Information Security Analyst

Bird & Bird LLP

City Of London

On-site

GBP 55,000 - 70,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Bird & Bird LLP is seeking a motivated Information Security Analyst to join its global Information Security Team. The role spans security operations, incident response, governance, risk management, compliance and supplier assurance, working across IT, risk and external security providers.

You will help maintain the ISMS, support audits and promote a strong security culture across the firm, with opportunities to influence international projects and technology solutions.

Qualifications

  • Experience in information security, cyber security or security operations.
  • Experience investigating security incidents and managing alerts.
  • Good understanding of Microsoft 365, Azure/Entra ID and cloud security principles.
  • Experience with vulnerability management programmes.
  • Familiarity with risk assessment methodologies and security governance practices.
  • Experience with security tooling such as SIEM, EDR/XDR, vulnerability scanners and email security platforms.
  • Experience in a law firm, professional services or regulated environment.
  • Knowledge of Microsoft Security technologies including Defender, Sentinel, Purview and Entra ID.

Responsibilities

  • Monitor, investigate and respond to security alerts across on‑prem and cloud environments.
  • Lead incident triage, containment and post‑incident reviews to minimise risk.
  • Coordinate vulnerability management and remediation across infrastructure and cloud services.
  • Support ISMS activities including ISO 27001 and Cyber Essentials Plus compliance.
  • Deliver security guidance on new technologies, projects and AI initiatives.
  • Manage third‑party security assurance activities and audits.
  • Provide security awareness training and promote a security culture across the organisation.

Skills

Information security
Cyber security
Security operations
Incident response
Vulnerability management
Security governance
Security frameworks
Risk assessment
Security tooling
Cloud security

Tools

SIEM
EDR/XDR
Vulnerability scanners
Email security platforms

Job description

Bird & Bird is seeking a motivated and experienced Information Security Analyst to join its global Information Security Team. This role is ideal for an individual who enjoys a broad range of security responsibilities spanning security operations, incident response, governance, risk management, compliance, supplier assurance and security project delivery.

As a member of a small but highly effective global Information Security team, you will play a key role in protecting the confidentiality, integrity and availability of the firm's information assets and client data. The successful candidate will work closely with IT infrastructure, service delivery, legal technology, risk and compliance teams, and external security providers to continuously enhance the firm's security posture. The Information Security team is responsible for maintaining and improving the firm's Information Security Management System (ISMS), ensuring compliance with industry standards, investigating security incidents, supporting audits and promoting a strong security culture across the organisation.

Bird & Bird's Technology Team mission is to support the strong technology focus of the Firm, provide modern technology to support the business and creative solutions for our Clients.

The team cover a broad range of technologies and specialisms including business architecture, business solutions, project and programme management, modern infrastructure and they are all primarily focused on international projects working alongside colleagues in our 34 offices. Whether it's analysing new solutions, driving innovation, developing client solutions or providing a first class, high availability infrastructure and support we are a diverse, energised group focused on service and contributing to both the internal and external use of technologies. We work extensively across the network and seek candidates who are keen to engage internationally and make wider contributions both internally and externally than just IT service and delivery.

