Brook Green Supply
Cyber Security Lead

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
The Role:
Brook Green Supply are an independent B2B energy supply company. You will be working alongside a vastly experienced team who have operated in the energy industry for many years, providing a fantastic career opportunity for a determined, flexible, and driven individual, with personal development and progression aligned to the continued growth and success of the business.
Reporting directly to the Operations Director, the Cyber Security Lead is accountable for cyber security governance and delivery across Brook Green Supply. You will set direction, prioritise security initiatives, and improve security posture across people, process, and technology. You will partner with departments across the business, as well as suppliers, to embed secure-by-design and respond effectively to incidents.
Essential Functions of the Job:
- Own and drive the cyber security roadmap, aligning priorities to business risk, regulatory expectations, and technology delivery plans.
- Lead delivery of security initiatives across cross-functional teams and third parties, from discovery through implementation and operational handover.
- Define and maintain security governance, including policies, standards, risk acceptance, and control assurance.
- Oversee cloud and software delivery security, embedding DevSecOps practices, threat modelling, and secure configuration baselines.
- Run cyber risk management, including vulnerability management, penetration testing coordination, and remediation tracking.
- Own incident management for cyber events, including response playbooks, coordination, communications, and post-incident learning.
- Strengthen monitoring and detection by using security telemetry, threat intelligence, and clear KPIs to build the operational picture.
- Manage supplier and third-party security risk, including due diligence, contract security requirements, and ongoing assurance.
- Plan and deliver security awareness and role-based training, improving security culture across the business.
- Support adoption of recognised frameworks and assurance activity, including NIST-aligned controls and ISO 27001 readiness and audits where applicable.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Skills & Experience Required:
- Proven track record leading cyber security improvement in a cloud-first environment, balancing hands-on delivery with governance and stakeholder management.
- Strong knowledge of security frameworks and assurance, including NIST, ISO 27001, GDPR, and SOC concepts. Experience of audit preparation and evidence management.
- Experience implementing and operating security controls across identity and access, endpoints, networks, cloud platforms, and SaaS tooling.
- Good understanding of secure software delivery and DevSecOps, including CI/CD security, secrets management, and threat modelling.
- Experience with incident response, including tabletop exercises, playbooks, and coordination of technical and business communications.
- Confident working with security data, monitoring tools, and threat intelligence to create actionable insights and prioritisation.
- Excellent written and verbal communication. Able to translate technical risk into business impact and decisions.
- Comfortable managing third parties, including MDR or SOC providers, consultants, and technology vendors.
- Relevant certifications are valued. Examples include CISSP, CISM, Security+, ISO 27001 Lead Implementer or Auditor, and cloud security certifications (Azure or AWS).


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Brook Green Supply is committed to ensuring equal opportunities, fairness of treatment, dignity and respect, and the elimination of all forms of discrimination in the workplace for all employees/contractors and job applicants. We will never ask if you have a disability at any point in the recruitment process. However, if you require any specific accommodations during the interview process, please let us know and we will do our best to support you.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills
Location