Fractional Information Security, Compliance & Data Protection Manager
Job Description
Fractional Information Security, Compliance & Data Protection Manager
This is a senior, hands-on governance and assurance role not a technical implementation position.
You will independently manage and drive ISMS and security compliance activities, ensuring the organization remains compliant, audit-ready and continually improving throughout the year.
The role will include responsibility for:
• Ownership and continual improvement of our ISMS • ISO 27001, ISO 27017 and ISO 27018 compliance and certification activities • Cyber Essentials and Cyber Essentials Plus • Internal audit planning and delivery • Management Reviews and ISMS Committee activities • Information Security Risk Register and risk treatment • Statement of Applicability and control governance • Policies, procedures and security governance documentation • Non-conformities, corrective actions and continual improvement • Security awareness and policy adherence • Supplier and third-party security assurance • Data protection governance and DPO responsibilities • Supporting customer security and compliance requirements • Working with technical control owners to ensure appropriate controls are implemented and evidenced
You will not be expected to implement technical controls yourself. However, you must have sufficient technical security knowledge to understand the controls, challenge where necessary and assess whether appropriate evidence demonstrates that requirements are being met.
Experience we're looking for
Strong practical experience managing ISO 27001 within a certified organisation is essential. We are particularly interested in candidates with experience across:
• ISO 27001 / 27017 / 27018 • Cyber Essentials / Cyber Essentials Plus • UK GDPR and Data Protection • NIST frameworks • SOC 2
Experience or knowledge of CMMC, NIST SP 800-171, CUI and ITAR would be highly desirable.
Experience within a B2B SaaS, cloud or software organisation would also be a significant advantage.
Qualifications such as ISO 27001 Lead Auditor / Lead Implementer, CISM, CISSP or CISA are welcome, but we're particularly interested in real-world experience of personally owning and operating an ISMS.
The engagement
Employment Type: Independent contractor
Work Arrangement: Remote
Time Commitment: Approximately 2–3 days per month, with flexibility around audit and certification periods
Compensation: Competitive day rate, dependent on experience
We are looking for someone who will genuinely own this function proactively managing the compliance calendar, driving actions, challenging control owners and ensuring security governance doesn't become something that only receives attention immediately before an audit.
Interviews begin: 1 September 2026
About the Company
LYNQ is reinventing manufacturing execution system (MES) software for small to midsize manufacturers looking for a plug-and-play offering to digitalise and drive their factory performance.
Formed around international standard IEC62264, LYNQ’s leading-edge manufacturing operations management solution can plan, track, automate, analyse and optimise factories to increase efficiency, productivity and profitability.
Configurable and quick to deploy, LYNQ understands the challenges of industry and helps manufacturers around the world to adapt and thrive in today’s competitive market.