

Leading U.S. energy holding firm operating utilities and renewable power assets across 24 states.
The primary responsibility is to implement and evolve the application security model, ensuring that security standards and best practices are fully integrated into the Software Development Lifecycle. This includes leading vulnerability management activities such as inventorying logical components, proactively discovering vulnerabilities, coordinating scanning and penetration testing, assessing findings, driving remediation, and producing comprehensive reports.
The Lead will also conduct security assessments of commercial software packages and act as the subject‑matter expert for Secure Software Development Standards, methods, and tools. They will work with global teams to align with Iberdrola‑defined standards, take accountability for governance and adoption within ScottishPower, and deliver education, training, and awareness programmes to embed these standards.
The Application Cybersecurity Lead will be based at ScottishPower HQ in Glasgow, with flexible and hybrid working options. The role requires the successful candidate to obtain UK Government Security Clearance and will work within the Digital Transformation team to roll out the Global Application Security Model across all ScottishPower businesses.
Ideal candidates possess detailed knowledge of the Secure Software Development Life Cycle (S‑SDLC), a solid understanding of cybersecurity threats, attack techniques, and threat modeling, as well as expertise in web application security and vulnerability discovery methods. Additional required knowledge includes application security architecture components such as segmentation, API gateways, encryption, privileged account management, and WAF, together with strong stakeholder‑management skills across multiple projects.
ScottishPower offers a competitive salary reviewed annually, a double‑matched pension contribution up to 10 %, 36 days of annual leave, holiday purchase, share incentive and Sharesave schemes, technology vouchers, electric vehicle schemes, and a range of personal insurance and health options. Additional benefits include financial wellbeing support, discounts on shopping, leisure, travel, and more, all aimed at supporting employees’ families, wellbeing, and climate‑action goals.