Information Security Coordinator
Role details
Job location
Tech stack
Job description
We are seeking a detail-oriented and proactive Information Security Coordinator to support our firm's compliance with ISO 27001 and respond to client security-related inquiries. This role is critical in maintaining our security posture, ensuring audit readiness, and building trust with clients through transparent and accurate responses to their security questionnaires., ISO 27001 Coordination:
- Coordinate internal and external ISO 27001 audits, including scheduling, documentation, and follow-up actions.
- Maintain and update the firm's Information Security Management System (ISMS).
- Track and report on audit findings, corrective actions, and continuous improvement initiatives.
- Liaise with departments across the firm to ensure compliance with ISO 27001 controls.
Client Security Questionnaires:
- Review, complete, and manage responses to client security questionnaires and due diligence requests.
- Collaborate with legal, IT, and compliance teams to gather accurate and timely information.
- Maintain a repository of standard responses and supporting documentation.
- Identify recurring themes or concerns and escalate where necessary.
General Information Security Support:
- Assist in the development and maintenance of security policies, procedures, and training materials.
- Support risk assessments and third-party vendor reviews.
- Help monitor compliance with internal security controls and regulatory requirements.
Requirements
Do you have experience in NIST standards?, Essential:
- Experience coordinating ISO 27001 audits or working within an ISMS framework.
- Strong understanding of information security principles and risk management.
- Excellent written communication skills, particularly in responding to formal client queries.
- High attention to detail and ability to manage multiple tasks simultaneously.
Desirable:
- Experience in a legal or professional services environment.
- Familiarity with other security frameworks (e.g., NIST, SOC 2).
Knowledge of data protection regulations (e.g., GDPR).
Qualifications:
- Degree or equivalent experience in Information Security, Risk Management, or a related field.
- ISO 27001 Lead Implementer or Auditor certification (preferred but not essential)., * We don't have a type. We believe our differences are our strength; varied cultures, approaches and experience can only benefit us.
Benefits & conditions
- In the office or WFH?: We think the best balance is more time in the office than at home, so we operate a 60:40 rule.
- Beyond salary: We offer plenty of benefits; private medical insurance, health cash plan, dental insurance, life assurance, critical illness insurance, matched pension contributions up to 7%, holiday trading, plus many more. Visit: Reward & Benefits ¦ Fieldfisher.
- Modern Office Space: Located in the iconic Titanic Quarter with excellent commuter links and parking nearby.
- Nurturing your talent: Take a 'build a career' approach to your training. You'll be on a pathway but free to wander if you see something you'd like to study more closely.
- Funnel your interests: You have a life outside work, and we can help it to flourish. Join clubs, affinity networks, inclusive events, and pro bono/charity initiatives.
Inclusion is not exclusive:
If all our differences are highlighted, no one stands out for being different. At Fieldfisher, all our rich diversity is celebrated.
We will provide the equipment to allow you to shine, at interview and beyond. Just let us know what you need.