Morson Talent
Incident Response Analyst

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Incident Response Analyst
Location: Scottish Power HQ, Glasgow
Working Pattern: Flexible & Hybrid
Compensation: Negotiable rate, Inside IR35, PAYE and UMB options available
Help us create a better future, quicker
SP Energy Networks (SPEN) has initiated an ambitious security transformation program to transparently reduce risk, achieve compliance with NIS regulations, and deliver a cyber-resilient business. The Incident Response Analyst is crucial in achieving our goals.
This role will be integrated into an active and ambitious global cyber security function, contributing to SPEN's cyber security purpose of delivering cyber-resilient OT and IT to enable a safe and reliable electricity supply to customers.
What you'll be doing
- Play a central role in strengthening SPEN's incident response capability by developing, maintaining, and continuously improving cyber security playbooks, procedures, and associated documentation.
- Work closely with incident responders, detection engineers, and wider cyber teams to ensure processes are clear, repeatable, and aligned with best practice.
- Support the full incident lifecycle - from preparation through to post-incident review - ensuring lessons learned are captured, documented, and fed into future improvements.
- Contribute to the maturity of SPEN's cyber response framework, ensuring playbooks are operationally effective, compliant with NIS regulations, and tailored to our evolving OT and IT environments.
- Develop and deliver an incident response exercise plan covering a range of scenarios designed to test team readiness, validate playbooks, and ensure operational effectiveness. These exercises may include tabletop scenarios, technical simulations, cross-team coordination drills, and lessons learned reviews that contribute directly to capability uplift.
- Build strong working relationships across the business. Engage with operational, engineering, legal, risk, communications, and technology stakeholders to understand their requirements, coordinate incident response activities when required, and ensure that documentation and processes reflect real-world operational needs.
- Help shape the wider strategy of the Incident Response function - identifying capability gaps, contributing to team roadmaps, supporting cross-industry collaboration, and driving continual service improvement within SPEN's cyber resilience program.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
What you'll bring
- Experience developing, maintaining, or executing incident response playbooks, runbooks, or procedures within a cyber security environment.
- Strong documentation skills - with the ability to translate complex technical activities into clear, structured, and usable operational guidance.
- Ability to plan, deliver, and evaluate incident response exercises - such as tabletop scenarios, simulation-based drills, or cross-team coordination activities - with a focus on validating playbooks and improving operational readiness.
- Demonstrable experience building effective relationships with technical and non-technical stakeholders, with the ability to collaborate, influence, and communicate clearly during both day-to-day operations and during security incidents.
- A good understanding of the incident response lifecycle, common attack techniques (MITRE ATT&CK), and how incident response processes integrate with threat detection, monitoring, and wider security operations.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills