Stephen Curtis-Spence
Cyber Security Manager @ StepChange Debt Charity
About
I’m a seasoned cyber security professional with a proven track record of leading security strategy, governance, and resilience across regulated environments. With deep expertise in ISO27001, risk management, incident response, and stakeholder engagement, I’ve consistently delivered robust security postures that protect critical services and build organisational trust. My leadership style is collaborative and pragmatic—I integrate seamlessly across teams and functions, from board-level advisory to hands-on technical delivery. I’m known for building strong relationships quickly, mentoring colleagues, and driving cultural change around cyber awareness. My background in the arts has shaped me into a nuanced communicator, equally effective with technical teams and executive stakeholders. I thrive in dynamic environments, mastering new technologies rapidly and translating complexity into actionable strategy. Whether coordinating audits, managing vCISO partnerships, or leading incident responses on Christmas Day, I bring dedication, integrity, and a calm, strategic mindset to every challenge. Outside of work, I’m a keen cyclist and hobbyist programmer—always exploring new ways to stay sharp, curious, and connected.
United Kingdom
West Midlands
Financial Services
Cyber Risk Management, Cybersecurity Incident Response, AWS , AZURE, IT & Business Strategy Alignment, IT Operations, Microsoft Servers, Microsoft Exchange, SQL, Microsoft Excel, Time Management, Quality Assurance Testing, Test Engineering, Help Desk Support, Technical Support, CISA, Disaster Recovery, Internal Audits, ISO 27001, Mimecast
Experience

Cyber Security Manager
Leeds
I lead the organisation’s cyber security strategy, governance and resilience capabilities, protecting sensitive client and business data in a regulated environment. I work closely with senior leadership, trustees, technology and risk teams to ensure security is embedded into decision-making and long-term planning. I designed and implemented an enterprise governance framework aligned to NCSC CAF, strengthened policy and assurance processes, and integrated cyber risk into wider corporate risk management. I oversee vulnerability management, penetration testing and audit remediation, ensuring risks are prioritised and resolved within appetite. I provide operational leadership for cyber incident response, ensuring clear escalation, effective communication and coordinated recovery. I maintain disaster recovery and service continuity arrangements in partnership with the Business Continuity Manager, with regular testing to validate organisational resilience. I design, develop and deliver executive cyber reporting, translating complex security and technology risks into clear, actionable insights for senior leadership and trustees. I often present this reporting independently, including in sessions where the CTO is not present. I act as a trusted adviser on cyber risk, resilience and investment, and oversee the cyber budget and key supplier relationships to ensure alignment with organisational priorities. I collaborate closely with enterprise architecture to shape and approve modernisation roadmaps for AWS infrastructure and Entra ID, ensuring secure design principles are embedded early. I chair the Security Committee and lead cross-functional security working groups, co-lead the organisation’s cyber culture programme, and have delivered executive tabletop exercises focused on ransomware resilience.

IT Security and Audit Officer
Served as the SRA’s lead cyber security SME, driving ISO27001:2022 accreditation and embedding organisation-wide governance, policies and controls. Acted as a primary security adviser to the Board and Audit & Risk Committee, shaping strategy, guiding risk appetite discussions and ensuring alignment with regulatory expectations. Held responsibility for the enterprise assurance programme, overseeing vulnerability management across SaaS, PaaS, IaaS and on-prem environments using tools such as Nessus, SonarCloud and MSRC. Chaired the CSIRT under the NIST framework, acting as final escalation point for high-impact cyber incidents and providing clear, risk-aligned reporting to senior leadership. Designed and led the transition to an outsourced SOC model, including vendor selection, contractual governance, KPI definition, budget oversight and service improvement. Strengthened resilience by chairing the organisation’s Disaster Recovery Steering Group, ensuring alignment between cyber security, business continuity and technology strategy. Delivered strategic security improvement programmes, including secure customer authentication redesign (MFA, reCAPTCHA, WAF) and embedding secure development lifecycle practices within Azure DevOps. Oversaw deployment of key security technologies such as Microsoft Sentinel, Fortinet, Barracuda WAF, Mimecast and SonarCloud. Worked closely with enterprise architecture, attending TDA forums and presenting designs to ensure secure patterns were built into modernisation roadmaps. Built strong internal and external partnerships — including with NCSC, regulators and security suppliers — to enhance threat awareness and strengthen the organisation’s resilience posture.

Corporate Services Officer (IT)
Birmingham, United Kingdom
Promoted to Corporate Services Officer (Feb 2016) with expanded responsibility for IT strategy, budget planning, and delivery of core IT services across 10 UK offices. Built on strong helpdesk experience to take ownership of infrastructure upgrades, supplier management, and emerging cyber security initiatives. Infrastructure & Service Delivery: Designed and implemented migration of on-prem servers to Hyper-V, reducing hardware maintenance costs by 40%. Planned and delivered organisation-wide rollout of Microsoft 365 (Exchange, Teams, SharePoint, Delve) and upgraded desktops to Windows 10, improving reliability and collaboration. IT Operations: Managed relationships with 3rd party IT, backup, and security providers. Controlled IT budgets, maintained the corporate asset register, and ensured secure disposal of redundant equipment in line with legal standards. Provided day-to-day IT support and guidance to staff across Groundwork Trusts in the UK. Cyber Security: Took lead role in cyber security, maintaining Cyber Essentials Plus accreditation and supporting GDPR compliance. Developed and presented security strategy to senior leadership, highlighting risks and mitigation measures. Configured and monitored firewalls (Draytec, WatchGuard) and delivered practical security advice and support across the organisation. Leadership & Wider Support: Stepped up to manage the Facilities team in the absence of the Facilities Manager, demonstrating adaptability and leadership beyond IT.

Customer Service Assistant (IT)
West Midlands
Delivered 50% cost reduction through successful contract negotiation and strategic infrastructure redesign. Configure and maintain Windows Server environments (2008 R2, 2012 R2, 2019), including Active Directory, DHCP, DNS, Group Policy, Hyper-V, MS SQL, and RDP services. Provide frontline support and troubleshooting for Windows 7/8/10 desktops, ensuring minimal downtime and fast resolution of incidents. Build, configure, and deploy new hardware in line with company standards, enhancing reliability and user experience. Redesigned VLAN mapping to strengthen network performance and security, ensuring a more resilient infrastructure. Configure and support Linux (Ubuntu) web servers, deploying open-source web applications to improve internal processes and collaboration.

Bar Staff
Birmingham City University Students Union
Birmingham, United Kingdom
I was responsible for giving excellent customer service and cashing up at the end of the night. This was a role which required excellent customer service in a fast paced environment.

Bar Supervisor
Station Cafebar, Dorridge
Birmingham, United Kingdom
I worked as the supervisor for a local cafe/bar. I was often the sole member of staff and was responsible for giving excellent customer service and cashing up at the end of the night. This was a challenging and fast paced environment.

Compliance Administrator
HC-One
Birmingham, United Kingdom
Managed a large compliance database for domiciliary care homes. Contract Role

Software Quality Assurance Tester
Birmingham, United Kingdom
Worked as part of a small QA team, designing and executing testing schedules for a case management system to ensure reliability and accuracy. Collaborated closely with the development team to identify and report bugs in preview builds, using structured testing criteria to maintain quality standards. Delivered testing to tight deadlines with a high degree of accuracy, contributing to timely product releases. Once builds were approved, provided first-line support to Legal Ombudsman staff during rollout, ensuring smooth adoption and minimal disruption.

Programmes Assistant
Birmingham, United Kingdom
Administering a national accreditation scheme for museums, I was responsible for maintaining a database of museum applications and current status. In addition I was responsible for preparing materials for panel meetings and minuting these meetings. I was also responsible for administering applications two small grant schemes.

Delivery Consultant/ Researcher
Birmingham, United Kingdom
Connaught Resourcing is a specialist recruitment company with a clear focus on the private provision of public services. This industry includes the front line delivery of employability, education and skills training, offender management, legal advisory services, healthcare, social housing, and a range of other support and outsourced services.
Education
Stephen Curtis-Spence's Contact Information
Phone
Find the Right Leads
Find Verified Contact Data
What LeadContact does well
Find verified emails, phone numbers, and decision-makers with 98% accuracy.
Find Leads
Find the right people by company, role, industry, location, and more.
925M+ professional profiles

Find Emails
Access verified email addresses for your target contacts.
657M+ emails

Find Phone Numbers
Get cross-validated phone data from multiple top sources.
239M+ phone numbers

More Accurate. Lower Cost.
Find contact data in 1 tool with 98% accuracy
LeadContact integrates leading enrichment tools to deliver more accurate contact data—without paying for each one.
Great conversations start with the right contact.
It’s time to find yours.



