Cyber Compliance Lead - Inside IR35 - SC Cleared

Cyber Compliance Lead - Inside IR35 - SC Cleared

Posted 2 weeks ago by SR2 | Socially Responsible Recruitment | Certified B Corporation™

£525 Per day
Inside
Remote
London, England, United Kingdom

Summary: The Cyber Compliance Lead role involves developing and embedding cyber governance, risk, and compliance capabilities for a critical national infrastructure client. This position requires overseeing cyber security policies, ensuring compliance with standards, and managing stakeholder engagement to maintain a high-assurance environment. The role is primarily remote with occasional travel and requires SC clearance. The successful candidate will play a key role in mitigating cyber risks across the organization.

Key Responsibilities:

  • Lead the development, maintenance, and oversight of cyber security policies, standards, and procedures
  • Monitor compliance with internal frameworks and external obligations (e.g. NIS Directive, NCSC CAF, ISO/IEC 27001)
  • Plan and conduct compliance reviews, control assessments, and audit responses
  • Liaise with internal stakeholders (technical and business) to ensure consistent policy application and evidence of control effectiveness
  • Manage the tracking and closure of non-conformities and audit findings
  • Provide assurance updates to senior stakeholders, supporting risk-informed decision-making
  • Support regulatory and third-party assurance activities, including evidence collation and readiness assessments
  • Contribute to the continuous improvement of the GRC operating model and maturity roadmap

Key Skills:

  • Strong background in cyber security compliance and/or audit within large or regulated organisations
  • In-depth knowledge of key frameworks such as NISD, ISO 27001, NIST CSF, CAF, or equivalent
  • Experienced in designing and implementing compliance monitoring programmes
  • Excellent stakeholder engagement skills, with the ability to challenge and influence at all levels
  • Comfortable translating complex technical issues into clear business language
  • Familiarity with public sector or Critical National Infrastructure (CNI) environments
  • Skilled in managing documentation, policies, and evidence for internal and external review

Salary (Rate): £525 daily

City: London

Country: United Kingdom

Working Arrangements: remote

IR35 Status: inside IR35

Seniority Level: undetermined

Industry: IT

Detailed Description From Employer:

Cyber Compliance Lead

Inside Ir35: £500 - £525

Primarily remote - once a month travel

SC Cleared

Overview:

SR2 is partnering with a key consultancy client to further develop and embed a critical national infrastructure client's cyber governance, risk, and compliance (GRC) capabilities. We are seeking a confident and experienced Cyber Compliance Lead to support the assurance of cyber controls, policy adherence, and alignment to relevant standards and regulatory requirements. This role will be instrumental in maintaining a high-assurance environment and ensuring that cyber risk is effectively mitigated across the organisation.

Key Responsibilities:

  • Lead the development, maintenance, and oversight of cyber security policies, standards, and procedures
  • Monitor compliance with internal frameworks and external obligations (e.g. NIS Directive, NCSC CAF, ISO/IEC 27001)
  • Plan and conduct compliance reviews, control assessments, and audit responses
  • Liaise with internal stakeholders (technical and business) to ensure consistent policy application and evidence of control effectiveness
  • Manage the tracking and closure of non-conformities and audit findings
  • Provide assurance updates to senior stakeholders, supporting risk-informed decision-making
  • Support regulatory and third-party assurance activities, including evidence collation and readiness assessments
  • Contribute to the continuous improvement of the GRC operating model and maturity roadmap

Essential Skills & Experience:

  • Strong background in cyber security compliance and/or audit within large or regulated organisations
  • In-depth knowledge of key frameworks such as NISD, ISO 27001, NIST CSF, CAF, or equivalent
  • Experienced in designing and implementing compliance monitoring programmes
  • Excellent stakeholder engagement skills, with the ability to challenge and influence at all levels
  • Comfortable translating complex technical issues into clear business language
  • Familiarity with public sector or Critical National Infrastructure (CNI) environments
  • Skilled in managing documentation, policies, and evidence for internal and external review