to attract clients looking for freelancers with a proven track record.
✨Attend Local Conferences and Meetups
Make sure to hit up cybersecurity meetups, workshops, and conferences in your area. These events are goldmines for networking, and you’ll often find people looking for freelancers after a chat over a coffee – so come prepared with your business cards and a killer elevator pitch!
✨Market Yourself Smartly
Set up a professional website that showcases your portfolio, expertise, and client testimonials. Optimise it for SEO with relevant keywords so potential clients searching for cybersecurity freelancers can easily find you. Don’t forget to link to your site on all your social media and profiles!
We think you need these skills to ace Cyber Incident Exercising Team Lead (NCSC CIE Scheme), Associate
Some tips for your application 🫡
Show Your Skills Through a Strong Portfolio:Since you're applying for a freelance role in cybersecurity, it's crucial to showcase your technical skills through a detailed portfolio. Include case studies of projects you've worked on, any security tools you've developed or assessed, and specifics on the methodologies you’ve used. This will help Intelance Digital Enablement Services Ltd understand what you're capable of.
Certifications Matter!:Make sure to list any relevant certifications you hold, such as CISSP, CEH, or CompTIA Security+. Freelance clients often value these credentials as they reflect your expertise and commitment to the field. If you’re actively pursuing more certifications, don’t hesitate to mention that too!
Rates, Availability, and Your Work Style:In your application, it’s essential to be clear about your freelance rates and availability. Clients appreciate transparency. Mention how many hours a week you can dedicate and your preferred working hours, as this sets expectations from the start and shows you're organised and professional.
Tailor Your CV to Highlight Cybersecurity Experience:When crafting your CV, make sure to tailor it specifically to cybersecurity. Highlight projects, tasks, and achievements related to security assessments, vulnerabilities you've mitigated, or compliance work you've undertaken. Keywords relevant to the job can grab attention and increase your chances of landing a spot at Intelance Digital Enablement Services Ltd.
How to prepare for a job interview at Intelance Digital Enablement Services Ltd
✨Showcase Your Cybersecurity Skills
As a freelancer in cybersecurity, it’s crucial we demonstrate not just our knowledge but our practical skills too. Be ready to discuss specific tools you’ve used, like Wireshark or Metasploit, and share relevant experiences where you identified vulnerabilities or mitigated risks in past projects.
✨Prepare Your Portfolio
Unlike traditional roles, freelancing relies heavily on your portfolio. Let’s curate a selection of past work that showcases our best projects. If we’ve handled penetration tests, audits, or incident responses, be sure to highlight these in your portfolio, and share any client testimonials if we have them.
✨Stay Updated on Trends and Tools
Cybersecurity is an ever-evolving field, so we should be prepared to chat about recent developments and how they impact our work. Familiarise ourselves with the latest threats, tools, and frameworks, like MITRE ATT&CK, that are pertinent to the projects we’re pitching.
✨Pitching Your Value as a Freelancer
When freelancing, we often need to negotiate our rates and value propositions. Be ready to explain how our skills can help Intelance Digital Enablement Services Ltd protect their assets and manage risks. It can help to outline some potential strategies or improvements we could implement for them based on their current setup.