We are working with a leading international law firm on the appointment of a Head of Information Security to lead and further develop the firm's global Information Security function.
This is a senior leadership position with responsibility for shaping the firm's Information Security strategy, strengthening its security governance and risk framework, and ensuring the organisation remains resilient against an increasingly sophisticated threat landscape.
The successful candidate will work closely with senior Technology and Business stakeholders, providing strategic direction while also ensuring that security initiatives are effectively delivered across the organisation.
Key Responsibilities
- Lead and develop the firm's global Information Security function, setting the strategy, roadmap and priorities.
- Own and evolve the Information Security strategy in line with wider business and technology objectives.
- Establish and maintain appropriate security governance, policies, standards, controls and assurance frameworks.
- Provide senior leadership with clear advice on cyber and information security risks, emerging threats and appropriate mitigation strategies.
- Work closely with the CIO, CISO, Technology leadership and wider business stakeholders to embed security across the organisation.
- Lead Information Security risk management, including risk assessment, treatment and reporting.
- Oversee security governance, compliance, audit and regulatory requirements.
- Partner with Cyber Security, Infrastructure, Cloud, Architecture, Data and Technology teams to ensure security is embedded across the technology estate.
- Provide oversight of third-party and supply-chain security risk.
- Support major technology and business transformation programmes, including cloud adoption, AI and emerging technology initiatives.
- Develop effective security metrics and reporting for senior leadership and governance forums.
- Lead, mentor and develop members of the Information Security team.
- Promote a strong security culture across the firm through awareness, education and stakeholder engagement.
Experience Required
We are looking for an experienced Information Security leader who has operated at a senior level within a complex and internationally distributed organisation.
You will ideally have:
- Significant experience leading Information Security, Cyber Security or a closely related function.
- Experience developing and delivering enterprise-wide Information Security strategy.
- Strong knowledge across security governance, risk, compliance and assurance.
- Experience managing and influencing senior business and technology stakeholders.
- Strong understanding of cloud security, IAM, infrastructure security and enterprise technology environments.
- Experience managing third-party and supply-chain security risk.
- Experience operating within a regulated, highly risk-se