The Firm
Join a leading law firm with a strong reputation for delivering high-quality legal services to clients across a range of sectors. As the firm continues to strengthen its information security and risk capabilities, it is looking for an Information Security Analyst to join its Information Security and Risk & Compliance function.
This is an excellent opportunity for someone looking to develop their career within Information Security Governance, Risk and Compliance (GRC), with exposure to ISO 27001, risk management, supplier assurance, audits and information security governance within a professional services environment.
The Role
As an Information Security Analyst, you will support the ongoing development and maintenance of the firm's Information Security Management System (ISMS) and wider governance framework.
You will work closely with stakeholders across the firm, supporting information security governance, risk management, supplier assurance, client due diligence, audit preparation, policy management, reporting and security awareness activities.
Key Responsibilities
- Support the administration and continual improvement of the firm's Information Security Management System (ISMS).
- Assist with ISO 27001 certification, surveillance and internal audit activities.
- Coordinate the collection of audit evidence and support remediation tracking.
- Support the management and maintenance of information security policies, standards, procedures and supporting documentation.
- Maintain information security risk, treatment, action and exception tracking records.
- Coordinate client information security due diligence questionnaires and assurance requests.
- Support third-party supplier assurance and risk assessment activities.
- Assist with the production of information security metrics, dashboards and management reporting.
- Support ISMS objectives and wider governance reporting.
- Assist with security awareness, communications and training initiatives across the firm.
- Maintain information security governance documentation, registers and tracking mechanisms.
- Work collaboratively with stakeholders across the business to support information security and compliance requirements.
About You
We're looking for someone with an interest in developing a career within Information Security, GRC, Risk & Compliance.
You will ideally have:
- An understanding of information security, risk management and governance principles.
- Strong organisational and administrative skills.
- Excellent written and verbal communication skills.
- Excellent attention to detail and a methodical approach to work.
- The ability to manage multiple priorities and meet deadlines.
- Strong analytical and problem-solving skills.
- Good working knowledge of Microsoft Office, including Word, Excel, PowerPoint and Outlook.
- The ability to build effective relationships with stakeholders at all levels.
- A self-motivated approach and willingness to learn and develop within Information Security and Risk & Compliance.
Desirable Experience
Experience or knowledge in any of the following would be advantageous:
- ISO 27001 or other information security frameworks.
- Supporting audits, compliance activities or governance processes.
- Working within Information Security, Risk, Compliance, Governance or a related function.
- Supplier assurance and third-party risk management.
- Producing reports, dashboards or management information.
- Relevant qualifications or certifications such as ISC2 Certified in Cybersecurity (CC), CompTIA Security+, ISO 27001 Foundation or similar.