Information Security Officer in Leeds

Information Security Officer in Leeds

Leeds Full-Time 57000 - 57000 £ / year (est.) No home office possible
Walker Morris LLP

At a Glance

  • Tasks: Lead and enhance the firm's information security governance and risk management.
  • Company: Join a modern law firm with a commitment to innovation and security.
  • Benefits: Competitive salary, bonus scheme, generous leave, and hybrid working options.
  • Other info: Inclusive workplace with opportunities for personal and professional growth.
  • Why this job: Shape the future of information security in a dynamic legal environment.
  • Qualifications: Experience in information security and strong knowledge of ISO standards required.

The predicted salary is between 57000 - 57000 £ per year.

We are seeking an experienced Information Security Officer to own and further develop the firm's information security governance, risk and compliance framework. Building on an established ISO 27001-certified environment, this role offers genuine scope to streamline, refine and enhance existing approaches, allowing you to put your own stamp on how information security operates within a modern law firm. Working closely with the wider IT team and Risk and Compliance, you will act as a trusted adviser to senior stakeholders, embedding practical, risk-based security into day-to-day business activities. You will oversee information security risk management, client and regulatory assurance, supplier security and security awareness across the firm. This is a role with real autonomy and is ideal for someone who enjoys ownership, influence and the opportunity to shape and grow a function as the firm continues to evolve.

Governance & Policy

  • Own and maintain the firm's information security governance framework, ensuring it remains current, risk-based and aligned to business strategy.
  • Define, draft and maintain information security policies, standards and procedures, ensuring they are clear, proportionate and practical for a modern law firm.
  • Ensure policies and standards are regularly reviewed, approved through appropriate governance, and effectively communicated across the firm.
  • Provide authoritative guidance on information security matters, acting as a trusted adviser to senior stakeholders and the wider business.
  • Embed security-by-design principles into business processes, projects and decisions.

Compliance & Assurance

  • Own and operate the firm's Information Security Management System (ISMS) in line with ISO 27001 / ISO 27002.
  • Lead preparation for, and ongoing compliance with, ISO 27001 surveillance and re-certification audits, driving continual improvement.
  • Maintain oversight of Cyber Essentials Plus, ensuring readiness for annual assessments and ongoing compliance with requirements.
  • Coordinate internal information security reviews and audits, ensuring findings are addressed and actions tracked to completion.
  • Provide regular, concise management reporting on information security posture, risks and compliance status.

Client & Regulatory Assurance

  • Act as the firm's primary point of contact for client information security assurance activities, including questionnaires and audits.
  • Provide clear, consistent evidence of the firm's information security controls and governance arrangements.
  • Support the business in meeting regulatory and contractual information security obligations, working closely with Risk and Compliance functions.

Risk Management

  • Lead the identification, assessment and ongoing management of information security risks across the firm.
  • Maintain oversight of the firm's information security risk register, ensuring risks are clearly articulated, prioritised and owned.
  • Work with IT, Risk & Compliance and business stakeholders to agree proportionate risk treatments aligned to the firm's risk appetite.

Third-Party & Supplier Assurance

  • Define and maintain the firm's approach to third-party information security assurance.
  • Support due diligence activities for new, existing suppliers and their solutions, assessing information security risk and alignment to firm standards.
  • Act as product owner for the supplier management system, accountable for the system roadmap, configuration, and continuous improvement, and supporting the process owner in delivering a compliant and effective supplier management process.

Security Awareness & Culture

  • Design and oversee the firm's information security awareness and training programme, ensuring relevance for different roles and audiences.
  • Promote a security-conscious culture, encouraging shared responsibility for protecting information.

Experience

  • Proven experience in an Information Security / GRC role, with responsibility for governance, risk management and compliance.
  • Certified ISO Lead Implementer/Auditor with strong working knowledge of ISO 27001 and ISO 27002, including operating and improving an ISMS in a regulated or professional services environment.
  • Experience supporting Cyber Essentials Plus or similar assurance frameworks.
  • Good understanding of GDPR, data protection principles and the management of confidential, personal and sensitive information.
  • Experience working with non-technical stakeholders, translating security requirements into practical, business-appropriate controls.
  • Experience supporting internal audits, external assessments and client assurance activities.

