Information Security Analyst

Herbert Smith Freehills Kramer

City Of London

On-site

GBP 60,000 - 80,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

A global law firm in London is seeking an Information Security professional to support their ISO 27001 certification and manage security tools. Candidates should have a degree and around three years of experience in information security, with strong ISO 27001 knowledge. The role involves providing assurance to stakeholders, risk assessment, and collaboration with IT and legal teams. This position offers the opportunity to work with a global team on emerging security technologies.

Qualifications

  • 3 years of experience in information security, or less with required competencies.
  • Strong knowledge of ISO 27001 certification.
  • Ability to deliver and monitor phishing simulation campaigns.

Responsibilities

  • Provide assurance to external stakeholders related to information security.
  • Support ISO 27001 certification and audit processes.
  • Manage ISMS tools, documentation and reports.

Skills

Information security
ISO 27001 implementation
Power BI analytics
Risk assessment
Stakeholder collaboration

Education

Degree educated (technical degree or similar)
MSc in security or similar
CISSP
CISA/CISM
ISO 27001 Lead Auditor

Tools

DLP tools
UEBA
Phishing simulation tools

Job description

Overview

An exciting opportunity within the General Counsel & Risk team as part of our global Information Security team.

The individual will work closely with the UK, Australia and US-based teams in the following primary areas of responsibility, focusing on the UK and EMEA offices:

Responsibilities
  • Providing assurance to external stakeholders, including:
  • Supporting the maintenance of the Firms ISO 27001 certification, in particular:
  • Preparing new and existing business units for certification/audit.
  • Collating metrics in support of governance and continual improvement.
  • Risk assessing new ways of working, alongside the Risk and IT teams.
  • Assessing compliance with client-specific security requirements within the legal teams.
  • Managing the ISMS tools, documentation and trackers.
  • Supporting internal security audit activities.
  • Operational Security Oversight
  • Investigate and manage DLP alerts and user behaviour anomalies, escalating as needed.
  • Support incident response for phishing, impersonation scams, and other security events.
  • Assist with API integration projects to enhance security workflows (e.g., ServiceNow integrations).
  • Security Awareness & Education
  • Deliver and monitor phishing simulation campaigns, producing reports and insights.
  • Contribute to security communications and awareness programs across the firm.
  • Strategic Initiatives
  • Participate in onboarding new security technologies such as Data Security Posture Management (DSPM).
  • Engage with AI Risk and Governance discussions to support emerging technology adoption.
  • Stakeholder Collaboration
  • Build strong relationships with IT, Risk, HR, and legal teams to embed security into business processes
  • Provide practical security advice to internal stakeholders.
Qualifications / Skills / Experience
  • Degree educated (technical degree or similar).
  • We would expect the successful candidate to have around three years\' experience in information security but may consider those with less experience providing they can demonstrate they meet the required competencies.
  • Strong knowledge of ISO 27001 implementation and certification.
  • Power BI analytics and reporting.
  • One or more of the following desired - MSc in security or similar; CISSP; CISA/CISM; ISO 27001 Lead Auditor.
  • Professional Services experience preferable.
  • Adaptable, diligent and works with initiative.
  • Strong relationship builder - internal and external.
  • Familiarity with security tools and systems would be advantageous (e.g., Email DLP, UEBA, phishing simulation).
  • Experience working as part of a global team.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Analyst
Information Security Analyst

Herbert Smith Freehills Kramer • City Of London

On-site
GBP 40,000 - 60,000
Cyber Security Analyst
Cyber Security Analyst

Novia Financial plc • Bath

On-site
GBP 55,000 - 75,000
Information Security Manager
Information Security Manager

Frontpoint Partners Ltd • Greater London

On-site
GBP 85,000 - 110,000
Information Security Engineer
Information Security Engineer

Selby Jennings • Greenwich

On-site
GBP 70,000 - 100,000
Head of Information Security
Head of Information Security

Michael James Associates • Greater London

On-site
GBP 120,000 - 180,000
Information Security Manager - HYBRID
Information Security Manager - HYBRID

Proactive Appointments • Cambridgeshire and Peterborough

On-site
GBP 60,000 - 90,000
Head of Information Security and Privacy
Head of Information Security and Privacy

Morgan Law • Greater London

On-site
GBP 120,000 - 180,000
IT Information Security Analyst - Compliance
IT Information Security Analyst - Compliance

Adecco • West Midlands

Hybrid
GBP 45,000 - 55,000
IT GRC Senior Analyst
IT GRC Senior Analyst

Nigel Wright Recruitment • Newcastle upon Tyne

Hybrid
GBP 70,000 - 90,000
Hybrid work policy
Security Analyst
Security Analyst

Peaple Talent • Manchester

On-site
GBP 40,000 - 60,000