At a Glance
- Tasks: Ensure top-notch security by managing audits, incidents, and compliance across global teams.
- Company: Join a leading firm with a strong focus on information security and risk management.
- Benefits: Competitive salary, flexible working options, and opportunities for professional growth.
- Other info: Collaborative environment with a chance to work on innovative security technologies.
- Why this job: Be at the forefront of cybersecurity, protecting vital information and making a real difference.
- Qualifications: Degree in a technical field and experience in information security preferred.
The predicted salary is between 49500 - 60500 Β£ per year.
Overview
An exciting opportunity within the General Counsel & Risk team as part of our global Information Security team.
The individual will work closely with the UK, Australia and US-based teams in the following primary areas of responsibility, focusing on the UK and EMEA offices:
Responsibilities
β’ Providing assurance to external stakeholders, including
- Supporting the maintenance of the Firms ISO 27001 certification, in particular:
- Preparing new and existing business units for certification/audit.
- Collating metrics in support of governance and continual improvement.
- Risk assessing new ways of working, alongside the Risk and IT teams.
- Assessing compliance with client-specific security requirements within the legal teams.
- Managing the ISMS tools, documentation and trackers.
- Supporting internal security audit activities.
- Operational Security Oversight
- Investigate and manage DLP alerts and user behaviour anomalies, escalating as needed.
- Support incident response for phishing, impersonation scams, and other security events.
- Assist with API integration projects to enhance security workflows (e. g., Service Now integrations).
- Security Awareness & Education
- Deliver and monitor phishing simulation campaigns, producing reports and insights.
- Contribute to security communications and awareness programs across the firm.
- Strategic Initiatives
- Participate in onboarding new security technologies such as Data Security Posture Management (DSPM).
- Engage with AI Risk and Governance discussions to support emerging technology adoption.
- Stakeholder Collaboration
- Build strong relationships with IT, Risk, HR, and legal teams to embed security into business processes
- Provide practical security advice to internal stakeholders.
Qualifications / Skills / Experience
- Degree educated (technical degree or similar).
- We would expect the successful candidate to have around three years\' experience in information security but may consider those with less experience providing they can demonstrate they meet the required competencies.
- Strong knowledge of ISO 27001 implementation and certification.
- Power BI analytics and reporting.
- One or more of the following desired - MSc in security or similar; CISSP; CISA/CISM; ISO 27001 Lead Auditor.
- Professional Services experience preferable.
- Adaptable, diligent and works with initiative.
- Strong relationship builder - internal and external.
- Familiarity with security tools and systems would be advantageous (e. g., Email DLP, UEBA, phishing simulation).
- Experience working as part of a global team.
- #J-18808-Ljbffr
Information Security Analyst employer: Herbert Smith Freehills Kramer
Herbert Smith Freehills Kramer is an exceptional employer, offering a dynamic work culture that fosters collaboration and innovation within its London office. Employees benefit from comprehensive professional development opportunities, a commitment to diversity and inclusion, and the chance to engage in meaningful work that addresses complex global challenges in risk management. With a focus on employee well-being and a supportive environment, this role provides a unique opportunity to grow within a leading international law firm.
Contact Details:
Herbert Smith Freehills Kramer Recruitment Team