Syndicated · explicitly fractionalFractional CISOUnited Kingdom
Fractional CISO, Cambridge Spark
FRACTIONAL CISO JOB · EDUCATION MANAGEMENT SECTOR · UNITED KINGDOM

Cambridge Spark, an edtech firm holding Cyber Essentials Plus, is recruiting a fractional vCISO to design security strategy, risk stewardship, and incident frameworks—not to execute operations or manage staff. This is a high-autonomy advisory role with a clear phased model: 1.5 days/week for ~3 months (setup), tapering to 2 days/month (steady state). The engagement is deliverable-driven and sits outside day-to-day operations.
Fractional CISO — the balanced verdict
Why this role stands out
- Explicitly fractional with realistic phasing and effort estimates (17–19 days setup, then 1–2 days/month)
- Clear separation of concerns — you advise, internal IT team executes; ensures independent assurance
- Strategic scope — security strategy, risk register architecture, board reporting, certification direction, incident frameworks
- Direct employer engagement with named internal contacts (Head of Engineering/SIRO)
Worth checking before you apply
- No day rate stated; commercial terms to be negotiated
- Incident response 'hands-on involvement in a live serious incident' flagged as separate call-off—scope creep risk if not contractually ring-fenced
- Org size and current maturity not detailed; gaps in risk register or control environment may reveal larger remediation effort than phased plan assumes
Our automated read of the posting text, not the employer's own assessment. Check each point with them before you apply.
How well the role as written suits a fractional or interim arrangement, scored 0–100 by our automated read of the posting text before it went on the board. It rates the posting, not you — we do not score or match candidates.
Fractional CISO — the posting in full
Engagement Overview Cambridge Spark is an education technology company that enables corporate and government organisations to achieve their business goals by educating their workforce with critical data transformation skills to succeed in the AI era. We currently hold Cyber Essentials Plus and are seeking an independent, Fractional Chief Information Security Officer (vCISO) to define our strategic security direction and provide independent assurance. This engagement is strictly deliverable-focused. You will not be integrating into our day-to-day operations or managing staff. Instead, you will provide senior, independent judgment and set the overarching security strategy, which will be executed by our internal IT & Systems Manager. This deliberate separation between control definition and operational execution ensures the objective assurance required by our regulated client base. Key Deliverables & Outcomes You will maintain full autonomy over how these outcomes are achieved as an external advisor, partnering with our Head of Engineering (acting SIRO) as your primary internal contact. Security Strategy & Roadmap: Define a clear, costed security strategy and sequenced improvement roadmap tailored to our evolving estate, threat landscape, and risk appetite. Risk & Assurance Stewardship: Architect a security-specific risk register and conduct regular, independent reviews of the control environment operated by the internal IT team. Board Reporting: Deliver periodic board-level reporting on organisational risk. Certification Direction: Deliver a formal, evidence-based recommendation on whether to pursue ISO 27001 or maintain Cyber Essentials Plus with a documented ISMS. Incident Framework: Design an incident response framework, testing plans, escalation pathways, and playbooks. (Note: Hands-on involvement in a live serious incident will be treated as a separate, ad-hoc call-off engagement). Client Assurance & Board Reporting: Mature the existing reusable security assurance evidence library for complex client due-diligence. Operational Boundaries To ensure unambiguous B2B boundaries and maintain focus on strategic deliverables, the following operational execution remains firmly with Cambridge Spark: Execution & First Response: Hands-on operations (patching, endpoint hardening, configuration) and incident first-response are owned by our internal IT & Systems Manager. Routine Questionnaires: Standard client security questionnaires will be completed by the internal team against the standards and evidence library you define. Accountability & Compliance: Final accountability sits with our SIRO. Data protection (DPO duties) and AI compliance (e.g., EU AI Act classification) sit with internal compliance owners, whom you will advise on security overlaps. Engagement Model & Commercials This is a phased, fractional engagement designed around project deliverables rather than a fixed weekly schedule. The cadence will naturally follow the required outputs: Setup Phase (~First 3 months): Estimated at 1.5 days per week (approx. 17–19 days total) to deliver the initial risk assessment, strategy, certification recommendation, and incident playbooks. Transition Phase (Months 4–6): Tapering to approximately 2 days per month as the roadmap moves into internal execution and the first independent assurance reviews commence. Steady State (Month 6 onwards): A lightweight retainer of 1–2 days per month for ongoing independent assurance, board reporting, and advisory services.
Same location
Other fractional jobs in the UK
Head of Medical Compliance, Governance & Diligence (Fractional)
CNX Therapeutics Ltd · Greater Londonest £1,000/dayGREATER LONDONGCFractionalSyndicatedHead of Applied Legal – AI Product (Fractional)
Stealth Startup · Londonest £1,600/day2 D/WKCEOInterimSyndicatedInterim Chief Executive Officer (Women's Health Charity)
Verity (PMOS UK) · United KingdomRate n/a3 D/WKOur own roles first · then the latest
Featured fractional roles
Fractional COO
Confidential client (Fractional Quest mandate) · LondonRate n/aLONDONCOOInterimExclusiveInterim Chief Operating Officer
Confidential client (Fractional Quest mandate) · LondonRate n/a5 D/WKFDInterimSyndicatedInterim Finance Director
Pragmatic Semiconductor · Cambridgeest £1,400/day5 D/WKExplore the category
Browse every fractional leadership role
not quite the right fit?
Tell us what you're actually looking for.
Browse the UK fractional and interim roles on our board — each day rate stated, estimated with its basis, or marked not stated — flagged when a role is worth a fractional pitch.
Hiring for a role like this? We undertake a shortlist of 3–5, five-stage vetting and an IR35 position on every brief.