To lead the firm's information security assurance activities, maintain the firm's information security certifications by coordinate of certification activities, and provide independent assessment of security control effectiveness. To also assist in the firm's information security risk management framework, working with the enterprise risk team. The role helps ensure that security controls continue to protect the organisation, support client commitments and enable the firm to meet its regulatory and contractual obligations within it's risk tolerance. Main duties and responsibilitiesOwn and maintain the ISO 27001:2022 Information Security Management SystemCoordinate internal and external certification auditsManage the lifecycle of policies, standards and supporting documentationFacilitate management reviews and support continual improvement activitiesEnsure security governance processes remain aligned to business objectives and evolving riskDesign and operate a programme of security control testing and assurance activitiesAssess the effectiveness of administrative, technical and operational controlsProduce assurance reports and communicate outcomes to relevant stakeholdersMonitor remediation activities and support closure of identified weaknessesDevelop assurance dashboards, metrics and management reportingSupport the ongoing maturity of the security governance frameworkReview the impact of regulatory, industry and client requirements on the control environmentContribute to internal security awareness and governance initiativesSupport external client requests relating to security assurance and certification activities where requiredFacilitate identification, assessment and evaluation of security risksProvide analysis and recommendations to support risk-based decisionsMonitor risk treatment activities and provide challenge where appropriateSupport risk acceptance and exception management processesAbout youEssential: Experience operating or supporting an ISO 27001 Information Security Management SystemKnowledge of information security control frameworks and assurance methodologiesKnowledge of Cyber Essentials PlusAbility to assess the effectiveness of security controls and identify improvement opportunitiesExperience coordinating audit, certification or assurance activitiesAbility to translate technical and governance topics into practical business outcomesExperience presenting security findings, recommendations and risk information to stakeholdersExperience identifying, assessing and managing information security risksUnderstanding of information security threats, vulnerabilities and control environmentsExperience applying risk management principles, frameworks and methodologiesAbility to evaluate the potential business impact of security risks and control gapsValuable Experience: Internal audit, risk management, compliance, technology assurance or operational resilience experienceKnowledge of frameworks such as NIST CSF, CIS Controls, SOC 2 or similar industry standardsExperience within regulated or client-facing environmentsRelevant professional qualifications such as ISO 27001 Lead Implementer, Lead Auditor, CISSP, CISM, CRISC or equivalentAbout usWe're a global law firm helping our clients achieve their goals wherever they do business. Our pursuit of innovation has transformed our delivery of legal services. With offices in the Americas, Europe, the Middle East, Africa and Asia Pacific, we deliver exceptional outcomes on cross-border projects, critical transactions and high-stakes disputes. At DLA Piper, we understand that inclusion is not a one-size-fits-all concept. We embrace and celebrate the range of perspectives, backgrounds and experiences that each individual brings to our firm. By fostering a culture that welcomes and appreciates all aspects of our individuality, we ensure that everyone has the opportunity to succeed. Our commitment to inclusion and positive social impact enables us to provide exceptional service to our clients and communities, while nurturing a unique and inclusive culture for all our people. We welcome the unique contribution that you will bring to our firm and actively encourage applications from all talented people β however your talent is packaged, whatever your background or circumstance and regardless of how you identify. We are committed to being accessible and accommodating any reasonable adjustments needed throughout the recruitment process to ensure an inclusive experience for all. If you need any support or adjustments, please let us know. Where local legislation permits, we will conduct relevant pre-engagement screening checks prior to your first day.
Information Security Policy Governance Lead in London employer: DLA Piper
DLA Piper is an exceptional employer, offering a dynamic and inclusive work culture that fosters collaboration across its global teams. With a strong commitment to employee growth, you will have access to continuous professional development opportunities while working in the vibrant city of London, known for its rich legal landscape and multicultural environment. Join us to make a meaningful impact as you navigate complex legal challenges in a supportive and innovative setting.