Information Security Analyst

Information Security Analyst

Full-Time 37800 - 46200 £ / year (est.) No working from home possible
H

At a Glance

  • Tasks: Join our Cyber Security team to protect and enhance information security across the firm.
  • Company: Howard Kennedy, a forward-thinking law firm with a collaborative culture.
  • Benefits: Competitive salary, 25 days holiday, private healthcare, and a supportive work environment.
  • Other info: Inclusive recruitment process with opportunities for personal and professional growth.
  • Why this job: Make a real impact in a hands-on role while developing your career in cyber security.
  • Qualifications: Experience in information security and strong analytical skills are essential.

The predicted salary is between 37800 - 46200 £ per year.

The role

We are seeking an Information Security Analyst to join our Cyber Security team.

This is a varied and hands‑on role, offering an excellent opportunity for a motivated security professional to develop their career within a forward thinking professional services environment.

Working across technical security, risk and governance, compliance, and continuous improvement, you will gain broad exposure to all aspects of information security while supporting a business that places technology, security, and client trust at its core.

As part of the Information Security function, you will play a key role in protecting the firm's information, systems, and digital services, helping to ensure legal services are delivered securely, reliably, and in line with regulatory, contractual, and client expectations.

Working closely with IT teams, Partners, lawyers, Business Services colleagues, suppliers, and security partners, you will help identify, assess, and manage risks, while providing practical security guidance that enables secure and productive ways of working.

The role spans security monitoring, incident response, vulnerability management, supplier assurance, compliance, reporting, and security awareness.

You will contribute to the ongoing development of the firm's security capabilities, helping to strengthen controls, improve resilience, and support a strong culture of information security across the business.

  • Role responsibility
  • Protect
  • Operate, review, and improve security controls, risk treatment activity, and security processes within approved policies, standards, and change governance.
  • Assist with identity and access management, including joiners/movers/leavers processes, access review evidence, and approved privileged access activities.
  • Support vulnerability management by coordinating evidence, prioritising remediation by business context and consequence, and tracking issues to closure.
  • Support the implementation and operation of security technologies and upgrades in line with agreed standards.
  • Review technical designs, configurations, and change proposals to identify security risk.
  • Support the definition and implementation of security requirements for new systems and material changes.
  • Work with suppliers and managed service providers to keep operational controls effective.
  • Monitor & Respond
  • Monitor security and threat detection systems, investigate alerts, and identify trends that need a response.
  • Respond to security policy breaches and provide practical guidance on secure working practices.
  • Act as an escalation point for security queries from the Service Desk, IT, and Risk and Compliance teams, including DSAR evidence gathering where appropriate.
  • Support incident response activities including triage, investigation, containment, documentation, remediation tracking, and post-incident review.
  • Support business continuity and disaster recovery activity, helping restore protected services quickly after disruption.
  • Monitor emerging threats and vulnerabilities and recommend appropriate mitigations.
  • Advise
  • Maintain the information security risk register so it reflects current risks, controls, actions, and escalation requirements.
  • Support audits, client due diligence, ISO 27001 assurance, and governance reporting through evidence collation, metrics, and action tracking.
  • Support third-party risk management, including onboarding, questionnaires, contract evidence, and ongoing supplier assurance.
  • Work with the Data Protection Officer on data protection incidents and assessments in line with UK GDPR, the Data Protection Act 2018, and SRA expectations where applicable.
  • Produce clear reports for technical and non-technical stakeholders.
  • Assist with the creation and delivery of cyber security awareness and training for colleagues.

About you

  • Ideally you will be able to demonstrate;
  • Experience in an information or cyber security role covering protection, monitoring, response, and advisory work; law firm or professional services experience is desirable.
  • Comfort and experience operating with real autonomy and ownership, ideally within a small or lean security team rather than a large structure.
  • Broad technical knowledge across networking, systems administration, infrastructure, applications, and security, with the ability to challenge designs and identify real risk.
  • Hands‑on experience with common security technologies and controls (e. g. endpoint protection, email/web security, firewalls, IDS/IPS).
  • Good working knowledge of Microsoft platforms and security capabilities.
  • Sound understanding of information risk, with the ability to assess conditions and consequences rather than rely solely on generic severity ratings.
  • Knowledge of relevant standards, good practice, and regulatory requirements, including UK GDPR and the Data Protection Act 2018.
  • Strong analytical skills with the ability to translate business requirements into proportionate security controls.
  • Excellent written and verbal communication skills, with the ability to engage both technical and non-technical stakeholders.
  • Organised, methodical, and accurate approach, with strong attention to detail and a willingness to learn and develop.
  • High levels of integrity and discretion when handling sensitive information.
  • Pragmatic, business‑focused mindset with the ability to balance risk and usability.
  • Curiosity and pro‑activity, with a continuous improvement mindset and willingness to challenge assumptions constructively.
  • A collaborative and service‑oriented approach, with an understanding of the pressures of a legal services environment.
  • The ability to work calmly and methodically particularly when managing incidents or competing priorities.

