IT Contractors UK Profile

Michael Somers

Fractional CISO & Interim Cyber Security Leader | GRC, PCI DSS, ISO 27001 | Outside IR35

Verified email Founding Contractor · 2026

Contractor snapshot

Primary specialism Cyber Security
Location / working location Manchester
Current availability Available now Confirmed 26 Aug 2026
Profile status Active contractor profile

Professional profile

Senior cyber security and GRC leader with 18+ years’ experience delivering pragmatic security, compliance and risk programmes across complex organisations. Experienced in Fractional CISO, Interim CISO, Head of Cyber Security and Head of GRC roles, with particular strengths in PCI DSS, ISO 27001, cyber risk, security governance, third-party risk, incident response, security assurance and executive-level stakeholder engagement. Former PCI DSS QSA with hands-on experience helping organisations achieve and maintain compliance, improve security maturity and translate technical risk into clear business decisions. Available for senior contract, interim and fractional engagements, including Outside IR35 assignments.

Core skills

CISO Fractional CISO Cyber Security Leadership GRC PCI DSS ISO 27001 Cyber Risk Management Information Security Governance Security Strategy Third-Party Risk Management Incident Response Security Assurance Compliance Internal Audit Executive Stakeholder Management

What I’m looking for next

Target roles: Fractional CISO · Interim Cyber Security Leader · GRC · PCI DSS · ISO 27001

Contract preferences

Working preferenceRemote · Hybrid
Will workRemote UK, Sensible office presence
IR35 preferenceOutside IR35
Active clearanceSC
SeniorityFlexible / depends on role
Contract lengthAny contract length
IT experience18 years
Contracting experience4 years

Relevant work experience

Over 18 years’ experience in cyber security, information security and technology, spanning senior leadership, consulting, architecture, GRC and programme delivery across retail, financial services, government, Critical National Infrastructure and regulated environments. Currently Director and Lead Consultant at Sandinista Consulting, delivering interim and fractional CISO engagements and cyber security consultancy. Recent assignments include establishing the cyber security function for the Independent Football Regulator; PCI DSS consultancy and remediation support for Post Office Ltd; ISO 27001 and ISO 9001 implementation and assurance for tombola; and security consultancy within Scottish Government. Previously contracted as PCI DSS Internal Security Assessor for John Lewis Partnership, acting as a subject matter expert across PCI DSS v4, payment architecture, FCA-related requirements and wider cyber security matters. Former Managing Consultant at Cyro Cyber, delivering vCISO and security architecture services across Critical National Infrastructure and major UK rail programmes. Prior permanent leadership includes Head of Cyber Security at CVS Group, where I developed and delivered the organisation’s three-year cyber strategy, security architecture, supplier assurance, risk management and security transformation programme. Earlier spent four years with Nettitude, consulting to more than 120 organisations across financial services, retail, public sector and multinational businesses, and previously led IT and Information Security for CNI provider Open Energi. Former PCI DSS QSA, CISSP and ISO 27001 Lead Auditor, with extensive board and C-suite stakeholder experience.

Experience & credentials

Certifications, sector experience and security clearance are self-declared unless specifically marked as independently verified by IT Contractors UK.

Certifications

CISSP

Professional links

Contact details are controlled by the contractor and are not displayed automatically. Profile information is self-declared unless explicitly marked as verified.

All content © 2013–2026 IT Contractors UK. All rights reserved. Unauthorised use, reproduction, or distribution of any material is strictly prohibited.