Information Security Manager (12 month fixed-term maternity cover) in London

Information Security Manager (12 month fixed-term maternity cover) in London

London Temporary 56700 - 69300 £ / year (est.) Home office (partial)
L

At a Glance

  • Tasks: Lead information security strategy and ensure compliance at a top LegalTech scale-up.
  • Company: Join Legatics, a leading company in legal transaction management.
  • Benefits: Enjoy 25 days holiday, private medical insurance, and early finish Fridays!
  • Other info: Dynamic work environment with opportunities for professional growth.
  • Why this job: Make a real impact on security for high-profile clients and innovative products.
  • Qualifications: Experience in information security and strong communication skills required.

The predicted salary is between 56700 - 69300 £ per year.

Legatics handles some of the world’s most complex and confidential legal transactions, so information security is core to the product and to client trust. The Information Security Manager owns information security across Legatics — setting the vision and strategy, maintaining our ISO 27001 certified ISMS, working hand-in-hand with engineering to embed security into our client-facing products, and acting as the security point of contact for our clients and business teams.

Reporting to the Head of Engineering, the role spans technical security, compliance and governance, client assurance, and the day-to-day operation of our security and IT tooling. It is a broad, hands-on role with a high degree of autonomy to shape direction as Legatics scales. This is a fixed-term appointment covering a period of maternity leave. The expected duration is approximately 12 months from the start date, although the actual end date will depend on the return date of the current postholder and may fall slightly earlier or later.

You will have full ownership of the remit set out below for the duration of the contract, with the same autonomy, access and support as a permanent member of the team.

About Legatics: Legatics is one of the world’s leading LegalTech scale-ups. Our legal transaction management platform enables law firms and their clients to collaborate on and close deals in an interactive online environment, providing clarity, reducing risk and saving time. Our customers include some of the world’s top law firms, such as Allen & Overy, Shearman, Hogan Lovells, Herbert Smith Freehills, and King & Wood Mallesons. We’ve been used on transactions in more than 60 countries on transactions worth over $1 trillion.

This role is offered on a fixed-term basis to provide cover during a colleague's maternity leave, with an anticipated duration of around 12 months.

  • You will be employed on the same terms and benefits as our permanent employees, including private medical insurance, health cash plan and pension.
  • The contract may be extended if the period of cover changes, and we will always give you as much notice as we can of the confirmed end date.
  • Where a suitable permanent role exists at the end of the contract, we will discuss it with you.
  • Fixed-term does not mean holding the fort. We are looking for someone who will genuinely own and advance our security posture during their time here, and we expect the work you do to outlast the contract.

Key responsibilities:

  • Security strategy, posture and governance: Own the vision, direction and roadmap for information security at Legatics, and continue developing the overall security posture, processes, systems and controls. Maintain up-to-date knowledge of the threat landscape, emerging best practice and tooling, and translate this into Legatics’ security priorities. Develop and run a strategy for continuous security and resilience testing — for example penetration testing, red-team exercises and threat modelling. Build relationships with relevant industry bodies and security peers at similar organisations.
  • ISO 27001 and compliance (ISMS ownership): Own ISO 27001 certification and the Information Security Management System (ISMS), including ongoing maintenance and continuous audit readiness; align the ISMS to ISO 27001:2022. Maintain the Master Document List, version control and approvals across all policies, and keep ISO documentation tracked in a central system. Finalise and maintain the Statement of Applicability (SoA), and keep the ISMS Manual current. Review and maintain core policies and keep the ISMS Risk Register up to date. Document and operate the threat intelligence process; maintain the Interested Parties register and the analysis of internal/external issues. Produce and maintain the ISMS Communication Plan and associated tracking. Run periodic user access reviews across Google Workspace and SaaS platforms. Collect, organise and maintain audit evidence.
  • Client security assurance: Complete client information security questionnaires and respond to customer security queries. Provide client-facing security remediation updates and discuss Legatics’ security posture directly with clients and prospects. Attend client meetings, remotely or on-site, as required. Build and improve tooling to speed up and standardise questionnaire responses.
  • Application and product security: Conduct technical risk assessments on product features, assess compliance risk for legal-sector clients, and advocate for server-side enforcement of access controls. Perform vulnerability and exploitability analysis, and prioritise remediation based on real exposure. Review the security risk of proposed integrations and data flows, and maintain the vendor risk register.
  • Cloud, identity and endpoint security: Audit and harden cloud and identity posture across Google Workspace and Microsoft Entra ID. Resolve identity and email-security issues. Own endpoint security across approximately 50 Windows and Mac endpoints.
  • Security monitoring and detection: Develop, extend and maintain security monitoring, reporting and tracking tools covering the full technical estate. Tune monitoring rules and alert configurations to improve signal quality and reduce false positives.
  • Incident response: Lead detection, triage, containment and response for security incidents. Draft and issue incident communications tailored to both technical and non-technical audiences.
  • AI security and governance: Set Legatics’ AI security posture, positioning security as an enabler for teams building with autonomous AI tools. Implement access controls, security architecture and detection rules for internal AI systems. Research AI coding risks and feed findings into engineering practice.
  • IT operations and tooling support: Handle day-to-day IT support across the team. Administer Claude Team connectors and support internal data tooling.

What we need from you:

The ideal candidate will have a mix of technical, compliance and communication skills. You do not need every item below — if you have strong foundations and are keen to learn the rest, we’d like to hear from you.

