Cyber Security & Compliance Lead

Russell-Cooke

Greater London

On-site

GBP 90,000 - 130,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Russell-Cooke is seeking a Cyber Security & Compliance Lead to define, deliver, and continuously improve the firm’s cyber security, information security, and compliance framework. You will work with IT, Risk & Compliance, and senior stakeholders to embed a strong security culture and align security with business priorities and client expectations.

The role requires senior-level expertise in cyber risk, incident response, and regulatory compliance, with a focus on ISO 27001, GDPR, and related

Qualifications

  • Significant experience in cyber security, information security, or IT risk roles.
  • Experience operating at a senior or lead level within a professional services or regulated environment.
  • Strong understanding of security frameworks (e.g. ISO 27001, NIST, Cyber Essentials, GDPR).
  • Experience managing cyber risk, audits, and compliance programmes.
  • Experience handling security incidents and leading response activities.
  • Ability to translate technical risk into clear business language for senior stakeholders.

Responsibilities

  • Define and deliver the firm’s cyber security and information security strategy, aligned to business objectives and regulatory requirements.
  • Own the firm’s cyber risk framework, including risk identification, assessment, mitigation, and reporting to senior leadership.
  • Establish and maintain security policies, standards, and controls, ensuring alignment with frameworks such as ISO 27001, GDPR, and legal sector requirements.
  • Lead security governance and compliance activities, including audits, certifications, client security assessments, and regulatory reporting.
  • Act as the firm’s senior escalation point for cyber incidents, overseeing response, investigation, and remediation activities.
  • Oversee threat detection, vulnerability management, and security monitoring, working with internal teams and external providers (e.g. SOC services).
  • Ensure effective identity and access management controls, data protection measures, and secure handling of sensitive client and firm data.
  • Work closely with the IT Infrastructure and Development Lead to ensure systems are designed and implemented securely ("secure by design").
  • Work closely with the IT Service Management Lead to ensure security controls are embedded within operational processes and incident management.
  • Develop and deliver a firm-wide security awareness and training programme, promoting a strong security culture across all staff.
  • Manage relationships with security vendors and partners, ensuring effective delivery of services and alignment with firm requirements.
  • Provide clear, business-focused reporting on cyber risk, incidents, and compliance to senior leadership and, where required, clients.
  • Support client engagements and audits, ensuring the firm meets client security expectations and due diligence requirements (increasingly critical in legal sector).
  • Stay informed of emerging threats, regulatory changes, and industry best practice, ensuring the firm adapts its security posture accordingly.

Skills

Cyber security
Information security
IT risk management
Senior/lead level experience
Regulated environment
ISO 27001
NIST
GDPR

Tools

SIEM tools
SOC services
Security platforms

Job description

Hours

Full-time, 9:30am - 5.30pm with flexibility required to support system changes, upgrades and critical incidents where necessary.

CYBER SECURITY & COMPLIANCE LEAD
Hours

Full-time, 9:30am - 5.30pm with flexibility required to support system changes, upgrades and critical incidents where necessary.

Department

IT / Risk & Compliance

The Role

The Cyber Security & Compliance Lead is responsible for defining, delivering, and continuously improving the firm’s cyber security, information security, and compliance framework.

The role ensures that the firm’s systems, data, and client information are protected against evolving threats, while maintaining compliance with regulatory, legal, and client-driven security requirements.

Acting as the firm’s senior authority on cyber risk, the role works closely with IT, Risk & Compliance, and senior stakeholders to embed a strong security culture and ensure that security is aligned to business priorities and client expectations.

