Information Security Governance Lead

DLA Piper

Amsterdam

On-site

EUR 90,000 - 130,000

Full time

4 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

DLA Piper is seeking an Information Security Governance Lead to drive assurance activities across the firm’s information security program. You will coordinate ISO 27001 certification activities, assess control effectiveness and support the risk management framework with enterprise risk teams.

You will collaborate with stakeholders to ensure controls protect the organization, meet client commitments, and comply with regulatory and contractual obligations within risk tolerance.

Qualifications

  • Experience operating or supporting an ISO 27001 Information Security Management System.
  • Knowledge of information security control frameworks and assurance methodologies.
  • Knowledge of Cyber Essentials Plus.
  • Ability to assess the effectiveness of security controls and identify improvement opportunities.

Responsibilities

  • Own and maintain the ISO 27001:2022 Information Security Management System.
  • Coordinate internal and external certification audits.
  • Manage the lifecycle of policies, standards and supporting documentation.
  • Facilitate management reviews and support continual improvement activities.
  • Ensure security governance processes remain aligned to business objectives and evolving risk.
  • Design and operate a programme of security control testing and assurance activities.
  • Assess the effectiveness of administrative, technical and operational controls.
  • Produce assurance reports and communicate outcomes to relevant stakeholders.
  • Monitor remediation activities and support closure of identified weaknesses.
  • Develop assurance dashboards, metrics and management reporting.
  • Support the ongoing maturity of the security governance framework.
  • Review the impact of regulatory, industry and client requirements on the control environment.
  • Contribute to internal security awareness and governance initiatives.
  • Support external client requests relating to security assurance and certification activities where required.
  • Facilitate identification, assessment and evaluation of security risks.
  • Provide analysis and recommendations to support risk-based decisions.
  • Monitor risk treatment activities and provide challenge where appropriate.
  • Support risk acceptance and exception management processes

Skills

ISO 27001 knowledge
Audit coordination
Risk management
Control effectiveness assessment
Security governance frameworks
Regulatory/commercial obligations
Security reporting to stakeholders
Risk-based decision support
Threats and vulnerability awareness

Education

ISO 27001 Lead Implementer/Auditor, CISSP/CISM/CRISC

Tools

ISO 27001 information security management system

Job description

Legal, Risk and Compliance

Information Security Governance Lead: To lead the firm's information security assurance activities, maintain the firm's information security certifications by coordinate of certification activities, and provide independent assessment of security control effectiveness. To also assist in the firm's information security risk management framework, working with the enterprise risk team.

The role helps ensure that security controls continue to protect the organisation, support client commitments and enable the firm to meet its regulatory and contractual obligations within it's risk tolerance.

London, United Kingdom
Leeds, United Kingdom

Main duties and responsibilities
  • Own and maintain the ISO 27001:2022 Information Security Management System
  • Coordinate internal and external certification audits
  • Manage the lifecycle of policies, standards and supporting documentation
  • Facilitate management reviews and support continual improvement activities
  • Ensure security governance processes remain aligned to business objectives and evolving risk
  • Design and operate a programme of security control testing and assurance activities
  • Assess the effectiveness of administrative, technical and operational controls
  • Produce assurance reports and communicate outcomes to relevant stakeholders
  • Monitor remediation activities and support closure of identified weaknesses
  • Develop assurance dashboards, metrics and management reporting
  • Support the ongoing maturity of the security governance framework
  • Review the impact of regulatory, industry and client requirements on the control environment
  • Contribute to internal security awareness and governance initiatives
  • Support external client requests relating to security assurance and certification activities where required
  • Facilitate identification, assessment and evaluation of security risks
  • Provide analysis and recommendations to support risk-based decisions
  • Monitor risk treatment activities and provide challenge where appropriate
  • Support risk acceptance and exception management processes
About you

Essential:

  • Experience operating or supporting an ISO 27001 Information Security Management System
  • Knowledge of information security control frameworks and assurance methodologies
  • Knowledge of Cyber Essentials Plus
  • Ability to assess the effectiveness of security controls and identify improvement opportunities
  • Experience coordinating audit, certification or assurance activities
  • Ability to translate technical and governance topics into practical business outcomes
  • Experience presenting security findings, recommendations and risk information to stakeholders
  • Experience identifying, assessing and managing information security risks
  • Understanding of information security threats, vulnerabilities and control environments
  • Experience applying risk management principles, frameworks and methodologies
  • Ability to evaluate the potential business impact of security risks and control gaps

Valuable Experience:

  • Internal audit, risk management, compliance, technology assurance or operational resilience experience
  • Knowledge of frameworks such as NIST CSF, CIS Controls, SOC 2 or similar industry standards
  • Experience within regulated or client-facing environments
  • Relevant professional qualifications such as ISO 27001 Lead Implementer, Lead Auditor, CISSP, CISM, CRISC or equivalent
About us

We're a global law firm helping our clients achieve their goals wherever they do business. Our pursuit of innovation has transformed our delivery of legal services. With offices in the Americas, Europe, the Middle East, Africa and Asia Pacific, we deliver exceptional outcomes on cross-border projects, critical transactions and high-stakes disputes.

Agile Working

We recognise that people have responsibilities and interests outside of their career and that as a business, we all benefit from working flexibly. That’s why we are open to discussing with candidates the different ways in which we are able to support requests for agile working arrangements.

Pre-Engagement Screening

In the event that we make an offer to you, and where local legislation permits, we will conduct pre-engagement screening checks that may include but are not limited to your professional and academic qualifications, your eligibility to work in the relevant jurisdiction, any criminal records, your financial stability, and references from previous employers.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information Security Officer
Information Security Officer

Doghouse Recruitment • Amsterdam

On-site
EUR 88,000 - 95,000
Up to 95000 EUR OTE per year
Non-contributory pension
Working from home allowance €2.40 per day
+2
Information Technology Security Specialist
Information Technology Security Specialist

Levy Global • Utrecht

On-site
EUR 70,000 - 110,000
Information Security Officer
Information Security Officer

WestPoint Search • Den Haag

On-site
EUR 70,000 - 100,000
11% Bonus
Flexible office days
Technical Information Security Analyst
Technical Information Security Analyst

PwC International • Amsterdam

Hybrid
EUR 90,000 - 120,000
Annual bonus
Hybrid work
Home office setup
+3
Manager, Firm Security Insights Capability
Manager, Firm Security Insights Capability

McKinsey & Company • Amsterdam

On-site
EUR 120,000 - 180,000
Exceptional benefits
ISO 27001 Security Governance Lead - Assurance & Risk
ISO 27001 Security Governance Lead - Assurance & Risk

DLA Piper • Amsterdam

On-site
EUR 90,000 - 130,000
Information Security Specialist
Information Security Specialist

Independent Recruiters • Amsterdam

On-site
EUR 55,800 - 66,346
13th-month payment
Holiday allowance
30 days of holiday annually
+1
Consultancy Services Data Protection and Data Security Audit
Consultancy Services Data Protection and Data Security Audit

Vector Synergy • Den Haag

On-site
EUR 70,000 - 90,000
Security Services Engagement Partner
Security Services Engagement Partner

Barclay Simpson • Amsterdam

On-site
EUR 90,000 - 130,000
SECURITY & PRIVACY OFFICER
SECURITY & PRIVACY OFFICER

Just Brands - Fashion & Retail • Lijnden

On-site
EUR 90,000 - 130,000
End-of-year bonus
Lunch provided
Gym access
+2