Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
JobTailor Logo

See all jobs on JobTailor

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Intelance

Cyber Incident Exercising Team Lead, Associate

Intelance

Cyber incident exercise team lead building Intelance’s UK NCSC-aligned exercising service. Designing and delivering tabletop and live-play exercises for organisationally significant incidents.

Posted 8/15/2026contractLondon • 🇬🇧 United KingdomSeniorWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in leading cyber incident exercises, including scoping, scenario development, and debriefing, while ensuring compliance with UK incident reporting standards and effective communication with diverse stakeholders.

Highest-signal resume keywords
Cyber Incident Exercises DeliveryTabletop And Live Play ExercisesThreat Intelligence ApplicationCrisis ManagementUK Incident Reporting Knowledge

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Exercise ScopingScenario DevelopmentInject DesignExercise ControlFacilitationDebriefingReportingCyber Incident Response PlansBusiness ContinuityCrisis Communications
Soft Skills
Strong Written CommunicationStrong Spoken Communication
Tools & Technologies
NCSC Exercise In A BoxNIST SP 800-84
Certifications & Qualifications
IASME CIE Team Lead Test
Industry Keywords
Regulated IndustriesPublic SectorCritical InfrastructureComplex Supply ChainsNCSC CIE Technical Standard

About the role

Key responsibilities & impact
  • Lead the complete Design, Develop, Conduct and Evaluate life cycle for cyber incident exercises
  • Scope exercises with clients and agree objectives, participants, assumptions, dependencies, safety controls and success measures
  • Design credible threat-led scenarios using current threat intelligence, relevant tactics, techniques and procedures, and frameworks such as MITRE ATT&CK
  • Lead tabletop and live play exercises for organisationally significant cyber incidents
  • Develop injects, timelines, participant materials, exercise control plans, observation records and communications
  • Facilitate exercises for Board, management and operational participants
  • Direct the exercise control function, manage pace and adapt delivery safely to player actions
  • Coordinate technical, legal, regulatory, communications and business continuity stakeholders
  • Lead debriefs, identify lessons and produce concise reports with practical actions
  • Maintain client case studies, references, feedback and scheme evidence
  • Coach other Intelance facilitators and help maintain a repeatable CIE delivery method
  • Apply relevant UK incident reporting and escalation knowledge, including the NCSC, law enforcement, Action Fraud and the Information Commissioner's Office

Requirements

What you’ll need
  • At least three years of experience delivering cyber incident exercises for external clients where exercising formed a key part of the role, or evidence of having passed the IASME CIE Team Lead test
  • Direct experience of both tabletop and live play exercises for organisationally significant incidents
  • Delivery experience at two or more levels: Board, management and operational
  • Physically based in the UK and able to travel to client locations
  • Proven experience leading exercise scoping, scenario development, inject design, exercise control, facilitation, debriefing and reporting
  • Strong knowledge of cyber incident response plans, incident management, business continuity and crisis communications
  • Ability to use threat intelligence and real-world tactics, techniques and procedures to build credible scenarios
  • Working knowledge of UK cyber incident reporting, law enforcement, Action Fraud, the Information Commissioner's Office and relevant legal or regulatory duties
  • Ability to provide client case studies, sample outputs and references; anonymised material acceptable initially
  • Strong written and spoken communication across technical and senior business audiences
  • Clear understanding of safe exercise delivery, confidentiality and conflicts of interest
  • Previous work against the NCSC CIE Technical Standard (desirable)
  • Experience with NCSC Exercise in a Box, NIST SP 800-84 or equivalent exercise methodology (desirable)
  • Experience in regulated industries, public sector, critical infrastructure or complex supply chains (desirable)
  • Incident response, crisis management, threat intelligence or digital forensics qualifications (desirable)
  • Experience building or leading a repeatable cyber exercising service (desirable)

Benefits

Comp & perks
  • Flexible project based associate work with remote design and agreed client site delivery
  • A written scope, timetable and agreed day rate before each assignment
  • Support from Intelance's wider cyber assurance, architecture, ISO and governance team
  • Access to structured delivery templates, secure collaboration and quality controls
  • Opportunity to shape the service method, exercise library and facilitator capability