On Site : 1
Contract Rate : 500
Contract Job : 1
Salary range high : 525
Salary range low : 500
Cyber Compliance Lead – Inside IR35 – SC Cleared
Cyber Compliance Lead – Inside IR35 – SC Cleared
Cyber Compliance Lead
Inside Ir35: £500 – £525
Primarily remote – once a month travel
SC Cleared
Overview:
SR2 is partnering with a key consultancy client to further develop and embed a critical national infrastructure client’s cyber governance, risk, and compliance (GRC) capabilities. We are seeking a confident and experienced Cyber Compliance Lead to support the assurance of cyber controls, policy adherence, and alignment to relevant standards and regulatory requirements. This role will be instrumental in maintaining a high-assurance environment and ensuring that cyber risk is effectively mitigated across the organisation.
Key Responsibilities:
- Lead the development, maintenance, and oversight of cyber security policies, standards, and procedures
- Monitor compliance with internal frameworks and external obligations (e.g. NIS Directive, NCSC CAF, ISO/IEC 27001)
- Plan and conduct compliance reviews, control assessments, and audit responses
- Liaise with internal stakeholders (technical and business) to ensure consistent policy application and evidence of control effectiveness
- Manage the tracking and closure of non-conformities and audit findings
- Provide assurance updates to senior stakeholders, supporting risk-informed decision-making
- Support regulatory and third-party assurance activities, including evidence collation and readiness assessments
- Contribute to the continuous improvement of the GRC operating model and maturity roadmap
Essential Skills & Experience:
- Strong background in cyber security compliance and/or audit within large or regulated organisations
- In-depth knowledge of key frameworks such as NISD, ISO 27001, NIST CSF, CAF, or equivalent
- Experienced in designing and implementing compliance monitoring programmes
- Excellent stakeholder engagement skills, with the ability to challenge and influence at all levels
- Comfortable translating complex technical issues into clear business language
- Familiarity with public sector or Critical National Infrastructure (CNI) environments
- Skilled in managing documentation, policies, and evidence for internal and external review