Threat Intelligence Lead in Glasgow

Threat Intelligence Lead in Glasgow

Glasgow Full-Time 63000 - 77000 £ / year (est.) Home office (partial)
S

At a Glance

  • Tasks: Lead cyber threat intelligence efforts to protect critical infrastructure and enhance security operations.
  • Company: Join SP Energy Networks, a leader in renewable energy and cyber resilience.
  • Benefits: Enjoy competitive salary, double-matched pension, 36 days leave, and unique employee perks.
  • Other info: Diverse opportunities for career growth in a supportive and inclusive environment.
  • Why this job: Make a real impact on cyber security while contributing to a sustainable future.
  • Qualifications: Experience in threat intelligence, SOC operations, and strong analytical skills required.

The predicted salary is between 63000 - 77000 £ per year.

Location: Glasgow

Salary: £54-68K (plus double-match pension)

Contract: Permanent, Hybrid (2-3 days per week in office)

Help us create a better future, quicker. SP Energy Networks (SPEN) has kicked off an ambitious security transformation programme to transparently reduce risk, achieve compliance with NIS regulations and deliver a cyber resilient business. The Cyber Threat Intelligence Lead will be essential in achieving our goals. This role will be integrated into an active and ambitious global cyber security function, contributing to SPEN’s cyber security purpose of delivering cyber resilient OT and IT, to enable a safe and reliable electricity supply to customers.

What You’ll Be Doing

  • Monitoring the threat landscape, analysing emerging risks, and delivering timely intelligence that supports Security Operations Centre (SOC) activities, incident response, threat hunting, detection engineering, risk management and the wider business.
  • Assessing adversary tactics, techniques and procedures (TTPs), developing intelligence led recommendations, and ensuring that threat intelligence is effectively integrated into wider security operations, vulnerability management and risk management programmes.
  • Collecting, processing, analysing and disseminating threat assessments and indicators.
  • Developing a strong understanding of the networks and systems within our environment to contextualise threat intelligence to support control implementation, detection coverage and ensuring our defences are aligned to real-world adversary tradecraft.
  • Transforming intelligence into actionable decisions, strengthening monitoring capabilities and driving improvement across the detection and response lifecycle.
  • Researching new and specialist techniques, working cross industry, and helping to shape our OT LAB.
  • Liaising and curating long term relationships with stakeholders to understand, document, prioritise, and communicate intelligence requirements.
  • Collaborating with threat detection, security monitoring, and incident response teams, providing subject matter expertise, sharing knowledge and developing/ coordinating intelligence sharing with trust groups.
  • Communicating the threat landscape and recommended actions to senior leadership, ensuring that the key threats to the business are understood from a top-down approach.
  • Identifying and supporting the integration of threat intelligence sources, commercial or other, to ensure the organisation has robust coverage of the threat landscape they face.

What You’ll Bring

  • Contributing to compliance with CAF and NIS requirements by providing intelligence driven analysis, evidence, reporting and operational support.
  • Improving alert fidelity, triage quality, and threat detection effectiveness by translating intelligence into practical detection requirements and investigative use cases.
  • A background in threat intelligence, SOC operations or detection analysis.
  • A strong understanding of attacker tactics and techniques, analytical frameworks, experience working with SIEM or SOAR technologies, threat hunting methodologies and a strong knowledge of the MITRE ATT&CK framework across both Enterprise and IC environments.
  • Experience supporting regulatory and security frameworks such as CAF, NIS, NCSC guidance, or similar will be highly beneficial.
  • Knowledge of OT security principles, IC environments, IEC 62443, networking fundamentals, and detection engineering would be advantageous.
  • Excellent analytical and communication skills, with the ability to translate complex threat information into clear, actionable outcomes for technical teams and stakeholders.
  • Comfortable prioritising intelligence activities in a fast-paced operational environment and supporting time sensitive investigations when required.

If you are passionate about cyber threat intelligence and want to help protect critical infrastructure operations against emerging threats, we would love to hear from you.

What’s In It For You

As well as a competitive salary which is reviewed annually, you can also enjoy a number of other benefits:

  • 36 days annual leave
  • Holiday purchase – perfect your work/life balance with extra annual leave
  • Share Incentive Plan and Sharesave Scheme
  • Payroll giving and charity matched funding
  • Technology Vouchers – save more and spread the cost of your technology purchases
  • Count us in – pledge to reduce carbon emissions and help fight climate change
  • Electric Vehicle Schemes – to help you transition to green/clean driving
  • Cycle to Work scheme and public transport season ticket loans
  • Options to purchase dental insurance, private medical insurance, health cash plan and annual health assessments
  • Life Assurance (4x salary)
  • Access to ‘nudge’ financial wellbeing support
  • Plus shopping, leisure, restaurant and gym discounts, and unique employee deals on travel insurance and more

Why SP Energy Networks

SP Energy Networks is part of the Iberdrola Group, one of the world’s largest integrated utility companies and a world leader in wind energy. We keep electricity flowing to homes and businesses through Central and Southern Scotland, North Wales and in the North West of England. We operate over 4000km of cables and lines that make up the transmission network – connecting infrastructure like wind farms into the electricity system. It’s a role that puts us right at the heart of Scotland’s ambition to be Net Zero by 2044. And we’re taking it very seriously. We’re investing >£5.5 billion into our transmission network, directly supporting the rapid growth needed in renewable energy.

With diverse opportunities across our businesses and a commitment to invest in our own internal talent, ScottishPower can offer people real career opportunities that meet personal and professional goals, in a global organisation. Inclusion, diversity, and a social purpose are at the heart of everything we do. Together with our values, they bring us together into a stronger, more sustainable business with direct links to the communities we serve.

We are committed to providing reasonable support or adjustments in our recruiting processes for candidates with disabilities, long term conditions, mental health conditions, or who are neurodivergent or require pregnancy-related support. If you need support, please reach out to careers@scottishpower.com.

Please note that any applicant who is not a citizen of the country of the vacancy will be subject to compliance with the applicable immigration requirements to legally work in that country. If/when required, the Company will support the employee with the necessary Immigration requirements.

IMPORTANT: Advert will close at 23:59 GMT the day before Job Posting End Date below September-16-2026.

Threat Intelligence Lead in Glasgow employer: ScottishPower

ScottishPower is an exceptional employer, offering a dynamic work environment at its Glasgow HQ where innovation meets sustainability. With a strong focus on employee well-being, the company provides generous benefits including up to 36 days of annual leave, a robust pension scheme, and opportunities for professional growth within a global leader in renewable energy. Join a diverse team committed to making a positive impact while enjoying flexible working arrangements and a culture that values inclusion and personal development.

S

Contact Details:

ScottishPower Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Threat Intelligence Lead in Glasgow

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including ScottishPower, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through ScottishPower

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at ScottishPower. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Threat Intelligence Lead in Glasgow

Threat Intelligence Analysis
Cyber Security
Incident Response
Threat Hunting
Detection Engineering
Risk Management
Adversary Tactics and Techniques

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at ScottishPower insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to ScottishPower that you’re committed to staying ahead in the game.

How to prepare for a job interview at ScottishPower

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at ScottishPower to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at ScottishPower.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.