Enable job alerts via email!

InfoSec Analyst

Locke & Mccloud

Greater London

Hybrid

GBP 55,000 - 65,000

Full time

30 days ago

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

Join a forward-thinking law firm as an Information Security Analyst, where you'll play a crucial role in enhancing security governance and resilience across various jurisdictions. This position involves maintaining ISMS, ensuring compliance with ISO 27001:2022, and conducting audits. You'll also engage in incident investigation and deliver training to promote secure behaviors. This innovative firm is dedicated to a major cyber transformation, providing a dynamic environment where your contributions will significantly impact the organization's security posture. If you're passionate about information security and compliance, this is the perfect opportunity for you.

Qualifications

  • Experience in information security or compliance-based roles is essential.
  • Knowledge of ISO 27001, Cyber Essentials, or NIST frameworks is required.

Responsibilities

  • Maintain and improve the ISMS, ensuring ISO 27001:2022 alignment.
  • Conduct internal audits and support third-party reviews.

Skills

Information Security
Compliance
Communication
Collaboration
Incident Investigation

Education

Experience in Information Security or Compliance
Certifications (CISMP, CISSP, ISO 27001 Lead Auditor)

Tools

ISO 27001
Cyber Essentials
NIST Framework
Microsoft 365

Job description

Information Security Analyst

Hybrid (London, 3 Days Onsite + Flexible Working)| £55,000–£65,000 + Strong UK Benefits | Strategic Cyber Investment

Be part of a forward-thinking law firm undergoing a major cyber transformation. As anInformation Security Analyst, you’ll support governance, lead audits, and build security resilience across multiple jurisdictions.

What You’ll Be Doing

  • Maintain and improve the ISMS, including policies, procedures, and guidelines

  • Ensure ongoing ISO 27001:2022 alignment across UK and international offices

  • Conduct internal audits, lead remediation efforts, and support third-party reviews

  • Run supplier due diligence and respond to client risk assessments

  • Investigate and escalate incidents, contributing to ongoing threat awareness

  • Deliver awareness training and drive adoption of secure behaviours

What You’ll Bring

  • Experience in information security or compliance-based roles

  • Knowledge of ISO 27001, Cyber Essentials, NIST or similar frameworks

  • Ability to communicate and collaborate across business functions

  • Comfortable working in cloud and Microsoft 365 environments

  • Certifications like CISMP, CISSP or ISO 27001 Lead Auditor are a bonus

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.