Rodeo
Get started

Cognassist

Data Protection Officer / ISO Lead

South Tyneside
Posted about 15 hours ago
Sign up to applySee more jobs like this

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

Please note: this is not a full-time role. This is a day-rate contracting position, with an anticipated commitment of around 2 days per month.

Role Purpose

As we scale, we are strengthening our information security, data protection and ISO compliance posture, and we are looking for an experienced contractor to own our ISMS, maintain ISO certification, and support our Data Protection Officer responsibilities.

The purpose of this role is to provide consultancy services specific to information security and audit compliance. The role supports the completion of Security Assurance Questionnaires, builds internal capability to ensure ongoing improvement in this area, and delivers cybersecurity assessments, policy reviews and regulatory compliance audits, alongside acting as ISO lead and providing Data Protection Officer consultancy as needed.

Key Responsibilities

  • Own, maintain and update all ISMS documentation, keeping policies, procedures, controls and records current and audit-ready.
  • Manage the ISMS on an ongoing basis, including control monitoring, risk treatment, and continual improvement.
  • Provide information, advice and guidance for the successful completion of Security Assurance Questionnaires from prospects and customers, which may involve meetings with prospects or clients, and build internal capability so the business can manage these confidently over time.
  • Conduct cybersecurity assessments and policy reviews, identifying gaps and driving remediation.
  • Plan and manage internal and external ISO audits and regulatory compliance audits, coordinating with certification bodies and preparing the business for surveillance and recertification.
  • Nominate a named representative to participate in Cognassist's InfoSec and Estate Committee, making themselves available when the committee meets, and actively engage in relevant work assigned following committee decisions.
  • Attend quarterly GRCA meetings with leadership.
  • Propose continuous improvement programmes specific to InfoSec governance, risk and compliance, and deliver roadmap activities agreed across the committee.
  • Provide Data Protection Officer consultancy on an ad hoc basis when needed by the business.
  • Comply with industry-standard security protocols and use tools that adhere to recognised security standards, including encrypted communications and secure networks.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

Experience and Skills

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job
  • Demonstrable experience providing InfoSec and audit compliance consultancy, ideally within a SaaS or technology environment.
  • Proven track record maintaining and managing an ISO ISMS through certification and audit.
  • Experience completing Security Assurance Questionnaires and responding to customer and supplier security due diligence.
  • Working knowledge of Data Protection Officer responsibilities, UK GDPR and the Data Protection Act 2018.
  • Relevant certification such as ISO Lead Implementer or Lead Auditor, and a recognised data protection qualification (for example BCS/CIPP).
  • Strong documentation skills and the ability to work independently with minimal oversight.
  • Ability to handle special category or sensitive personal data with appropriate care and confidentiality.
Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Skills

Information Security
ISO 27001
Data Protection
GDPR
ISMS Management
Cybersecurity Assessments
Regulatory Compliance
Audit Management
Security Assurance Questionnaires
Policy Review
Risk Management
Consultancy
UK GDPR
Data Protection Act 2018
ISO Lead Implementer
ISO Lead Auditor

Location

South Tyneside, England, United Kingdom

Sign up to applySee more jobs like this