Key Responsibilities
  • Monitor, investigate and respond to security alerts and incidents across on-premise and cloud environments.
  • Lead incident triage, containment, remediation and post-incident reviews to minimise business risk.
  • Manage security operations workflows, ensuring issues are prioritised and resolved within agreed SLAs.
  • Coordinate vulnerability management activities, driving remediation across infrastructure, applications and cloud services.
  • Conduct security assessments, technical reviews and support penetration testing programmes.
  • Support and maintain the Information Security Management System (ISMS), including ISO 27001 and Cyber Essentials Plus compliance activities.
  • Perform risk assessments and ensure security policies, standards and procedures remain effective and up to date.
  • Provide security guidance on new technologies, projects, cloud services and AI adoption initiatives.
  • Manage third-party security assurance activities, including supplier assessments, client questionnaires and audits.
  • Deliver security awareness training and promote a strong security culture across the organisation.
  • Contribute to the continuous improvement of security controls, processes, reporting and strategic security initiatives.
What you'll bring
  • Experience in information security, cyber security, security operations or related disciplines.
  • Experience investigating security incidents and managing security alerts.
  • Good understanding of Microsoft 365, Azure/Entra ID and cloud security principles.
  • Experience working with vulnerability management programmes.
  • Knowledge of security frameworks and standards including:
    • ISO/IEC 27001
    • Cyber Essentials Plus
    • NIST Cyber Security Framework
    • CIS Controls
  • Familiarity with risk assessment methodologies and security governance practices.
  • Experience with security tooling such as SIEM, EDR/XDR, vulnerability scanners and email security platforms.
  • Experience within a law firm, professional services organisation, financial services firm or other highly regulated environment.
  • Experience responding to client security questionnaires and audits.
  • Knowledge of Microsoft Security technologies including Defender, Sentinel, Purview and Entra ID.
What's in it for you

We provide comprehensive support for our colleagues' health and wellbeing, including private medical cover, life assurance, critical illness cover, and regular health assessments. In addition, we offer a range of lifestyle benefits designed to help our team live their best lives, such as a cycle to work scheme, access to online GP appointments, discounted gym memberships, and an electric vehicle scheme.

If you require any assistance, please email us at talentacquisitionlondon@twobirds.com

Bird & Bird opens up a world of possible for lawyers and professionals everywhere. Working for a leading international law firm like Bird & Bird means working alongside people who are truly collegiate in the way they work with everyone. We work as one global team, with over 70% of work involving people from across the firm. And that's only increasing! It's this common purpose and shared approach that makes for a more productive and collaborative place to work. Your firm. Your future.

If you want to find out more, visit www.twobirds.com

As a disability and neurodiversity inclusive employer we want to ensure that you have a barrier-free recruitment experience at Bird & Bird. If you require any adjustments during the recruitment process, please provide details to your recruitment contact who will be in touch to discuss any details provided and understand more about your individual adjustment needs.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Analyst
Information Security Analyst

Bird & Bird • Greater London

On-site
GBP 60,000 - 90,000
Enterprise Architect
Enterprise Architect

Bird & Bird • Greater London

Hybrid
GBP 90,000 - 120,000
private medical cover
life assurance
critical illness cover
+6
Business Acceptance Analyst
Business Acceptance Analyst

Bird & Bird • Greater London

On-site
GBP 42,000 - 65,000
Private medical cover
Life assurance
Cycle to work scheme
+1
Senior LegalTech & Innovation Executive (12 month FTC)
Senior LegalTech & Innovation Executive (12 month FTC)

Bird & Bird LLP • Greater London

On-site
GBP 55,000 - 75,000
Private medical cover
Life assurance
Cycle to work scheme
+3
Client Relationship Manager
Client Relationship Manager

Bird & Bird • Greater London

On-site
GBP 70,000 - 100,000
Private medical cover
Life assurance
Critical illness cover
+5
Senior Facilities Administrator (18 month FTC)
Senior Facilities Administrator (18 month FTC)

Bird & Bird • Greater London

On-site
GBP 32,000 - 42,000
Private medical cover
Life assurance
Cycle to work scheme
+1
Global Information Security Analyst
Global Information Security Analyst

Bird & Bird LLP • City Of London

On-site
GBP 55,000 - 70,000
Receptionist
Receptionist

Bird & Bird • Greater London

On-site
GBP 21,000 - 26,000
Private medical cover
Life assurance
Critical illness cover
+4
Information Security Analyst
Information Security Analyst

Fieldfisher • Belfast City District

Hybrid
GBP 65,000 - 90,000
Private medical insurance
Health cash plan
Dental insurance
+5
Global Information Security Analyst - Incident & Risk Lead
Global Information Security Analyst - Incident & Risk Lead

Bird & Bird • Greater London

On-site
GBP 60,000 - 90,000