Information Security Officer - Mandarin Speaking in London

Information Security Officer - Mandarin Speaking in London

London Full-Time 63000 - 77000 £ / year (est.) Home office (partial)
S

At a Glance

  • Tasks: Manage and improve information security practices across Asia, ensuring compliance with ISO 27001 standards.
  • Company: Dynamic firm committed to maintaining high information security standards in a global environment.
  • Benefits: Competitive salary, inclusive culture, and opportunities for professional growth.
  • Other info: Fluency in English and Mandarin essential; travel to Hong Kong and Beijing expected.
  • Why this job: Be a key player in enhancing information security while collaborating internationally.
  • Qualifications: Strong knowledge of ISO 27001 and experience in information security roles required.

The predicted salary is between 63000 - 77000 £ per year.

Reporting to the Senior Information Security Manager, the Information Security Officer for Asia will play a key role in maintaining the firm's ISO 27001 certification across its offices in Asia (Hong Kong and Beijing).

This is a new role, based in London, that will primarily be responsible for the day-to-day management, administration and continual improvement of the Asia Information Security Management System (ISMS).

This is a hands-on individual contributor role, requiring a strong understanding of the ISO 27001 standard and the ability to work independently, building strong relationships with stakeholders across both Europe and Asia offices.

The role will help ensure that information security practices in Asia remain aligned with both the firm's global standards and applicable local regulatory requirements.

The role will also provide security oversight and guidance for projects, technology changes, and operational activities across the firm's Asia offices, ensuring that information security risks are managed effectively.

A strong background in information security Governance, Risk and Compliance (GRC) is essential.

The role requires fluency in both English and Mandarin, with Cantonese considered beneficial.

Occasional travel to Hong Kong and Beijing will be required, typically two to four trips per year, each lasting several days.

Given the requirement to collaborate regularly with colleagues across Asia, some flexibility in working hours is desirable, for example 8:00am to 4:00pm UK time.

Key responsibilities

The key responsibilities of this role are set out below and there may be others which are not listed.

You may be required on occasion to work outside our normal working hours of 9:30am to 5:30pm.

• Manage the day-to-day operations of the firm’s Asia ISMS by

  • Maintaining policies such that they align with the firm’s global standards but reflect local variations in both the regulatory landscape and working practice.
  • Maintain and continuously improve risk, incident and exceptions registers.
  • Track relevant metrics against ISMS objects and produce management review reports for Steering Group meetings.
  • Coordinate and facilitate internal and external ISO 27001 audits for the Hong Kong and Beijing offices, managing audit schedules, stakeholder engagement, and the completion of audit deliverables.
  • Coordinate with relevant Business Services teams and stakeholders to develop, implement, and monitor remediation plans for audit findings, and drive continuous improvement.
  • Collaborate with the wider Information Security and Privacy (ISP) team to support the delivery of information security awareness and training programmes, promoting a strong security culture across the Hong Kong and Beijing offices.
  • Provide advice and support to the Hong Kong and Beijing offices, as their primary information security representative.
  • Candidate profile

Candidates for this position must have

  • Strong working knowledge of ISO 27001, e. g. ISO 27001 Lead Implementer or Lead Auditor.
  • Prior experience in an information security or GRC role, ideally within a regulated environment or an organisation aligned to ISO 27001.
  • A self-motivated, results-driven mindset with a strong sense of ownership and accountability.
  • Excellent organisational skills, with the ability to prioritise effectively in a fast-paced environment.
  • Proven ability to collaborate effectively, build strong professional relationships, and communicate confidently with senior leadership.
  • Fluent in both English and Mandarin. Cantonese speaking beneficial.
  • Ability and willingness to travel to Hong Kong and Beijing, typically two to four trips per year

We are committed to ensuring that our recruitment processes are barrier-free and as inclusive as possible for everyone.

This includes making adjustments for people who have a disability or long-term condition.

If you have any questions or require any adjustments to be made to one or both of the application or interview processes, please contact the Recruitment Team.

We are a Disability Confident Committed employer and will offer an interview to applicants with a disability or long-term condition who best meet the minimum or essential criteria for our Business Services roles.

If you would like to apply through the Disability Confident 'Offer An Interview' commitment, please apply via our online application form and not via Linked In.

You are disabled under the Equality Act 2010 if you have a physical or mental impairment that has a ‘substantial’ and ‘long-term’ negative effect on your ability to do normal daily activities.

For more information about the Disability Confident scheme, please see the government website here.

We welcome applications irrespective of race, colour, ethnic or national origin, disability, sex, gender identity, sexual orientation, age, religion, belief or marital status.

#J-18808-Ljbffr

Information Security Officer - Mandarin Speaking in London employer: Slaughter and May

Join a dynamic and inclusive work environment as a Paralegal in our Pensions, Employment and Incentives Group, where you will have the opportunity to support experienced legal professionals on a variety of impactful projects. Our commitment to employee growth is evident through our supportive culture and focus on professional development, ensuring that you can thrive in your legal career while contributing to meaningful client work. Located in a vibrant area, we offer a collaborative atmosphere that values diversity and encourages innovative thinking.

S

Contact Details:

Slaughter and May Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Information Security Officer - Mandarin Speaking in London

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Slaughter and May, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through Slaughter and May

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Slaughter and May. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Information Security Officer - Mandarin Speaking in London

ISO 27001
Information Security Management System (ISMS)
Governance, Risk and Compliance (GRC)
Audit Coordination
Stakeholder Engagement
Risk Management
Incident Management

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Slaughter and May insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Slaughter and May that you’re committed to staying ahead in the game.

How to prepare for a job interview at Slaughter and May

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at Slaughter and May to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Slaughter and May.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.