Fractional CISO (Contract / Project Based)
Remote
Engagement Overview
Cambridge Spark is an education technology company that enables corporate and government organisations to achieve their business goals by educating their workforce with critical data transformation skills to succeed in the AI era. We currently hold Cyber Essentials Plus and are seeking an independent, Fractional Chief Information Security Officer (vCISO) to define our strategic security direction and provide independent assurance.
This engagement is strictly deliverable-focused. You will not be integrating into our day-to-day operations or managing staff. Instead, you will provide senior, independent judgment and set the overarching security strategy, which will be executed by our internal IT & Systems Manager. This deliberate separation between control definition and operational execution ensures the objective assurance required by our regulated client base.
Key Deliverables & Outcomes
You will maintain full autonomy over how these outcomes are achieved as an external advisor, partnering with our Head of Engineering (acting SIRO) as your primary internal contact.
- Security Strategy & Roadmap: Define a clear, costed security strategy and sequenced improvement roadmap tailored to our evolving estate, threat landscape, and risk appetite.
- Risk & Assurance Stewardship: Architect a security-specific risk register and conduct regular, independent reviews of the control environment operated by the internal IT team.
- Board Reporting: Deliver periodic board-level reporting on organisational risk.
- Certification Direction: Deliver a formal, evidence-based recommendation on whether to pursue ISO 27001 or maintain Cyber Essentials Plus with a documented ISMS.
- Incident Framework: Design an incident response framework, testing plans, escalation pathways, and playbooks. (Note: Hands-on involvement in a live serious incident will be treated as a separate, ad-hoc call-off engagement).
- Client Assurance & Board Reporting: Mature the existing reusable security assurance evidence library for complex client due-diligence.
Operational Boundaries
To ensure unambiguous B2B boundaries and maintain focus on strategic deliverables, the following operational execution remains firmly with Cambridge Spark:
- Execution & First Response: Hands-on operations (patching, endpoint hardening, configuration) and incident first-response are owned by our internal IT & Systems Manager.
- Routine Questionnaires: Standard client security questionnaires will be completed by the internal team against the standards and evidence library you define.
- Accountability & Compliance: Final accountability sits with our SIRO. Data protection (DPO duties) and AI compliance (e.g., EU AI Act classification) sit with internal compliance owners, whom you will advise on security overlaps.
Engagement Model & Commercials
This is a phased, fractional engagement designed around project deliverables rather than a fixed weekly schedule. The cadence will naturally follow the required outputs:
- Setup Phase (~First 3 months): Estimated at 1.5 days per week (approx. 17–19 days total) to deliver the initial risk assessment, strategy, certification recommendation, and incident playbooks.
- Transition Phase (Months 4–6): Tapering to approximately 2 days per month as the roadmap moves into internal execution and the first independent assurance reviews commence.
- Steady State (Month 6 onwards): A lightweight retainer of 1–2 days per month for ongoing independent assurance, board reporting, and advisory services.





