Cyber Security Governance Manager (Part‑Time)
Hours: 2–3 days per week (0.4–0.6 FTE)
Salary: £22,000–£30,000 (£45,000–£60,000 FTE equivalent)
Location: Kent (hybrid)
Reports to: Managing Director / Operations Director
About Us
Kyndi is a leading provider of assistive technologies and monitoring solutions aimed at enhancing the lives of individuals with disabilities. Our innovative products empower users to overcome challenges and live more independently. We are dedicated to providing cutting-edge personalised solutions that make a meaningful impact on the lives of our customers.
Role Purpose
The Cyber Security Governance Manager is the organisation’s internal owner of cyber risk, responsible for ensuring external IT providers deliver secure, compliant, and reliable services. This role provides governance and assurance rather than hands-on technical engineering; MSPs/providers retain responsibility for technical delivery.
The postholder will ensure the business meets Cyber Essentials Plus, GDPR, and internal security standards while maintaining strong control over identity, access, and supplier performance.
The role requires someone confident in working with outsourced IT providers, setting clear expectations, reviewing evidence, and ensuring security standards are maintained across the organisation.
This part-time role would suit an experienced cyber governance, compliance, or security assurance professional looking to take ownership of internal cyber and IT governance within a growing organisation.
Key Responsibilities
1. Cyber Risk Ownership
- Maintain and update the cyber risk register.
- Present quarterly cyber risk updates to leadership.
- Monitor GDPR, Cyber Essentials Plus, and relevant regulatory requirements.
- Track key security actions and risks through to completion.
2. Identity & Access Governance
- Approve privileged access and admin accounts.
- Ensure MFA, conditional access, and device compliance are enforced.
- Oversee secure joiners/leavers processes.
- Monitor and review supplier access permissions on a regular basis.
3. Supplier Oversight & Assurance
- Manage the Infrastructure Provider and Support Provider.
- Chair monthly IT & cyber governance meetings.
- Validate patching, backups, monitoring, endpoint security, phishing/user awareness controls, and other key security measures.
- Ensure both suppliers collaborate effectively and meet SLAs.
4. Policy & Governance Control
- Maintain cyber security policies (access control, MFA, device compliance, incident response).
- Confirm policies are followed and supporting evidence is retained.
- Approve changes with security impact.
5. Incident Response Leadership
- Act as Incident Lead during cyber events.
- Coordinate suppliers and internal stakeholders.
- Ensure evidence capture and post‑incident review.
- Implement lessons learned and improvements.
6. Compliance & Audit Evidence
- Own Cyber Essentials Plus readiness and evidence collection.
- Oversee penetration test remediation.
- Maintain audit logs, supplier reports, and compliance documentation.
Skills & Experience Required
Essential
· Strong governance, risk, or operational leadership background.
· Ability to challenge suppliers and enforce standards.
· Understanding of cyber security principles (non‑technical).
· Experience with compliance frameworks (GDPR, CE+, ISO27001 basics).
· Excellent communication and documentation skills.
· Practical experience preparing an organisation for Cyber Essentials Plus certification/audit.
· Practical ISO 27001/ISMS experience.
Desirable
· Experience managing outsourced IT providers.
· Knowledge of identity and access security (MFA, conditional access).
· Incident response coordination experience.
· ITIL Foundation.
Qualifications
Essential
· GDPR/Data Protection training.
Desirable
· CompTIA Security+.
· NCSC Incident Response training.
Please note: Due to the nature of this role, successful candidates must complete a Non-Police Personnel Vetting (Level 1) and a DBS check.
Please be aware that Police vetting is a strict requirement of the role and is outside of Kyndi’s discretion. Vetting checks may take into account criminal convictions, cautions, associations and relevant information relating to both the candidate and their immediate family members.
Candidates should carefully consider whether there is anything in their own background, or that of their immediate family, which may prevent them from successfully passing Police vetting.
Unfortunately, if a candidate is unable to obtain the required Police vetting clearance, they will not be able to take up the role.
We want every candidate to have the opportunity to perform at their best throughout our recruitment process. If you require any reasonable adjustments, please let us know.
We are proud to support members of the Armed Forces community and welcome applications from Reservists and Veterans. We recognise the valuable skills and experience gained through military service and are committed to supporting employees who have Reservist commitments. This includes providing flexibility for training commitments and supporting employees who may be mobilised for service. Our aim is to ensure Reservists have the same opportunities for employment and career development whilst balancing their service commitments.
We are an equal opportunities employer and welcome applications from everyone.
Pay: £45,000.00-£60,000.00 per year
Benefits:
- Casual dress
- Company pension
- Employee discount
- Free parking
- Health & wellbeing programme
- Life insurance
- Sick pay
Application question(s):
- Do you have practical experience preparing an organisation for Cyber Essentials Plus certification/audit?
- Do you have practical ISO 27001/ISMS experience?
Language:
Work authorisation:
- United Kingdom (required)
Work Location: Hybrid remote in Chatham