ISO 27001 Security Governance Lead

DLA Piper LLP

Greater London

On-site

GBP 70,000 - 110,000

Full time

48 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Flexible working arrangements
Inclusion and diversity

Job summary

DLA Piper is seeking an Information Security Assurance Lead to own the ISO 27001:2022 framework, coordinate audits, and drive continual improvement across policy, risk and governance processes. The role involves testing security controls, reporting findings to stakeholders, and supporting risk-based decision making.

You will collaborate with the enterprise risk team to ensure regulatory and contractual obligations are met, while contributing to security awareness and client-facing assurance

Qualifications

  • Experience operating or supporting an ISO 27001 Information Security Management System
  • Knowledge of information security control frameworks and assurance methodologies
  • Knowledge of Cyber Essentials Plus
  • Ability to assess the effectiveness of security controls and identify improvement opportunities
  • Experience coordinating audit, certification or assurance activities
  • Ability to translate technical and governance topics into practical business outcomes
  • Experience presenting security findings, recommendations and risk information to stakeholders
  • Experience identifying, assessing and managing information security risks
  • Understanding of information security threats, vulnerabilities and control environments
  • Experience applying risk management principles, frameworks and methodologies
  • Ability to evaluate the potential business impact of security risks and control gaps

Responsibilities

  • Own and maintain the ISO 27001:2022 Information Security Management System
  • Coordinate internal and external certification audits
  • Manage the lifecycle of policies, standards and supporting documentation
  • Facilitate management reviews and support continual improvement activities
  • Ensure security governance processes remain aligned to business objectives and evolving risk
  • Design and operate a programme of security control testing and assurance activities
  • Assess the effectiveness of administrative, technical and operational controls
  • Produce assurance reports and communicate outcomes to relevant stakeholders
  • Monitor remediation activities and support closure of identified weaknesses
  • Develop assurance dashboards, metrics and management reporting
  • Support the ongoing maturity of the security governance framework
  • Review the impact of regulatory, industry and client requirements on the control environment
  • Contribute to internal security awareness and governance initiatives
  • Support external client requests relating to security assurance and certification activities where required
  • Facilitate identification, assessment and evaluation of security risks
  • Provide analysis and recommendations to support risk-based decisions
  • Monitor risk treatment activities and provide challenge where appropriate
  • Support risk acceptance and exception management processes

Skills

ISO 27001 knowledge
Audit coordination
Risk management
Governance & reporting
Stakeholder communication
Security control assessment

Education

ISO 27001 Lead Implementer
Lead Auditor
CISSP
CISM
CRISC

Tools

NIST CSF knowledge
CIS Controls knowledge

Job description

DLA Piper is seeking an Information Security Assurance Lead to own the ISO 27001:2022 framework, coordinate audits, and drive continual improvement across policy, risk and governance processes. The role involves testing security controls, reporting findings to stakeholders, and supporting risk-based decision making.

You will collaborate with the enterprise risk team to ensure regulatory and contractual obligations are met, while contributing to security awareness and client-facing assurance

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Information Security Controls & ISO27001 Lead
Senior Information Security Controls & ISO27001 Lead

Bdo • City of Westminster

On-site
GBP 90,000 - 140,000
Senior Information Security Lead (ISO 27001 & Risk)
Senior Information Security Lead (ISO 27001 & Risk)

BDO UK LLP • Greater London

Hybrid
GBP 90,000 - 130,000
Senior GRC Lead: ISO 27001 & AI Security
Senior GRC Lead: ISO 27001 & AI Security

Cirrus Logic • City of Edinburgh

Hybrid
GBP 49,000 - 80,000
Hybrid work model
Edinburgh office
Global GRC Lead — ISO 27001/02/05, ISO 31000 & Audits
Global GRC Lead — ISO 27001/02/05, ISO 31000 & Audits

Precise Placements • City Of London

On-site
GBP 65,000 - 95,000
Security Assurance Lead — ISO 27001, NIST, SOC2
Security Assurance Lead — ISO 27001, NIST, SOC2

TalentHawk • England

On-site
GBP 60,000 - 80,000
Global Health & Safety Leader — ISO 45001 & Risk Governance
Global Health & Safety Leader — ISO 45001 & Risk Governance

DLA Piper • Leeds

Hybrid
GBP 90,000 - 130,000
Global Information Security Analyst — ISO 27001 & Risk
Global Information Security Analyst — ISO 27001 & Risk

Herbert Smith Freehills Kramer • City Of London

On-site
GBP 60,000 - 80,000
Hybrid/Remote ISO 27001 InfoSec Lead & Compliance
Hybrid/Remote ISO 27001 InfoSec Lead & Compliance

Ascend Consulting • City Of London

Hybrid
GBP 59,000 - 72,000
Global Information Security Analyst — ISO 27001 & Risk
Global Information Security Analyst — ISO 27001 & Risk

Herbert Smith Freehills Kramer • City Of London

On-site
GBP 40,000 - 60,000
GRC Lead
GRC Lead

Precise Placements • City Of London

On-site
GBP 65,000 - 95,000