Project Manager
Project Manager - NSIS & Cyber Security Compliance
6-Month Contract
Inside IR35
Rate - £550 - £650p/d
Remote - with occasional meetings in either North Yorkshire or Scotland (dependant on candidates location)
We're hiring a contract Project Manager to lead delivery within a live NSIS compliance programme, working toward full compliance by the end of 2027. This isn't generic project management: it's delivery inside a security and risk-led environment, run to the standard expected of Operators of Essential Services under the UK's NIS Regulations, with governance, cyber risk and regulatory reporting under constant scrutiny.
We want a Project Manager who's genuinely comfortable in this world and can hold their own in a conversation about cyber risk or the NCSC's Cyber Assessment Framework and enjoys bringing structure to operational and security teams who aren't used to formal project discipline.
What You'll Be Leading
- Lead and deliver multiple projects within a live NSIS / critical national infrastructure compliance programme, alongside a Programme Manager, fellow Project Managers and Business Analysts.
- Own project plans, schedules and milestones end-to-end, keeping governance artefacts current in SharePoint and Microsoft Project.
- Build and run the project governance framework, risk, controls and reporting, that gives assurance to programme leadership and, ultimately, regulators.
- Translate complex security and compliance deliverables into milestones that operational and technical teams can actually deliver against.
- Produce status, risk and progress reporting fit for senior and regulator-facing scrutiny.
- Proactively manage cyber and delivery risk, surfacing issues and dependencies before they threaten the compliance deadline.
- Work hands-on with operational, technical and security stakeholders who are more used to BAU than formal project delivery and bring them into a structured way of working.
What You'll Bring
- A track record managing multiple concurrent projects inside a complex, security or risk-led programme.
- Delivery experience in a regulated industry, where governance and audit trail matter as much as pace.
- Confident stakeholder management, comfortable engaging and where needed challenging, senior stakeholders, including those from security and risk backgrounds.
- A history of introducing project structure, governance and rigour where it didn't exist before.
- Sharp planning and organisational skills, with real discipline around maintaining project controls and artefacts.
- Experience producing reporting for an executive, ideally regulator-facing, audience.
Specialist Experience We'd Love to See
- Direct exposure to the NIS Regulations, Operators of Essential Services (OES) obligations, or the NCSC's Cyber Assessment Framework (CAF).
- Background delivering cybersecurity, information security or operational resilience programmes.
- Experience in the energy or utilities sector.
- Knowledge of physical security, site security controls or infrastructure protection projects.
- Exposure to operational technology (OT) or IT/OT-converged environments.
- Familiarity with related standards or frameworks such as ISO 27001 or NIST CSF.
- Experience delivering projects involving data security, operational resilience or critical national infrastructure more broadly.