Information Security Governance Manager in Birmingham
Information Security Governance Manager

Information Security Governance Manager in Birmingham

Birmingham Full-Time 36000 - 60000 £ / year (est.) No home office possible
DLA Piper

At a Glance

  • Tasks: Lead security governance, risk, and compliance activities in a dynamic legal environment.
  • Company: Join a global law firm known for innovation and exceptional service.
  • Benefits: Inclusive culture, career growth opportunities, and support for diverse backgrounds.
  • Why this job: Make a real impact on security practices while collaborating with talented teams.
  • Qualifications: Experience in security standards and team management; strong relationship-building skills.
  • Other info: Flexible work environment with a commitment to accessibility and inclusion.

The predicted salary is between 36000 - 60000 £ per year.

Manage the security governance, risk and compliance activities within the Information Security Team. Work with wider governance functions to support the implementation and validation of security controls. Ensure that all obligations and certifications are met and that clients receive assurance regarding the security of the data that the firm holds for them. This role acts as a governance interface between teams within Information Security, Office of General Counsel, Risk & Resilience, and wider business functions through building relationships and assisting other teams in improving their security controls and the firm's security posture. Develop and improve the team's capabilities in response to changes in technology and business practices whilst keeping up to date with the latest security trends and capabilities.

Main Duties and Responsibilities

  • Management: Management responsibility for a team of 4 people who deliver assurance of the firm's security controls, respond to client security queries and audits, input into client terms of business, and identify security risks. Responsible for ensuring that all processes and capabilities are scalable to meet the needs of the business and the demands of its clients.
  • Governance, Control Assurance and Compliance: Maintain and evolve the information security policy suite, standards, baselines, and control library. Ownership of internal security compliance practices and controls within DLA Piper International, including ISO27001:2022, Cyber Essentials +, DISP, and other government mandated control frameworks. Ensure all certifications are completed successfully each year or audit period; lead on security risk management processes, ensuring they are integrated with wider enterprise risk management capabilities including KRIs. Provide clear security risk narratives and options to senior stakeholders. Design and run the control assurance programme (testing, monitoring, evidence collection). Coordinate internal/external audits (ISO 27001, Cyber Essentials +, DISP) and manage findings to closure. Track and report compliance posture, control coverage, and remediation progress. Accountable for external client audits and pitch responses, ensuring compliance with any security-related legislation or client requirements. Ensure that the firm's security controls are documented and integrated into the Information Security Management System and control framework. Define and publish security KPIs/KRIs, maturity metrics, and board-ready reporting. Ensure lessons learned from incidents feed into controls, policy, and security training. Ensure the team is focused on continual improvement in all its processes and that the needs of the business are being met in a timely manner.

About you: While not an in-depth technical role, it does require the ability to work with both technical and non-technical teams in the context of security. The role works closely with Security Architecture and Security Operations teams and has access to their expertise. Understanding of professional services organisations and the legal sector. Extensive experience of security standards and certifications including ISO 27001, Cyber Essentials, NIST CSF, and DISP. Experience of managing teams to ensure requirements are delivered on time. Ability to handle multiple priorities, working to sometimes conflicting timescales in a fast-paced and challenging environment. Ability to build trust and rapport to develop effective relationships, internally and externally. Pragmatic approach to responding to requirements and expectations from the wider business. Significant experience of managing security governance and compliance activities in a professional services organisation or other multinational business. Thorough understanding of risk management concepts and processes. Recent experience of cloud technologies and organisations making use of SaaS, PaaS, and IaaS services. Knowledge of business continuity standards, physical security, and wider operational risks are useful. Qualifications and certifications in information security, risk management, and audit are desirable such as 27001 Lead Implementer/Auditor, CISM, CISA, CRISC, or CISSP.

