LYNQ | MES Software
Fractional Information Security, Compliance & Data Protection Manager

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
We’re hiring: Fractional Information Security, Compliance & Data Protection Manager
LYNQ is looking for an experienced Information Security and Compliance professional to join us on a fractional contractor basis and take ownership of our ongoing security governance and compliance programme.
This is a senior, hands-on governance and assurance role not a technical implementation position. We are looking for someone who can independently manage and drive our ISMS and security compliance activities, ensuring that we remain compliant, audit-ready and continually improving throughout the year.
The role will include responsibility for:
- Ownership and continual improvement of our ISMS
- ISO 27001, ISO 27017 and ISO 27018 compliance and certification activities
- Cyber Essentials and Cyber Essentials Plus
- Internal audit planning and delivery
- Management Reviews and ISMS Committee activities
- Information Security Risk Register and risk treatment
- Statement of Applicability and control governance
- Policies, procedures and security governance documentation
- Non-conformities, corrective actions and continual improvement
- Security awareness and policy adherence
- Supplier and third-party security assurance
- Data protection governance and DPO responsibilities
- Supporting customer security and compliance requirements
- Working with technical control owners to ensure appropriate controls are implemented and evidenced
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
You will not be expected to implement technical controls yourself. However, you must have sufficient technical security knowledge to understand the controls, challenge where necessary and assess whether appropriate evidence demonstrates that requirements are being met.
Experience we're looking for
Strong practical experience managing ISO 27001 within a certified organisation is essential. We are particularly interested in candidates with experience across:
- ISO 27001 / 27017 / 27018
- Cyber Essentials / Cyber Essentials Plus
- UK GDPR and Data Protection
- NIST frameworks
- SOC 2


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Experience or knowledge of CMMC, NIST SP 800-171, CUI and ITAR would be highly desirable. Experience within a B2B SaaS, cloud or software organisation would also be a significant advantage.
Qualifications such as ISO 27001 Lead Auditor / Lead Implementer, CISM, CISSP or CISA are welcome, but we're particularly interested in real-world experience of personally owning and operating an ISMS.
The engagement
Independent contractor
Remote
Approximately 2–3 days per month, with flexibility around audit and certification periods
Competitive day rate, dependent on experience
We are looking for someone who will genuinely own this function proactively managing the compliance calendar, driving actions, challenging control owners and ensuring security governance doesn't become something that only receives attention immediately before an audit.
We will begin interviewing from 1 September 2026. If this sounds like you, or you know someone who would be a great fit, we'd love to hear from you.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills
Location