Information Security Analyst

Herbert Smith Freehills Kramer

City Of London

On-site

GBP 40,000 - 60,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

A global law firm is seeking an experienced Information Security professional as part of its General Counsel & Risk team. You will focus on enhancing security processes, ensuring compliance with ISO 27001, and collaborating with various internal teams. The ideal candidate has a technical degree, strong experience in information security, and familiarity with security tools. This role presents a unique opportunity to impact security practices across EMEA offices while managing projects related to security awareness and incident response.

Qualifications

  • Degree educated (technical degree or similar).
  • Approximately three years' experience in information security.
  • Strong knowledge of ISO 27001 implementation.

Responsibilities

  • Provide assurance to external stakeholders.
  • Support maintenance of the Firms ISO 27001 certification.
  • Manage ISMS tools, documentation, and trackers.

Skills

ISO 27001 implementation
Power BI analytics
Information security
Relationship building
Adaptability

Education

Degree in a technical field
MSc in security or similar

Tools

Email DLP
UEBA
Phishing simulation tools

Job description

Overview

An exciting opportunity within the General Counsel & Risk team as part of our global Information Security team.

The individual will work closely with the UK, Australia and US-based teams in the following primary areas of responsibility, focusing on the UK and EMEA offices:

Responsibilities
  • Providing assurance to external stakeholders, including:
  • Supporting the maintenance of the Firms ISO 27001 certification, in particular:
  • Preparing new and existing business units for certification/audit.
  • Collating metrics in support of governance and continual improvement.
  • Risk assessing new ways of working, alongside the Risk and IT teams.
  • Assessing compliance with client-specific security requirements within the legal teams.
  • Managing the ISMS tools, documentation and trackers.
  • Supporting internal security audit activities.
  • Operational Security Oversight
  • Investigate and manage DLP alerts and user behaviour anomalies, escalating as needed.
  • Support incident response for phishing, impersonation scams, and other security events.
  • Assist with API integration projects to enhance security workflows (e.g., ServiceNow integrations).
  • Security Awareness & Education
  • Deliver and monitor phishing simulation campaigns, producing reports and insights.
  • Contribute to security communications and awareness programs across the firm.
  • Strategic Initiatives
  • Participate in onboarding new security technologies such as Data Security Posture Management (DSPM).
  • Engage with AI Risk and Governance discussions to support emerging technology adoption.
  • Stakeholder Collaboration
  • Build strong relationships with IT, Risk, HR, and legal teams to embed security into business processes
  • Provide practical security advice to internal stakeholders.
Qualifications / Skills / Experience
  • Degree educated (technical degree or similar).
  • We would expect the successful candidate to have around three years\' experience in information security but may consider those with less experience providing they can demonstrate they meet the required competencies.
  • Strong knowledge of ISO 27001 implementation and certification.
  • Power BI analytics and reporting.
  • One or more of the following desired - MSc in security or similar; CISSP; CISA/CISM; ISO 27001 Lead Auditor.
  • Professional Services experience preferable.
  • Adaptable, diligent and works with initiative.
  • Strong relationship builder - internal and external.
  • Familiarity with security tools and systems would be advantageous (e.g., Email DLP, UEBA, phishing simulation).
  • Experience working as part of a global team.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information Security Analyst
Information Security Analyst

Herbert Smith Freehills Kramer • City Of London

On-site
GBP 60,000 - 80,000
Information Security Manager
Information Security Manager

Frontpoint Partners Ltd • Greater London

On-site
GBP 85,000 - 110,000
Information Security Engineer
Information Security Engineer

Selby Jennings • Greenwich

On-site
GBP 70,000 - 100,000
Information Security Analyst
Information Security Analyst

Broster Buchanan • Liverpool

On-site
GBP 40,000 - 60,000
Information Security And Assurance Analyst
Information Security And Assurance Analyst

MLR Associates • Pirbright

Hybrid
GBP 35,000 - 40,000
Hybrid working
Benefits package
Enterprise Security Risk Manager
Enterprise Security Risk Manager

Core-Asset Consulting Ltd • City of Edinburgh

On-site
GBP 70,000 - 110,000
Information Security Consultant
Information Security Consultant

InfraView Ltd • Greater London

On-site
GBP 70,000 - 85,000
Head of Information Security
Head of Information Security

Michael James Associates • Greater London

On-site
GBP 120,000 - 180,000
Head of Information Security and Privacy
Head of Information Security and Privacy

Morgan Law • Greater London

On-site
GBP 120,000 - 180,000
IT Information Security Analyst - Compliance
IT Information Security Analyst - Compliance

Adecco • West Midlands

Hybrid
GBP 45,000 - 55,000