At Howard Kennedy we believe that everyone deserves the space to thrive.

We're committed to creating an inclusive recruitment experience that reflects the diversity of both our people and our clients.

We are proud to be an equal opportunities employer.

We welcome applications from individuals of all backgrounds and identities, and we're committed to ensuring that our recruitment process is fair, transparent, and accessible to all.

We understand that every candidate's needs are different If there's anything we can do to make your application journey more comfortable- whether for interviews, assessments, or onboarding-please let us know.

We'll work with you to remove any barriers and ensure our recruitment process is comfortable for you.

Contact our recruitment team at to discuss any support you might need.

Agency Introductions

Please note that we are not accepting applications via agencies for this role at this time.

Before sharing any named candidate CVs, please contact your recruitment representative.

If any named CVs are sent from agencies without approval from our recruitment team, they will not be deemed valid introductions, and no agency fee will be paid.

Benefits

  • Competitive salary
  • 25 days annual holiday
  • Permanent Health Insurance
  • Life Assurance
  • Interest free Season Ticket Loan
  • Private Healthcare
  • Pension Scheme
  • Staff Introductory Scheme
  • Employee Assistance Programme

About us

With almost 200 lawyers in one location, we ensure our clients have the right team to help them get from where they are to where they want to be.

We advise major corporates and institutions as well as entrepreneurial, ambitious enterprises which are often privately or family owned, or private equity backed.

As well as our significant business law capability, we are one of only a few London-based law firms with a large private wealth offering.

Our clients find our straightforward approach a compelling alternative to larger, less personal firms.

Whether you are an ambitious and talented individual wanting to hit the ground running from day one, or an established professional looking for a new opportunity, Howard Kennedy is the firm where you can really make it happen.

We have earned a strong reputation for our exceptional and uniquely talented people who between them deliver outstanding results for clients.

In a firm of our size, our strong team dynamic creates a thriving culture of creativity and entrepreneurialism.

Howard Kennedy is a pragmatic and non-hierarchical environment where success is shared, and you are proactively encouraged to thrive at your own pace.

Our distinctive culture is built on fairness and respect.

Guided by the firm's values of talk straight, think smart and be yourself, everyone in the firm holds equal value, and everyone plays their role in supporting, encouraging and inspiring colleagues to do their best work.

At the same time, we recognise and reward individualism, celebrating the diversity of our people and supporting them to grow their practice and drive their own career advancement.

As well as client work, there is opportunity to broaden your horizons at the firm with fulfilling pro bono and charity projects.

We have a regular social calendar full of wellbeing activities, charitable and social events too.

#J-18808-Ljbffr

Information Security Analyst employer: Howard Kennedy

At Howard Kennedy, we pride ourselves on being an exceptional employer that fosters a collaborative and inclusive work culture. As an Information Security Analyst, you will benefit from a competitive salary, generous annual leave, and comprehensive health insurance, all while working in a dynamic environment that encourages professional growth and development. Our commitment to diversity and employee well-being, combined with our focus on innovation and client trust, makes us a rewarding place to advance your career in the heart of London.

H

Contact Details:

Howard Kennedy Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Information Security Analyst

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Howard Kennedy, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through Howard Kennedy

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Howard Kennedy. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Information Security Analyst

Information Security
Risk Management
Compliance
Incident Response
Vulnerability Management
Security Monitoring
Data Protection

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Howard Kennedy insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Howard Kennedy that you’re committed to staying ahead in the game.

How to prepare for a job interview at Howard Kennedy

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at Howard Kennedy to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Howard Kennedy.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.