About us: We are a global law firm helping our clients achieve their goals wherever they do business. Our pursuit of innovation has transformed our delivery of legal services. With offices in the Americas, Europe, the Middle East, Africa, and Asia Pacific, we deliver exceptional outcomes on cross-border projects, critical transactions, and high-stakes disputes. At DLA Piper, we understand that inclusion is not a one-size-fits-all concept. We embrace and celebrate the range of perspectives, backgrounds, and experiences that each individual brings to our firm. By fostering a culture that welcomes and appreciates all aspects of our individuality, we ensure that everyone has the opportunity to succeed. Our commitment to inclusion and positive social impact enables us to provide exceptional service to our clients and communities while nurturing a unique and inclusive culture for all our people. We welcome the unique contribution that you will bring to our firm and actively encourage applications from all talented people - however your talent is packaged, whatever your background or circumstance, and regardless of how you identify. We are committed to being accessible and accommodating any reasonable adjustments needed throughout the recruitment process to ensure an inclusive experience for all. If you need any support or adjustments, please let us know. Where local legislation permits, we will conduct relevant pre-engagement screening checks prior to your first day.

Information Security Governance Manager in Birmingham employer: DLA Piper

DLA Piper is an exceptional employer that prioritises innovation and inclusion, making it a fantastic place for professionals in the Information Security field. With a strong commitment to employee growth, we offer opportunities for continuous learning and development within a supportive team environment. Our global presence and diverse culture ensure that every individual can thrive and contribute meaningfully to our mission of delivering outstanding legal services.
DLA Piper

Contact Detail:

DLA Piper Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Information Security Governance Manager in Birmingham

✨Tip Number 1

Network like a pro! Reach out to folks in the industry, attend events, and connect with people on LinkedIn. Building relationships can open doors that a CV just can't.

✨Tip Number 2

Prepare for interviews by researching the company and its security practices. Show them you know your stuff about ISO 27001 and Cyber Essentials – it’ll impress them!

✨Tip Number 3

Practice your responses to common interview questions, especially around risk management and compliance. We want you to sound confident and knowledgeable when discussing your experience.

✨Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, we love seeing candidates who are proactive!

We think you need these skills to ace Information Security Governance Manager in Birmingham

Security Governance
Risk Management
Compliance Management
ISO 27001
Cyber Essentials
NIST CSF
DISP
Team Management
Stakeholder Engagement
Control Assurance
Audit Coordination
Cloud Technologies
SaaS, PaaS, IaaS
Business Continuity Standards
Information Security Policy Development

Some tips for your application 🫡

Tailor Your Application: Make sure to customise your CV and cover letter to highlight your experience with security governance, risk management, and compliance. We want to see how your skills align with the specific requirements of the Information Security Governance Manager role.

Showcase Your Team Management Skills: Since this role involves managing a team, don’t forget to mention your leadership experience. Share examples of how you've successfully led teams in the past, especially in delivering security assurance and handling client queries.

Highlight Relevant Certifications: If you have any qualifications like ISO 27001 Lead Implementer or CISM, make sure they’re front and centre in your application. We love seeing candidates who are committed to their professional development in information security.

Apply Through Our Website: We encourage you to submit your application through our website. It’s the best way for us to receive your details and ensures you’re considered for the role. Plus, it shows you’re keen on joining our team!

How to prepare for a job interview at DLA Piper

✨Know Your Security Standards

Make sure you brush up on key security standards like ISO 27001, Cyber Essentials, and DISP. Be ready to discuss how you've applied these in your previous roles, as this will show your understanding of the compliance landscape.

✨Showcase Your Team Management Skills

Since this role involves managing a team, prepare examples of how you've successfully led teams in the past. Highlight your ability to handle multiple priorities and deliver results under pressure, as this is crucial in a fast-paced environment.

✨Build Relationships

Demonstrate your ability to build trust and rapport with both technical and non-technical teams. Share specific instances where you've collaborated effectively across departments, as this will be key in acting as a governance interface.

✨Stay Updated on Trends

Keep yourself informed about the latest trends in information security and risk management. Being able to discuss recent developments or changes in technology will show that you're proactive and committed to continual improvement.

Information Security Governance Manager in Birmingham
DLA Piper
Location: Birmingham

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

>