Fractional CISO, LYNQ | MES Software
FRACTIONAL CISO JOB · SOFTWARE DEVELOPMENT SECTOR · UNITED KINGDOM
LYNQ (software, 11–50 people) is recruiting a fractional Information Security & Compliance Manager on an independent contractor basis for ~2–3 days/month. This is a governance-first, hands-on leadership role owning ISO 27001 certification, ISMS operation, internal audit, DPO duties and compliance calendar—not technical implementation. Ideal fit for a senior security professional building a portfolio of fractional board or management roles.
The balanced verdict
- Explicitly fractional (2–3 days/month) with clear remote flexibility
- Senior governance leadership, not junior/technical role
- Well-scoped responsibilities (ISMS ownership, ISO 27001/27017/27018, Cyber Essentials, GDPR, internal audit, SoA, risk register)
- Real-world ISMS operation valued over certifications alone; B2B SaaS context is modern and well-resourced
- Employer-direct posting with named company and interview timeline
- No explicit day rate stated; 'competitive, dependent on experience' requires early negotiation
- 2–3 days/month is very light; verify workload spikes around ISO audit/certification cycles align with candidate availability
- Role sits between DPO, security governance and internal assurance—ensure reporting line and authority to challenge control owners is clear
The posting in full
We’re hiring: Fractional Information Security, Compliance & Data Protection Manager LYNQ is looking for an experienced Information Security and Compliance professional to join us on a fractional contractor basis and take ownership of our ongoing security governance and compliance programme.
This is a senior, hands-on governance and assurance role not a technical implementation position. We are looking for someone who can independently manage and drive our ISMS and security compliance activities, ensuring that we remain compliant, audit-ready and continually improving throughout the year.
The role will include responsibility for:
- Ownership and continual improvement of our ISMS• ISO 27001, ISO 27017 and ISO 27018 compliance and certification activities• Cyber Essentials and Cyber Essentials Plus• Internal audit planning and delivery• Management Reviews and ISMS Committee activities• Information Security Risk Register and risk treatment• Statement of Applicability and control governance• Policies, procedures and security governance documentation• Non-conformities, corrective actions and continual improvement• Security awareness and policy adherence• Supplier and third-party security assurance• Data protection governance and DPO responsibilities• Supporting customer security and compliance requirements• Working with technical control owners to ensure appropriate controls are implemented and evidenced
You will not be expected to implement technical controls yourself. However, you must have sufficient technical security knowledge to understand the controls, challenge where necessary and assess whether appropriate evidence demonstrates that requirements are being met.
Experience we're looking for Strong practical experience managing ISO 27001 within a certified organisation is essential. We are particularly interested in candidates with experience across:
- ISO 27001 / 27017 / 27018• Cyber Essentials / Cyber Essentials Plus• UK GDPR and Data Protection• NIST frameworks• SOC 2
Experience or knowledge of CMMC, NIST SP 800-171, CUI and ITAR would be highly desirable. Experience within a B2B SaaS, cloud or software organisation would also be a significant advantage.
Qualifications such as ISO 27001 Lead Auditor / Lead Implementer, CISM, CISSP or CISA are welcome, but we're particularly interested in real-world experience of personally owning and operating an ISMS.
The engagement Independent contractor Remote Approximately 2–3 days per month, with flexibility around audit and certification periods Competitive day rate, dependent on experience
We are looking for someone who will genuinely own this function proactively managing the compliance calendar, driving actions, challenging control owners and ensuring security governance doesn't become something that only receives attention immediately before an audit.
We will begin interviewing from 1 September 2026. If this sounds like you, or you know someone who would be a great fit, we'd love to hear from you.
Other fractional jobs in the UK
Fractional Chief Growth Officer - 6+ Months (2-4 days pw) (2)
Market Access Partner, Financial Services (Fractional, Contract)
Fractional Part time Sales Directors
Featured fractional mandates
Fractional C-Suite
Fractional Commercial Finance & Governance Director (ACA / FCA)
Fractional Head Of Talent
Browse every fractional leadership role
Tell us what you're actually looking for.
Browse every live UK fractional and interim mandate — day-rate transparent, verified live, and flagged when a role is worth a fractional pitch.