At a Glance
- Tasks: Lead security initiatives and ensure compliance with ISO 27001 and SOC 2 standards.
- Company: Join a fast-growing LegalTech company making waves in information security.
- Benefits: Competitive salary, equity options, hybrid work, and generous holiday allowance.
- Other info: Dynamic team culture with opportunities for professional growth and development.
- Why this job: Make a real impact on safeguarding sensitive data while shaping IT and security practices.
- Qualifications: Experience in information security, compliance certifications, and strong communication skills.
The predicted salary is between 60000 - 80000 £ per year.
We're looking for a skilled Senior Information Security Officer to join Definely at a pivotal stage of growth. In this role, you'll take ownership of implementing and maintaining our security standards, supporting compliance programs, and promoting secure practices across engineering and business teams. You'll play a key role in ensuring our systems and processes align with ISO 27001 and SOC 2 requirements, contributing to risk assessments, and supporting incident response activities. Working closely with product and engineering teams, you'll help embed security into the design of our Microsoft Word add-ins and AI-driven features. As we scale, you'll also provide IT support across the business, helping to manage devices, onboard new team members, and support day-to-day IT operations to ensure our people can work securely and efficiently. This is an exciting opportunity to have a direct impact on the security posture of a fast-growing LegalTech company, helping safeguard enterprise customers' most sensitive data while also shaping how we scale IT and security together.
What you'll do
- Governance & Compliance
- Own and evolve Definely's Information Security Management System (ISMS).
- Lead ISO 27001 and SOC 2 Type II audits, ensuring controls remain effective.
- Drive readiness for ISO/IEC 42001 AI certification.
- Apply prior experience successfully obtaining ISO and SOC certifications.
- Manage customer due diligence requests and run Definely's SafeBase-powered Trust Center; streamline customer security questionnaires, DPAs, and RFP security sections.
- Product & Engineering Partnership
- Embed secure SDLC practices across product teams, from design to release.
- Perform threat modelling, define non-functional security requirements, and review designs for security impact.
- Guide security considerations in our AI/LLM-enabled products.
- Risk & Incident Management
- Own the company-wide incident response plan and lead tabletop exercises.
- Perform ongoing risk assessments, vendor security reviews, and DPIAs.
- Ensure strong access management, secrets management, and cloud security hygiene.
- IT Support & Operations
- Provide day-to-day IT support for employees, including device management, troubleshooting, and access provisioning.
- Support onboarding and offboarding processes to ensure secure and efficient setup of accounts, devices, and permissions.
- Help scale internal IT processes and tooling as the company grows.
- Enablement & Communication
- Deliver security training and awareness across the company.
- Communicate risks and incidents clearly to technical and non-technical stakeholders.
What you'll bring
- Proven experience in information security within a SaaS or product led environment.
- Strong track record of delivering ISO 27001, SOC 2, or similar certifications, with interest in ISO/IEC 42001 AI standards.
- Experience with compliance tooling such as Drata and working with ISO auditors, ideally in the UK.
- Solid understanding of GDPR and data protection best practices.
- Deep knowledge of secure SDLC, threat modelling, and securing AI and LLM based systems.
- Strong cloud security expertise across Azure or AWS, including access control, secrets management, and incident response.
- Experience running IT operations in a scaling business, including device management, SaaS tooling, and identity systems such as SSO and IAM.
- Excellent communication skills, with the ability to work cross functionally and manage customer security and due diligence processes.
- Relevant certifications such as CISSP, CISM, CCSK, or ISO 27001 Lead Auditor, and a degree in a related field.
What we can offer you
- Competitive salary & annual bonus.
- Equity in Definely.
- Quarterly team socials & holiday parties.
- Hybrid working & 1 month "work from anywhere".
- 25 days holiday.
Senior Information Security Officer in London employer: Definely Ltd.
Contact Detail:
Definely Ltd. Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Senior Information Security Officer in London
✨Tip Number 1
Network like a pro! Reach out to your connections in the industry, attend relevant meetups, and engage with professionals on LinkedIn. We all know that sometimes it's not just what you know, but who you know that can help you land that dream job.
✨Tip Number 2
Prepare for interviews by researching the company and its culture. Understand their products and how they align with your skills, especially in information security. We want you to show them that you're not just a fit for the role, but also for the team!
✨Tip Number 3
Practice your responses to common interview questions, especially those related to security standards like ISO 27001 and SOC 2. We recommend doing mock interviews with friends or using online platforms to boost your confidence before the real deal.
✨Tip Number 4
Don't forget to follow up after your interviews! A simple thank-you email can go a long way in keeping you top of mind. And remember, if you’re interested in this role, apply through our website to make sure your application gets the attention it deserves!
We think you need these skills to ace Senior Information Security Officer in London
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the Senior Information Security Officer role. Highlight your experience with ISO 27001 and SOC 2 certifications, as well as any relevant IT support skills. We want to see how your background aligns with what we're looking for!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about information security and how you can contribute to our team at Definely. Be sure to mention specific projects or experiences that relate to the job description.
Showcase Your Communication Skills: Since you'll be working with both technical and non-technical teams, it's important to demonstrate your communication skills in your application. Use clear and concise language, and maybe even include examples of how you've effectively communicated security risks in the past.
Apply Through Our Website: We encourage you to apply through our website for the best chance of getting noticed. It helps us keep track of applications and ensures you’re considered for the role. Plus, it’s super easy to do!
How to prepare for a job interview at Definely Ltd.
✨Know Your Standards
Make sure you’re well-versed in ISO 27001 and SOC 2 requirements. Brush up on the specifics of these standards and be ready to discuss how you've implemented them in past roles. This will show that you understand the core of what the company needs.
✨Showcase Your Technical Skills
Prepare to talk about your experience with secure SDLC practices, threat modelling, and cloud security, especially if you have hands-on experience with Azure or AWS. Bring examples of how you've embedded security into product design, as this is crucial for the role.
✨Communicate Clearly
Practice explaining complex security concepts in simple terms. You’ll need to communicate risks and incidents to both technical and non-technical stakeholders, so being able to articulate your thoughts clearly will set you apart.
✨Demonstrate Your IT Support Experience
Be ready to discuss your experience in managing IT operations, including device management and onboarding processes. Highlight any specific tools or systems you've used, as this will show your readiness to support the team effectively.