Essential
Technical skills and expertise
  • Significant experience in cyber security, information security, or IT risk roles.
  • Experience operating at a senior or lead level within a professional services or regulated environment.
  • Strong understanding of security frameworks (e.g. ISO 27001, NIST, Cyber Essentials, GDPR).
  • Experience managing cyber risk, audits, and compliance programmes.
  • Experience handling security incidents and leading response activities.
  • Ability to translate technical risk into clear business language for senior stakeholders.
Desirable
  • Experience within a law firm or legal services environment.
  • Experience supporting client security audits and due diligence processes.
  • Familiarity with SOC services, SIEM tools, and modern security platforms.
  • Professional certifications (e.g. CISSP, CISM, ISO 27001 Lead Implementer).
Key Responsibilities

Duties include but are not limited to:

  • Define and deliver the firm’s cyber security and information security strategy, aligned to business objectives and regulatory requirements.
  • Own the firm’s cyber risk framework, including risk identification, assessment, mitigation, and reporting to senior leadership.
  • Establish and maintain security policies, standards, and controls, ensuring alignment with frameworks such as ISO 27001, GDPR, and legal sector requirements.
  • Lead security governance and compliance activities, including audits, certifications, client security assessments, and regulatory reporting.
  • Act as the firm’s senior escalation point for cyber incidents, overseeing response, investigation, and remediation activities.
  • Oversee threat detection, vulnerability management, and security monitoring, working with internal teams and external providers (e.g. SOC services).
  • Ensure effective identity and access management controls, data protection measures, and secure handling of sensitive client and firm data.
  • Work closely with the IT Infrastructure and Development Lead to ensure systems are designed and implemented securely ("secure by design").
  • Work closely with the IT Service Management Lead to ensure security controls are embedded within operational processes and incident management.
  • Develop and deliver a firm-wide security awareness and training programme, promoting a strong security culture across all staff.
  • Manage relationships with security vendors and partners, ensuring effective delivery of services and alignment with firm requirements.
  • Provide clear, business-focused reporting on cyber risk, incidents, and compliance to senior leadership and, where required, clients.
  • Support client engagements and audits, ensuring the firm meets client security expectations and due diligence requirements (increasingly critical in legal sector).
  • Stay informed of emerging threats, regulatory changes, and industry best practice, ensuring the firm adapts its security posture accordingly.
Salary And Benefits

We offer competitive salaries and generous benefits.

We have a diverse workforce and aim to attract high calibre applicants that reflect the demography of our geographical location and client base. Individuals will be employed solely on merit and the requirement of the position. No applicant or employee receives less favourable treatment on the grounds of sex, race, marital status, disability, age, sexual orientation, gender Identity or religion. Reasonable adjustments will be made to eliminate or reduce disadvantage.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security & Compliance Lead
Cyber Security & Compliance Lead

Russell Cooke LLP • Greater London

On-site
GBP 90,000 - 130,000
Head of Information Security
Head of Information Security

Kingsley Napley • Greater London

On-site
GBP 120,000 - 180,000
Pension
Life assurance
Private medical insurance
+7
Head of IT Security - Law Firm
Head of IT Security - Law Firm

Totum Partners • Greater London

Hybrid
GBP 120,000 - 180,000
Hybrid work (2 days onsite)
Professional development
Cyber Security Consulting Lead
Cyber Security Consulting Lead

DiverseJobsMatter • Greater London

Hybrid
GBP 90,000 - 140,000
30 days holiday + buy 2
Pension 10%
Hybrid working
Managing Consultant - FS - Digital Trust and Cyber Security
Managing Consultant - FS - Digital Trust and Cyber Security

PA Consulting • City of Westminster

On-site
GBP 70,000 - 100,000
Health and lifestyle perks
25 days annual leave
Generous pension scheme
+2
Cyber Risk & Security Manager
Cyber Risk & Security Manager

Spirit UK Ltd • Greater London

Hybrid
GBP 50,000 - 70,000
Cyber Security Manager
Cyber Security Manager

La Fosse • Greater London

Hybrid
GBP 60,000 - 90,000
Fast-paced work environment
Opportunity for career growth
Legal Director – Cyber (FTC)
Legal Director – Cyber (FTC)

Cyber UK • Greater London

On-site
GBP 90,000 - 150,000
IT Cyber Security Specialist
IT Cyber Security Specialist

Picture More Ltd • City Of London

Hybrid
GBP 95,000 - 100,000
Cyber Security Consultant
Cyber Security Consultant

Moore Kingston Smith • Greater London

On-site
GBP 42,000 - 50,000