Part Time
N/A
4
Aug 28, 2026
# Fractional GRC & Information Security Compliance Consultant
### GDPR, Cyber Essentials, IASME & ISO 27001 Readiness
Votari is an early-stage UK election-technology company building verifiable digital voting infrastructure.
We are looking for a hands-on **GRC / Information Security Compliance Consultant** to take ownership of our privacy, security and certification readiness.
This is not a strategy-only advisory role.
We already have substantial technical architecture documentation, a Data Protection Impact Assessment, privacy documentation, data-flow analysis and existing GDPR/security research. We need someone who can take that foundation and turn it into an operational compliance programme.
The immediate objectives are:
* Bring our GDPR compliance documentation up to date
* Complete our Record of Processing Activities
* Review our controller / processor position and data-processing relationships
* Review subprocessors, international transfers and DPAs
* Update privacy, retention, DSAR and breach-response procedures
* Maintain and update our DPIA
* Build a practical security risk register
* Formalise core information-security policies
* Prepare and guide us through Cyber Essentials
* Prepare for IASME Cyber Assurance
* Establish the foundations for ISO 27001 certification
* Organise evidence and documentation suitable for enterprise and government procurement
You would act as the operational owner of the process and coordinate specialist legal, penetration-testing or certification providers where required.
## What we are looking for
We are particularly interested in someone who has personally taken small technology companies or SaaS businesses through compliance and certification programmes.
Strong experience in several of the following is important:
* ISO 27001 implementation
* Cyber Essentials / Cyber Essentials Plus
* IASME Cyber Assurance
* GDPR operational compliance
* Record of Processing Activities
* DPIAs
* Information-security risk management
* Security policies and control frameworks
* Supplier / subprocessor reviews
* Cloud and SaaS environments
* Enterprise security questionnaires
* Government or regulated-industry procurement
Useful professional credentials include:
* ISO 27001 Lead Implementer
* ISO 27001 Lead Auditor
* CIPP/E
* CISM
* CISSP
* IASME / Cyber Essentials experience
Certifications are useful, but practical implementation experience matters more.
## Important
We are not looking for:
* a generic cybersecurity consultant
* a penetration tester
* a lawyer
* someone who only produces high-level compliance presentations
* someone whose experience is primarily managing compliance teams inside large enterprises
We need someone comfortable doing the actual work: reviewing systems, writing policies, creating registers, gathering evidence, closing gaps and driving certification activity through to completion.
## Initial engagement
We expect the initial engagement to run for approximately **8–12 weeks**, initially around **one day per week**, with flexibility around assessment or certification periods.
If the engagement works well, this may continue as a lighter fractional compliance role.
## When applying
Please answer the following:
1. Tell us about one company with fewer than approximately 20 employees that you personally helped through Cyber Essentials, ISO 27001 or a similar compliance programme.
2. What did you personally produce or implement during that engagement?
3. Have you personally prepared a company for ISO 27001 certification? If yes, what parts of the process did you own?
4. What experience do you have implementing GDPR operational requirements such as RoPA, DPIAs, processor registers, retention policies, DSAR procedures and breach-response processes?
5. Have you worked with UK Cyber Essentials or IASME Cyber Assurance?
6. If you joined Votari next week, what would you expect to complete during your first 30 days?
Please include your expected hourly or daily rate and your availability.
Generic AI-generated proposals that do not address the questions above will not be considered.