Cognassist logo

Data Protection Officer / ISO Lead

Cognassist
2 hours ago
Full-time
Remote
United Kingdom
Data Protection Officer

Please note: this is not a full-time role. This is a day-rate contracting position, with an anticipated commitment of around 2 days per month.

Role purpose

As we scale, we are strengthening our information security, data protection and ISO compliance posture, and we are looking for an experienced contractor to own our ISMS, maintain ISO certification, and support our Data Protection Officer responsibilities.

The purpose of this role is to provide consultancy services specific to information security and audit compliance. The role supports the completion of Security Assurance Questionnaires, builds internal capability to ensure ongoing improvement in this area, and delivers cybersecurity assessments, policy reviews and regulatory compliance audits, alongside acting as ISO lead and providing Data Protection Officer consultancy as needed.

Key responsibilities

  • Own, maintain and update all ISMS documentation, keeping policies, procedures, controls and records current and audit-ready.

  • Manage the ISMS on an ongoing basis, including control monitoring, risk treatment, and continual improvement.

  • Provide information, advice and guidance for the successful completion of Security Assurance Questionnaires from prospects and customers, which may involve meetings with prospects or clients, and build internal capability so the business can manage these confidently over time.

  • Conduct cybersecurity assessments and policy reviews, identifying gaps and driving remediation.

  • Plan and manage internal and external ISO audits and regulatory compliance audits, coordinating with certification bodies and preparing the business for surveillance and recertification.

  • Nominate a named representative to participate in Cognassist's InfoSec and Estate Committee, making themselves available when the committee meets, and actively engage in relevant work assigned following committee decisions.

  • Attend quarterly GRCA meetings with leadership.

  • Propose continuous improvement programmes specific to InfoSec governance, risk and compliance, and deliver roadmap activities agreed across the committee.

  • Provide Data Protection Officer consultancy on an ad hoc basis when needed by the business.

  • Comply with industry-standard security protocols and use tools that adhere to recognised security standards, including encrypted communications and secure networks.

Experience and skills

  • Demonstrable experience providing InfoSec and audit compliance consultancy, ideally within a SaaS or technology environment.

  • Proven track record maintaining and managing an ISO ISMS through certification and audit.

  • Experience completing Security Assurance Questionnaires and responding to customer and supplier security due diligence.

  • Working knowledge of Data Protection Officer responsibilities, UK GDPR and the Data Protection Act 2018.

  • Relevant certification such as ISO Lead Implementer or Lead Auditor, and a recognised data protection qualification (for example BCS/CIPP).

  • Strong documentation skills and the ability to work independently with minimal oversight.

  • Ability to handle special category or sensitive personal data with appropriate care and confidentiality.