All Jobs Vacancy

Fractional Information Security, Compliance & Data Protection Manager

Posted Today by LYNQ | MES Software

We’re hiring: Fractional Information Security, Compliance & Data Protection Manager LYNQ is looking for an experienced Information Security and Compliance professional to join us on a fractional contractor basis and take ownership of our ongoing security governance and compliance programme.

This is a senior, hands-on governance and assurance role not a technical implementation position.

We are looking for someone who can independently manage and drive our ISMS and security compliance activities, ensuring that we remain compliant, audit-ready and continually improving throughout the year.

Responsibilities

  • Ownership and continual improvement of our ISMS
  • ISO 27001, ISO 27017 and ISO 27018 compliance and certification activities
  • Cyber Essentials and Cyber Essentials Plus
  • Internal audit planning and delivery
  • Management Reviews and ISMS Committee activities
  • Information Security Risk Register and risk treatment
  • Statement of Applicability and control governance
  • Policies, procedures and security governance documentation
  • Non-conformities, corrective actions and continual improvement
  • Security awareness and policy adherence
  • Supplier and third-party security assurance
  • Data protection governance and DPO responsibilities
  • Supporting customer security and compliance requirements
  • Working with technical control owners to ensure appropriate controls are implemented and evidenced

Experience we're looking for

  • Strong practical experience managing ISO 27001 within a certified organisation is essential.
  • We are particularly interested in candidates with experience across:
  • ISO 27001 / 27017 / 27018
  • Cyber Essentials / Cyber Essentials Plus
  • UK GDPR and Data Protection
  • NIST frameworks
  • SOC 2
  • Experience or knowledge of CMMC, NIST SP 800-171, CUI and ITAR would be highly desirable.
  • Experience within a B2B SaaS, cloud or software organisation would also be a significant advantage.

Qualifications

  • Qualifications such as ISO 27001 Lead Auditor / Lead Implementer, CISM, CISSP or CISA are welcome, but we're particularly interested in real-world experience of personally owning and operating an ISMS.

The engagement

Independent contractor

Remote

Approximately 2–3 days per month, with flexibility around audit and certification periods

Competitive day rate, dependent on experience

We are looking for someone who will genuinely own this function proactively managing the compliance calendar, driving actions, challenging control owners and ensuring security governance doesn't become something that only receives attention immediately before an audit.

We will begin interviewing from 1 September 2026. If this sounds like you, or you know someone who would be a great fit, we'd love to hear from you.

Rate:
Not specified
Location:
United Kingdom
IR35 Status:
Not specified
Remote Status:
Remote
Industry:
Cybersecurity
Seniority Level:
Senior

Take-Home Pay

Not Available

Visit calculators for additional details

Create a free account to view the take-home pay for this contract

Share job