About

Brian Stephens

Cyber specialist with 20+ years' experience enhancing security maturity across enterprise and Critical National Infrastructure (CNI) environments — architecting, implementing and aligning security and infrastructure controls to measurable frameworks, and delivering risk-based assurance programmes that achieve high-bar certifications such as Cyber Essentials Plus. Translates technical IT and security requirements into measurable, business-aligned outcomes through strong GRC practice, KQL-driven detection and reporting, and stakeholder engagement.

Certifications & clearances

  • Active SC Clearance
  • DBS Cleared
  • Cyber Essentials Certified
  • ISO 27001 Implementation

Key skills

Strategic Assurance & GRC

NIST CSF 2.0
ISO 27001
ONR SyAPs
NCSC CAF
Third-party risk assessments
Regulatory compliance alignment

Cloud Security & Identity

Azure
Microsoft 365 E5
Microsoft Defender
Microsoft Purview
Microsoft Sentinel
Entra ID
Conditional Access

Security Operations & Automation

SecOps design and run
KQL
PowerShell
Python
Logic Apps

Programme Delivery & Documentation

Project delivery
HLD/LLD
SoWs
CAB packs
Board-level reporting

See the resources page for the standards and frameworks referenced above.

Experience

  1. Cyber Security Assurance Lead

    Dec 2024 – Current

    Sizewell C Nuclear

    • •Established and maintained an audit-ready evidence baseline ensuring compliance with NIST CSF 2.0, ISO 27001 and ONR SyAPs.
    • •Delivered Cyber Essentials Plus certification for the second year running, closing material detection gaps identified during assessment.
    • •Developed Sentinel KQL detection rules and workbooks aligned to ONR SyAPs and NIST CSF 2.0 control objectives.
  2. Cyber Security Engineer

    Feb 2022 – Nov 2024

    Sizewell C Nuclear

    • •Secured Azure/M365 cloud architecture for a greenfield nuclear environment.
    • •Delivered IAM, PIM and Conditional Access to strengthen access control posture.
    • •Hardened endpoints via WDAC, Intune, Defender for Endpoint and application RBAC policies.
  3. Cyber Security Consultant

    Nov 2021 – Jan 2022

    FirstPort Property Management

    • •Led end-to-end deployment of Microsoft Sentinel, including detection content and incident response automation.
    • •Optimised the Microsoft 365 E5 security suite — Defender rollout, DLP and AIP labelling.
    • •Architected Conditional Access and MCAS policies enforcing zero-trust access.
  4. Security Consultant

    Jun 2021 – Nov 2021

    TCS — Northern Power Grid

    • •Led the endpoint cyber security programme for Northern Power Grid's OT pre-production environment.
    • •Deployed Carbon Black EDR/Application control on-prem, with custom rule creation and tuning.
    • •Authored HLD/LLD and CAB project documentation.
  5. Lead Infrastructure Security Engineer

    Jan 2020 – Jun 2021

    INEOS Oil and Gas

    • •Led a NIST-aligned security programme across UK on-prem, cloud, IT and critical OT infrastructure.
    • •Delivered Carbon Black EDR and Cisco Umbrella deployment with baseline policy and alert tuning.
    • •Led IAM, Okta, O365 ATP and Fortinet firewall replacement projects.
  6. Infrastructure Security Engineer

    Oct 2017 – Nov 2019

    Kobalt Music

    • •Deployed CIS Top 20 security controls and hardened server/desktop baselines globally.
    • •Led global EDR, penetration testing and vulnerability management, including Carbon Black and Qualys.
    • •Automated CIS-hardened Windows 10 builds, cutting build time by 66%.
  7. Infrastructure Engineer

    May 2017 – Sep 2017

    Kurt Geiger

    • •Resolved service issues and closed ISO 27001 audit findings across HQ and DC sites.
    • •Led decommissioning of legacy servers and migration to Server 2012 R2 with SQL upgrades.
    • •Migrated business-critical IIS .NET web applications from Server 2000/2003 to 2012 R2.
  8. Network Systems Analyst

    Jan 2016 – Jan 2017

    ACCOR Hotels UK

    • •Led ACCOR's PCI DSS/GDPR security rollout across UK hotels, contributing to successful certification.
    • •Owned PCI DSS and Qualys vulnerability reporting, remediation and security controls delivery.
    • •Coordinated MPLS-to-fibre migration to support secure network modernisation.
  9. Network Systems Engineer

    May 2015 – Dec 2015

    ACCOR Hotels UK

    • •Delivered 3rd line support across 3 HQs, 250 sites, 2,700 users and 350 servers.
    • •Supported server, network, corporate Wi-Fi and Oracle IPOS infrastructure.
    • •Managed SCCM deployments and monthly patching to maintain security and system updates.
  10. Infrastructure Engineer

    Feb 2010 – Mar 2015

    Kent Wildlife Trust

    • •Unified a fragmented four-site estate into a modernised, scalable architecture.
    • •Delivered the organisation's foundational Disaster Recovery and Business Continuity posture.
  11. Network Support Engineer

    Jul 2006 – Dec 2009

    Stealth Solutions

  12. Infrastructure Project Engineer

    May 2005 – May 2006

    Connexions

Work

Case studies covering engagements across Azure security architecture, IAM, and cyber assurance are available on the case studies page. Articles on GRC, third-party risk and security-by-design are on the blog.

Connect

Kent Wildlife Trust logo
ACCOR HOTELS logo
KURT GEIGER logo
Kobalt Music logo
INEOS Oil & Gas logo
Sizewell C logo
Northern Powergrid logo