At a Glance
- Tasks: Lead security compliance audits and manage ISO 27001 ISMS for a global law firm.
- Company: Join Hogan Lovells, a top international law firm with a collaborative culture.
- Benefits: Flexible working hours, hybrid work options, and a supportive team environment.
- Why this job: Make a real impact in security compliance while working with diverse clients globally.
- Qualifications: ISO 27001 experience and strong communication skills required.
- Other info: Opportunity for international travel and career growth in a dynamic environment.
The predicted salary is between 48000 - 72000 £ per year.
Keen to become part of a truly global, collaborative team of professionals? Your journey begins here.
Department Information Security
Office Location: London
Reports To: Head of Information Risk
Working Hours: 35 hours per week, 9:30am to 5:30pm but additional hours may be required. We are happy to consider agile and flexible working patterns. Our approach to hybrid working allows for up to 40% of time working from home and 60% working in the office.
Firm Description: Hogan Lovells is one of the leading global law firms. Our distinctive market position is founded on our exceptional breadth of our practice, on deep industry knowledge, and on our 'one team' global approach. Formed through the combination of two top international law firms, Hogan Lovells has over 40 offices in the Americas, Asia-Pacific, Europe, the Middle East and Africa. With a presence in the world’s major financial and commercial markets, we are well placed to provide excellent business-oriented advice to our clients locally and internationally. Our people are the key to our success, which is why we seek to recruit and retain the most talented individuals in all regions of our global practice.
Department Description: The department is responsible for the use of Information Technology, computer systems and electronic communications throughout the firm and where appropriate to its clients.
Role Overview: Hogan Lovells is seeking an experienced Security Compliance Manager who will be responsible for coordinating and responding to external and internal security and compliance audit activities while managing the firm’s ISO 27001 ISMS. They will represent the firm’s security program to clients, manage ISO 27001 audits, and will also be responsible for managing security assessments and audits of key partners.
Key Responsibilities / Accountabilities:
- Serve as the primary liaison between the firm and its clients for IT and security-centric inquiries.
- Maintain the firm’s ISO 27001 ISMS and associated deliverables.
- Coordinate and maintain internal and external security assessment schedule.
- Manage security assessments, as required by the firm’s clients and certification agencies.
- Manage security and compliance deliverables across multiple teams.
- Collaborate with internal and external stakeholders on controls and gap remediation.
- Maintain appropriate documentation and records in order to meet compliance requirements.
- Clearly explain our Security and Compliance program to clients and other third parties.
- Provide responses to customer security questionnaires and RFPs detailing firm capabilities.
- Develop recommendations to correct control deficiencies and provide ideas for process improvements.
- International travel may be required.
Specific duties or responsibilities may be reviewed from time to time to reflect changes in personnel and management structure, staff location or services. All members of the firm participate in our Responsible Business program.
Person Specification:
- ISO 27001 Lead Auditor and / or extensive experience in working with ISO 27001 and related standards.
- Working knowledge of ISO 27001 and Cyber Essentials Plus requirements and controls.
- 5+ years of IT and Security audits or assessments, or related experience.
- Conceptual understanding of security best practices and solutions.
- Possess a sufficient understanding of technical concepts including systems, networks and security architecture best practices in order to effectively evaluate risk and assess the effectiveness of controls.
- Knowledge of industry compliance standards, including ISO27001.
- Demonstrated written and oral communication skills and ability to communicate with all levels of management.
- Ability to interact effectively with, and influence, internal and external customers.
- Keen attention to detail and accuracy in order to analyse and finalise documents.
- Ability to build relationships and work cross-functionally with internal and external constituents.
- Broad knowledge of risk management, vulnerability management, and third party risk.
- Familiarity with control design, execution and monitoring, policies and procedures.
Agile Working Statement: Our goal is to embed flexibility across our business by giving everyone the opportunity to work in an agile way, whether as a regular pattern or on an ad hoc basis, and we will be happy to discuss this further.
Equal Opportunities Employment Statement: It is the policy of Hogan Lovells to provide equal opportunities for all employees in relation to recruitment, training and promotion. Decisions in these areas will be made only by reference to the requirements of the job and shall not be influenced by any consideration of racial or ethnic origin, religion, sex, gender and gender identity, age, sexual orientation, marital and civil partnership status, pregnancy or disability.
All vacancies are open to direct applicants. Recruitment agencies; please be advised that we have a preferred supplier list in place for all roles.
Security Compliance Manager employer: Hogan Lovells
Contact Detail:
Hogan Lovells Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Security Compliance Manager
✨Tip Number 1
Network like a pro! Reach out to your connections in the industry, attend relevant events, and engage with professionals on platforms like LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Tip Number 2
Prepare for interviews by researching the company and its culture. Understand their security compliance needs and be ready to discuss how your experience aligns with their goals. Tailor your responses to show that you’re not just a fit for the role, but also for the team.
✨Tip Number 3
Practice makes perfect! Conduct mock interviews with friends or mentors to refine your answers and boost your confidence. Focus on articulating your experience with ISO 27001 and how you've tackled security challenges in the past.
✨Tip Number 4
Don’t forget to follow up after interviews! A simple thank-you email can leave a lasting impression. Use this opportunity to reiterate your enthusiasm for the role and highlight any key points from your conversation that showcase your fit for the position.
We think you need these skills to ace Security Compliance Manager
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the Security Compliance Manager role. Highlight your experience with ISO 27001 and any relevant audits or assessments you've managed. We want to see how your skills align with what we're looking for!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about security compliance and how your background makes you a great fit for our team. Keep it engaging and personal – we love to see your personality come through.
Showcase Your Communication Skills: Since this role involves liaising with clients and stakeholders, make sure to demonstrate your written communication skills in your application. Clear, concise language will show us that you can effectively convey complex information – a key part of the job!
Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way to ensure your application gets to us quickly and efficiently. Plus, you’ll find all the details you need about the role and our company culture there!
How to prepare for a job interview at Hogan Lovells
✨Know Your ISO 27001 Inside Out
Make sure you have a solid understanding of ISO 27001 and its requirements. Be prepared to discuss how you've applied these standards in your previous roles, especially in managing security assessments and audits.
✨Showcase Your Communication Skills
As a Security Compliance Manager, you'll need to liaise with various stakeholders. Practice explaining complex security concepts in simple terms, as well as how you’ve effectively communicated with clients and teams in the past.
✨Prepare for Scenario-Based Questions
Expect questions that ask how you would handle specific security compliance scenarios. Think about past experiences where you identified control deficiencies or managed security assessments, and be ready to share those examples.
✨Demonstrate Your Attention to Detail
Highlight your keen attention to detail by discussing how you maintain documentation and records for compliance. Bring examples of how your meticulous nature has helped improve processes or meet compliance requirements in your previous roles.