Fractional CISO jobs
UK on your terms.
Browse live UK fractional CISO jobs and security mandates graded on rate, fit and IR35. Set your certifications once; get matched to companies actively hiring. Build your portfolio career.
What is a fractional CISO?
Part-time Chief Information Security Officer jobs UK. Not a consultant, not an MSSP: the CISO, 1–3 days a week.
Part-time
A chief information security officer, 1–3 days a week.
Senior, certified CISO capability across a defined slice of the week. You get the security leadership you need without a full-time salary or a five-day commitment.
Embedded
Outside IR35
Time-bound
CISO responsibilities
What fractional CISOs own versus what they delegate.
✓ OWNS
- Security strategy & roadmap
- Risk register & appetite
- Compliance programmes (ISO, SOC 2)
- Incident response planning
- Board reporting & metrics
- Security team structure
- Vendor selection & management
- Policy & governance framework
× DELEGATES
- 24/7 SOC monitoring
- Hands-on penetration testing
- Day-to-day ticket resolution
- Firewall configuration
- Vulnerability patching
- Security awareness training delivery
- Log analysis & SIEM tuning
- Identity management operations
Fractional CISO vs alternatives
How a fractional CISO compares to other security solutions.
CISO rates by sector
Day rates vary with regulatory requirements and company complexity.
| Sector | Typical scenario | Day rate range | Median |
|---|---|---|---|
| SME/Startup | First security hire, basic compliance | £700–£900 | £800 |
| Scale-up | ISO 27001, SOC 2, growing team | £900–£1,350 | £1,125 |
| Enterprise | Complex estate, multi-framework | £1,350–£1,650 | £1,500 |
| Regulated | Financial services, healthcare | £1,650–£2,500 | £2,075 |
What could you earn?
Model the cost vs a full-time CISO, or what you could earn across your portfolio.
When to hire a fractional CISO
Four scenarios where fractional CISO jobs deliver highest impact for UK businesses.
Compliance deadline
ISO 27001, SOC 2, or sector-specific cert needed for growth or contract.
Post-incident recovery
Breach happened. Need credible leadership to rebuild trust and programme.
Regulatory pressure
New regulations (NIS2, DORA, FCA) require board-level security ownership.
M&A or funding
Due diligence needs credible security leadership and mature programme.
IR35 structured correctly
Outside IR35 from day one. No retrospective HMRC risk.
Right of Substitution
The CISO can send a qualified substitute. You contract the limited company, not the individual.
Control
They control how, when and where they deliver. You define outcomes, not the working pattern.
Mutuality
No obligation to offer or accept work beyond the agreed mandate. True contractor relationship.
How we vet CISOs
Every fractional CISO is verified across four dimensions before they reach you.
Security credibility
Verify real track record leading security at your stage — not just audit or pen-testing background.
SOURCINGCertification check
Validate certs (CISSP, CISM, sector-specific) and ongoing CPE compliance.
VERIFICATIONReference validation
Speak to recent fractional clients, boards. Real outcomes, not just tenure.
DUE DILIGENCEShortlist delivery
3–5 candidates, each with rate percentile, fit score and IR35 structure.
48 HOURSFractional CISO FAQ
Common questions about hiring and working as a fractional CISO.
Related resources
Deep dives on fractional CISO topics.
CISO Cost Analysis
Detailed breakdown of fractional CISO rates, cost comparisons, and ROI calculations.
Virtual CISO Roles
How virtual CISO placements differ from fractional — remote-first model explained.
Interim CISO Jobs
Short-term security leadership for crisis response and transformation projects.