Be at the heart of actionFly remote-controlled drones into enemy territory to gather vital information.

Apply Now

Cyber Threat Intelligence & Vulnerability Management Lead

Plymouth
3 days ago
Create job alert

Cyber Threat
Intelligence & Vulnerability Management Lead
Flexible location
Hybrid working
Permanent, full time

Closing date: Monday 3rd November 2025

Who we are

We’re not just talking about making a difference, we’re making it happen.
We generate dispatchable, renewable power and create stable energy in an
uncertain world. Building on our proud heritage, we have ambition to become the
global leader in sustainable biomass and carbon removals.

You’ll be joining our teams of practical doers, future thinkers and business
champions. We’re enabling a zero carbon, lower cost energy future for all, and
working hard to decarbonise the planet for generations to come.

About the role

The primary purpose of this role is to manage and influence all aspects of
Cyber Threat Intelligence and Vulnerability Management, but particularly in the
development of the threat landscape to Drax. You’ll also assist in the
development of Technical Controls in accordance with policy, standards and
regulatory requirements.

You’ll help to develop and support senior management with the technical
controls and cyber threat intelligence skills within the group-wide security
team and through the rollout of tools, technical controls, policies and
procedures, and coaching and mentoring. The role will also have responsibility
for working with asset owners to ensure that they understand their
responsibilities regarding risk and technical security controls.

You’ll deliver against the business strategy, the technical roadmap and
objectives set out in the Security strategy – covering group wide security
requirements.

Additional responsibilities include:

  • Supporting the definition of technical controls matrices, Security Operations
    Centre (SOC) processes, industrial control matrices and architectural controls,
    providing oversight to other SMEs in support of their BAU activities and
    maintaining accurate documentation and record keeping.
  • Ensuring controls and risk treatment plans align with our policies and
    standards.
  • Leading threat intelligence and vulnerability management review meetings with
    key stakeholders and provision of security representation at business unit
    technical review and Senior Leadership Team (SLT) meetings as required.
    Effectively communicating all technical controls and mitigations.
  • Continuing to develop and improve the Group Cyber Threat Intelligence
    framework technical controls, industrial controls and architectural controls
    including the effective management of the required documentation across the
    Group.
  • Recommending and implementing an appropriate toolkit for Cyber Threat
    Intelligence.
  • Technical control reporting.
  • Researching threats, Indicators of Compromise (IoCs) and threat actor Tactics,Techniques and Procedures (TTPs) to support Threat Hunting, Signature
    Development and Threat Intelligence Platform (TIP) processes.
  • Providing strong technical oversight to deliver consistency and quality in
    technical work across the Group.
  • Participating in Audits, Technical Design Authority and Change Advisory
    Boards as required.

    Who we’re looking for

    This role requires the ability to interpret Cyber Threat Intelligence and
    technical controls and communicate effectively to all levels of the
    organisation.

    Ideally, you’ll have a good experience working within IT/OT in an operational
    or corporate environment with a good knowledge of control frameworks such as
    ISO27001, ITIL (Information Technology Infrastructure Library), NIST, SABSA and
    IEC 62443 and cyber kill chain.

    You’ll have a good knowledge of Risk Management Methodologies such as ISO27005
    and IRAM2/security frameworks NIST/NIS CAF/IEC/SoGp Cyber Kill chain with
    strong IT technical skills to support this knowledge.

    You’ll also demonstrate strong communication (verbal and written) and
    stakeholder management skills, with the ability to take the initiative and
    handle multiple projects simultaneously.

    Rewards and benefits

    As you help us to shape the future, we’ve shaped our rewards and benefits to help you thrive and support your lifestyle:

  • Competitive salary
  • Discretionary group performance-based bonus
  • 25 days annual leave (plus Bank Holidays)
  • Single cover private medical insurance
  • Pension scheme

    We’re committed to making a tangible impact on the climate challenge we all face. Drax is where your individual purpose can work alongside your career drive. We work as part of a team that shares a passion for doing what’s right for the future. With Drax you can shape your career and a future for generations to come.

    Together, we make it happen.

    At Drax, we’re committed to fostering an environment where everyone feels valued and respected, regardless of their role. To make this a reality, we actively work to better represent the communities we operate in, foster inclusion, and establish fair processes. Through these actions, we build the trust needed for all colleagues at Drax to contribute their perspectives and talents, no matter their background. Find out more about our approach here.

    How to apply

    Think this role’s for you? Click the ‘Apply now’ button to begin your Drax journey.

    If you want to find out more about Drax, check out our LinkedIn page to see our latest news

Related Jobs

View all jobs

Cyber Threat Intelligence & Vulnerability Management Lead

Cyber Threat Intelligence & Vulnerability Management Lead

Cyber Threat Intelligence & Vulnerability Management Lead

Cyber Threat Intelligence & Vulnerability Management Lead

Cyber Threat Intelligence & Vulnerability Management Lead

Cyber Threat Intelligence & Vulnerability Management Lead

Subscribe to Future Tech Insights for the latest jobs & insights, direct to your inbox.

By subscribing, you agree to our privacy policy and terms of service.

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

Cyber Security Recruitment Trends 2025 (UK): What Job Seekers Must Know About Today’s Hiring Process

Summary: UK cyber security hiring has shifted from title‑led CV screens to capability‑driven assessments that emphasise incident readiness, cloud & identity security, detection engineering, governance/risk/compliance (GRC), measurable MTTR/coverage gains & secure‑by‑default engineering. This guide explains what’s changed, what to expect in interviews, & how to prepare—especially for SOC analysts, detection engineers, blue/purple teamers, penetration testers, cloud security engineers, DFIR, AppSec, GRC & security architecture. Who this is for: SOC & detection engineers, security operations leads, DFIR analysts, penetration testers/red teamers, purple teamers, AppSec/DevSecOps engineers, security architects, cloud security engineers, identity/IAM engineers, vulnerability managers, GRC/compliance specialists, product security & security programme managers targeting roles in the UK.

Why Cyber Security Careers in the UK Are Becoming More Multidisciplinary

Cyber security used to be viewed primarily as a technical discipline: firewalls, encryption, intrusion detection, penetration testing. In the UK today, it’s far broader. Organisations now face complex legal frameworks, ethical dilemmas, human-behaviour risks, communication challenges & usability hurdles. This shift means cyber security careers are becoming more multidisciplinary. From protecting NHS patient records to defending financial services, securing supply chains & safeguarding national infrastructure, cyber security now touches every sector. Employers increasingly want professionals who understand law, ethics, psychology, linguistics & design alongside traditional technical skills. In this article, we’ll explore why UK cyber security careers are expanding in this way, how these five disciplines shape the profession, and what job-seekers & employers need to know to thrive in this new landscape.

Cyber Security Team Structures Explained: Who Does What in a Modern Cyber Security Department

Cyber security has become a top priority for UK organisations of all sizes. From small businesses to financial institutions, healthcare providers, and government bodies, the risk of cyber attack is now a constant concern. Threats are more sophisticated, regulations more demanding, and customers more aware of data privacy than ever before. But defending against cyber threats isn’t simply about having the right tools — it’s about having the right team. A modern cyber security department relies on clearly defined roles and responsibilities to ensure that defences are proactive, incidents are managed swiftly, and compliance is maintained. This article explains the structure of a modern cyber security team, the roles you’ll typically find within it, how they collaborate, and what skills, qualifications, and salaries are expected in the UK job market.