Enable job alerts via email!

InfoSec Analyst

Locke & Mccloud

London

Hybrid

GBP 55,000 - 65,000

Full time

30 days ago

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

Join a forward-thinking law firm as an Information Security Analyst during a significant cyber transformation. In this hybrid role, you will support governance, lead audits, and build security resilience across multiple jurisdictions. Your expertise in information security and compliance will be vital as you maintain the Information Security Management System (ISMS), ensuring alignment with ISO 27001:2022 standards. Collaborate with various business functions, conduct internal audits, and deliver awareness training to drive secure behaviors. This position offers a competitive salary and strong benefits, making it an exciting opportunity for professionals passionate about cybersecurity.

Qualifications

  • Experience in information security or compliance-based roles is essential.
  • Knowledge of ISO 27001, Cyber Essentials, NIST or similar frameworks is crucial.

Responsibilities

  • Maintain and improve the ISMS, ensuring ISO 27001:2022 alignment.
  • Conduct internal audits and lead remediation efforts.

Skills

Information Security
Compliance
Communication
Collaboration
Incident Investigation

Education

Experience in information security or compliance roles
Certifications like CISMP, CISSP or ISO 27001 Lead Auditor

Tools

ISO 27001
Cyber Essentials
NIST
Microsoft 365

Job description

Information Security Analyst

Hybrid (London, 3 Days Onsite + Flexible Working) | £55,000–£65,000 + Strong UK Benefits | Strategic Cyber Investment

Be part of a forward-thinking law firm undergoing a major cyber transformation. As an Information Security Analyst, you’ll support governance, lead audits, and build security resilience across multiple jurisdictions.

What You’ll Be Doing
  1. Maintain and improve the ISMS, including policies, procedures, and guidelines
  2. Ensure ongoing ISO 27001:2022 alignment across UK and international offices
  3. Conduct internal audits, lead remediation efforts, and support third-party reviews
  4. Run supplier due diligence and respond to client risk assessments
  5. Investigate and escalate incidents, contributing to ongoing threat awareness
  6. Deliver awareness training and drive adoption of secure behaviours
What You’ll Bring
  1. Experience in information security or compliance-based roles
  2. Knowledge of ISO 27001, Cyber Essentials, NIST or similar frameworks
  3. Ability to communicate and collaborate across business functions
  4. Comfortable working in cloud and Microsoft 365 environments
  5. Certifications like CISMP, CISSP or ISO 27001 Lead Auditor are a bonus
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.