  • Experience in an information security or cyber-security role.
  • Strong knowledge of fundamental internet technologies, Linux systems, cloud infrastructure and networking.
  • Experience with SIEM, log and traffic analysis, monitoring, reporting and auditing approaches.
  • Hands-on experience managing an ISMS and ISO 27001 compliance.
  • Confident completing client information security questionnaires and discussing security posture directly with customers.
  • Familiarity with cloud and identity platforms and endpoint/EDR tooling.
  • Application security and vulnerability triage, and vendor / third-party risk assessment.
  • An interest in, or experience of, AI and agentic security risks.
  • Solid communication skills, able to work with and influence both technical and non-technical stakeholders.
  • Experience in a startup or scale-up environment is beneficial.
  • A right to work in the UK.
  • An ability to work from our London office at least twice a week.

What we offer you:

  • 25 days holiday per year (plus public holidays).
  • Early Finish Fridays - on the last Friday of every month, we finish around lunchtime!
  • Pension with NEST.
  • Private Medical Insurance with Bupa.
  • Healthshield Health Cash Plan.
  • Personal Learning & Development budget.
  • Access to Mental healthcare for you and your immediate family.
  • Enhanced parental leave policies.
  • Lots of opportunities for accelerated professional development and career progression.
  • A warm, genuinely collaborative culture and an awesome team.

We put users at the heart of our design to provide legal transaction experiences that everyone loves. In order to make that a reality, we seek to foster a diverse and inclusive working environment that can empower our people to be creative, effective and innovative. We don’t discriminate against gender, race, religion or belief, disability, age, marital status or sexual orientation. Whatever your background may be, we welcome anyone with talent, drive and emotional intelligence. We're committed to building a diverse team and are constantly looking for ways to improve our processes to help us do that.

Information Security Manager (12 month fixed-term maternity cover) in London employer: Legatics

Legatics is an exceptional employer, offering a dynamic work environment in the heart of London where innovation meets collaboration. As an Information Security Manager, you will enjoy a high degree of autonomy while contributing to a leading LegalTech scale-up, with access to comprehensive benefits including private medical insurance, a personal learning budget, and enhanced parental leave policies. The company fosters a warm, inclusive culture that prioritises employee growth and development, making it an ideal place for those seeking meaningful and rewarding employment.

L

Contact Details:

Legatics Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Information Security Manager (12 month fixed-term maternity cover) in London

Get Engaged in Cybersecurity Communities

Dive into online forums or local meetups, like OWASP events or Cybersecurity conferences. These spaces are packed with pros who can share insights and might even know about temporary roles at places like Legatics.

Showcase Your Skills Publicly

Link your GitHub or create a series of blogs sharing your knowledge on cybersecurity topics. It’s a great way to demonstrate your expertise and attract attention from hiring managers, especially when they see your passion in action.

Stay On Top of Temp Opportunities

Keep an eye on platforms that list temporary positions specifically in tech. Websites focusing on contract roles in cybersecurity can lead straight to employers like Legatics.

Make Contact with Recruiters Specialising in Cybersecurity

Reach out to recruitment agencies that focus on cybersecurity roles. They often have insights into temporary roles before they’re advertised and can put your name forward to companies like Legatics.

We think you need these skills to ace Information Security Manager (12 month fixed-term maternity cover) in London

Information Security Management
ISO 27001 Compliance
Technical Risk Assessment
Vulnerability Analysis
Cloud Security
Identity and Access Management
Incident Response

Some tips for your application 🫡

Show Off Your Technical Skills:In cybersecurity, it's vital to highlight your skills with relevant tools and technologies. Make sure your CV showcases your experience with firewalls, intrusion detection systems, and any cybersecurity frameworks you've worked with. This gives Legatics a clear view of your capabilities right off the bat.

Certifications Matter:If you’ve got any cybersecurity certifications, like CompTIA Security+ or CISSP, flaunt them! These not only validate your skills but also show that you’re committed to the field. Add a section to your CV specifically for this, because in a temporary role like this, those credentials can really set you apart.

Tailor Your Cover Letter to the Role:For a temporary position, we want to see your willingness to learn and adapt quickly. Make your cover letter specific to the role at Legatics; mention why you’re excited about the opportunity and how it fits your career goals. A personal touch can make a big difference!

Don’t Forget the Soft Skills:In cybersecurity, technical skills are crucial, but so are soft skills like teamwork and communication. Make sure to weave examples of how you've collaborated with teams or communicated complex ideas into your application. This shows that you're not just a tech whizz but also a great team player, perfect for a temporary role at Legatics.

How to prepare for a job interview at Legatics

Brush Up on Technical Skills

Make sure you’re familiar with the latest cybersecurity tools and techniques, like firewalls, intrusion detection systems, and malware analysis. During the interview with Legatics for the Information Security Manager (12 month fixed-term maternity cover), be prepared to discuss specific scenarios where you tackled security threats or vulnerabilities.

Show Your Problem-Solving Prowess

Cybersecurity is all about thinking on your feet. Expect technical questions that require you to demonstrate your problem-solving abilities. You might be presented with a mock security breach scenario, so practising your responses to potential threats can be a game changer!

Demonstrate Your Adaptability

As this is a temporary role, showing that you're adaptable and quick to learn is crucial. Talk about times you've picked up new skills or reacted to changing situations quickly. Employers want to know you can hit the ground running and keep things secure during your short stay at Legatics.

Bring Relevant Certifications

If you have any relevant cybersecurity certifications, like CompTIA Security+ or CEH, be sure to mention them. This can really help you stand out during a temporary hiring process, as it showcases your commitment to the field and your readiness to take on the Information Security Manager (12 month fixed-term maternity cover) role at Legatics.