Skills

  • Strong influencing and stakeholder management skills, with the confidence to constructively challenge and drive change.
  • Ability to take a risk-based, pragmatic approach, balancing security, usability and business outcomes.
  • Clear written and verbal communication skills, with the ability to produce high-quality policies, reports and guidance.
  • Logical, methodical approach with strong attention to detail.
  • Excellent organisational skills and the ability to manage multiple priorities effectively.

Benefits

  • Salary up to £57,000 per annum, depending on experience.
  • Earn up to 10% of your salary with our annual bonus scheme.
  • Minimum of 25 days annual leave plus Bank Holidays per year, increasing to 31 days with length of service, with the opportunity to buy up to 5 days holiday per year.
  • Hybrid working with on average 40–60% of your time spent in the office.
  • Auto-enrolled into the workplace pension scheme, with a minimum contribution of 6% of your salary.
  • 4x your annual salary in the event of a death in service.

Equal Opportunity Statement

Walker Morris is committed to being an inclusive employer. We welcome applications regardless of sexual orientation, gender identity and expression, age, neuro‑diversity or disability status, family or parental status, race, religion or ethnicity. If you need any reasonable adjustments throughout the recruitment process, please don't hesitate to ask. We are a Disability Confident employer.

Information Security Officer in Leeds employer: Walker Morris LLP

At Walker Morris, we pride ourselves on being an exceptional employer, offering a dynamic work environment where innovation in information security is not just encouraged but expected. With a strong commitment to employee growth, our hybrid working model allows for a balanced lifestyle while providing opportunities to shape the future of our information security governance. Join us and enjoy competitive benefits, including a generous annual leave policy and a supportive culture that values diversity and inclusion.
Walker Morris LLP

Contact Detail:

Walker Morris LLP Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Information Security Officer in Leeds

✨Tip Number 1

Network like a pro! Reach out to your connections in the industry, attend relevant events, and engage with professionals on platforms like LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.

✨Tip Number 2

Prepare for interviews by researching the company and its culture. Understand their approach to information security and be ready to discuss how your experience aligns with their needs. Tailor your responses to show how you can add value to their team.

✨Tip Number 3

Practice makes perfect! Conduct mock interviews with friends or mentors to refine your answers and boost your confidence. Focus on articulating your experience with ISO standards and risk management clearly and concisely.

✨Tip Number 4

Don’t forget to follow up after interviews! A simple thank-you email can leave a lasting impression and keep you top of mind. Plus, it shows your enthusiasm for the role and the company.

We think you need these skills to ace Information Security Officer in Leeds

Information Security Governance
Risk Management
Compliance Frameworks
ISO 27001
ISO 27002
Cyber Essentials Plus
GDPR Knowledge
Stakeholder Management
Influencing Skills
Communication Skills
Policy Development
Attention to Detail
Organisational Skills
Training Programme Design
Third-Party Risk Assessment

Some tips for your application 🫡

Tailor Your Application: Make sure to customise your CV and cover letter to highlight your experience in information security governance, risk management, and compliance. We want to see how your skills align with our needs, so don’t hold back on showcasing your relevant achievements!

Showcase Your Certifications: If you’ve got certifications like ISO Lead Implementer or Auditor, make them pop! We love seeing that you’re certified in ISO 27001 and ISO 27002, as it shows you know your stuff and can hit the ground running.

Be Clear and Concise: When writing your application, keep it straightforward and to the point. We appreciate clear communication, so make sure your policies, reports, and guidance examples are easy to understand and well-structured.

Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, it gives you a chance to explore more about us and what we do!

How to prepare for a job interview at Walker Morris LLP

✨Know Your ISO Inside Out

Make sure you’re well-versed in ISO 27001 and ISO 27002. Brush up on the specifics of the standards and be ready to discuss how you've implemented or improved an ISMS in your previous roles. This will show that you can hit the ground running.

✨Speak Their Language

Prepare to translate complex security concepts into business-friendly language. Since you'll be working with non-technical stakeholders, practice explaining how security measures align with business goals. This will demonstrate your ability to bridge the gap between IT and the wider business.

✨Showcase Your Risk Management Skills

Be ready to discuss your experience with risk management. Prepare examples of how you've identified, assessed, and managed information security risks in the past. Highlight your approach to balancing security with usability and business outcomes.

✨Engage with Security Culture

Think about how you can promote a security-conscious culture within the firm. Be prepared to share ideas for training programmes or awareness initiatives you've led before. This shows that you’re not just about compliance but also about fostering a proactive security environment.

Information Security Officer in Leeds
Walker Morris LLP
Location: Leeds

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

>