At a Glance
- Tasks: Join our team to enhance IT security and resilience through hands-on testing and documentation.
- Company: Be part of a leading firm in London, dedicated to innovative technology solutions.
- Benefits: Enjoy a hybrid work model, competitive salary, and opportunities for professional growth.
- Why this job: Make a real impact on cybersecurity while collaborating with diverse teams in a dynamic environment.
- Qualifications: Hands-on experience in disaster recovery and knowledge of security frameworks are essential.
- Other info: We celebrate diversity and encourage applications from all backgrounds.
The predicted salary is between 48000 - 72000 £ per year.
Job Description
ROLE OVERVIEW //
We are recruiting for an experienced IT Security and Resilience Specialist to join the IT Infrastructure Engineering Team. Which is part of the Technology Department, and the wider Business Services function based at the firm’s head office in London. This is a hybrid role that is both hands-on and process-focused, ensuring that our disaster recovery (DR), failover, and operational resilience capabilities are effective, tested, annually reviewed and continually improved.
The Security & Resilience Specialist will plan and execute DR and resilience testing, drive remediation activities through to closure, and ensure that evidence and documentation meet client, regulatory, and audit standards. This is not a purely administrative role; the successful candidate will work directly with infrastructure and security teams to fix issues as well as document them.
KEY RESPONSIBILITIES //
The key responsibilities of this role are set out below and there may be others which are not listed. You may be required on occasion to work outside our normal working hours of 9:30am to 5:30pm.
Cyber Security & Engineering
- Constantly review and improve the firm’s security posture and external security rating.
- Identify vulnerabilities in hardware and software to be remediated by Engineering\\Operations teams.
- Understand current and emerging security threats.
- Assist and lead in Incident Response investigations and mitigation.
- Evaluate, test and recommend security enhancements.
- Support CE+ accreditation
- Identify security risks and exposures, determine the cause of security violations and suggest procedures to halt future incidents.
- Perform targeted regular and ad-hoc scans to identify potential breaches of the firm data and security and data protection policies
- Identify, analyse, monitor and minimise areas of risk that pertain to Information technology.
Resilience
- Plan and run DR, failover, and resilience tests end-to-end, including test design, leading its orchestration and execution, evidence capture, and reporting.
- Validate Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs) through realistic testing.
- Ensure DR runbooks, procedures, and evidence packs are accurate, up-to-date, and practical.
- Working with Engineers to automate recovery testing and evidence collection where feasible (e.g. scripting, orchestration tools).
- Act as the primary technical liaison with the Business Continuity Planning (BCP) team, providing input into BIAs and ensuring Infrastructure can meet resilience obligations.
- Maintain a central log of resilience activities, including issues, actions, and progress against remediation targets.
- Produce clear updates and dashboards for senior stakeholders.
- Delivery-focused: equally comfortable running a failover test as updating\\reviewing runbooks.
- Structured and organised with strong attention to detail.
- Able to work independently while interfacing effectively with Cyber Security, BCP, and Infrastructure teams.
- Excellent communicator who can translate technical findings into clear business impact.
CANDIDATE PROFILE //
Candidates for this position must have:
- Hands-on experience with disaster recovery, failover testing, and operational resilience in IT infrastructure.
- Solid understanding of business continuity and security frameworks (e.g. ISO27001, ISO23001 NIST) and how to evidence controls.
- Experience producing and maintaining high-quality technical documentation and runbooks.
- Strong coordination skills with cross-functional teams.
- Proficiency with infrastructure tooling and at least one scripting language (PowerShell or Python preferred).
- Experience and understanding of hyperconverged infrastructure preferably with Nutanix, VMWare, Commvault and hybrid cloud infrastructure (Azure or similar).
- Knowledge of vulnerability management, monitoring/alerting, and automation/orchestration platforms.
- Certifications such as Microsoft SC-200, Certified Ethical Hacker and CBCP or CBCI equivalent DR/resilience credentials.
We welcome applications irrespective of race, colour, ethnic or national origin, disability, sex, gender identity, sexual orientation, age, religion, belief or marital status.
IT Security and Resilience Specialist employer: Slaughter and May
Contact Detail:
Slaughter and May Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land IT Security and Resilience Specialist
✨Tip Number 1
Familiarise yourself with the specific security frameworks mentioned in the job description, such as ISO27001 and NIST. Being able to discuss these frameworks and how they apply to disaster recovery and operational resilience will show your expertise during interviews.
✨Tip Number 2
Highlight any hands-on experience you have with disaster recovery and failover testing. Be prepared to share specific examples of tests you've conducted, the challenges faced, and how you overcame them, as this will demonstrate your practical knowledge.
✨Tip Number 3
Brush up on your scripting skills, particularly in PowerShell or Python. If you can showcase a project where you've automated recovery testing or evidence collection, it will set you apart from other candidates.
✨Tip Number 4
Prepare to discuss your coordination skills with cross-functional teams. Think of examples where you've successfully collaborated with Cyber Security, BCP, or Infrastructure teams, as this role requires strong communication and teamwork.
We think you need these skills to ace IT Security and Resilience Specialist
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights relevant experience in IT security, disaster recovery, and operational resilience. Use keywords from the job description to demonstrate that you meet the specific requirements of the role.
Craft a Strong Cover Letter: Write a cover letter that showcases your hands-on experience with disaster recovery and failover testing. Explain how your skills align with the responsibilities outlined in the job description and express your enthusiasm for the role.
Highlight Relevant Certifications: If you have certifications such as Microsoft SC-200 or Certified Ethical Hacker, make sure to mention them prominently in your application. These credentials can set you apart from other candidates.
Showcase Communication Skills: Since the role requires excellent communication skills, provide examples in your application of how you've effectively communicated technical findings to non-technical stakeholders in previous roles.
How to prepare for a job interview at Slaughter and May
✨Showcase Your Technical Expertise
Be prepared to discuss your hands-on experience with disaster recovery and failover testing. Highlight specific projects where you successfully implemented operational resilience strategies, and be ready to explain the technical details behind your decisions.
✨Understand Security Frameworks
Familiarise yourself with key security frameworks such as ISO27001 and NIST. During the interview, demonstrate your understanding of how these frameworks apply to the role and how you have used them in past experiences to enhance security posture.
✨Communicate Clearly
As an IT Security and Resilience Specialist, you'll need to translate complex technical findings into business impacts. Practice explaining your past work in simple terms, focusing on how your actions benefited the organisation and mitigated risks.
✨Prepare for Scenario-Based Questions
Expect scenario-based questions that assess your problem-solving skills in real-world situations. Think of examples where you identified vulnerabilities or led incident response investigations, and be ready to discuss the outcomes and lessons learned.