Information Security Analyst
Herbert Smith Freehills LLP
London, UK
5 days ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Apply on www.collegerecruiter.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Job source
Tech stack
Artificial Intelligence
Cyber Security
Data Security
Information Security Management
Phishing
Information Security Management System
Servicenow
Job description
The individual will work closely with the UK, Australia and US-based teams in the following primary areas of responsibility, focusing on the UK and EMEA offices, * Providing assurance to external stakeholders, including:
- Supporting the maintenance of the Firms ISO 27001 certification, in particular:
- Preparing new and existing business units for certification/audit.
- Collating metrics in support of governance and continual improvement.
- Risk assessing new ways of working, alongside the Risk and IT teams.
- Assessing compliance with client-specific security requirements within the legal teams.
- Managing the ISMS tools, documentation and trackers.
- Supporting internal security audit activities.
- Operational Security Oversight
- Investigate and manage DLP alerts and user behaviour anomalies, escalating as needed.
- Support incident response for phishing, impersonation scams, and other security events.
- Assist with API integration projects to enhance security workflows (e.g., ServiceNow integrations).
- Security Awareness & Education
- Deliver and monitor phishing simulation campaigns, producing reports and insights.
- Contribute to security communications and awareness programs across the firm.
- Strategic Initiatives
- Participate in onboarding new security technologies such as Data Security Posture Management (DSPM).
- Engage with AI Risk and Governance discussions to support emerging technology adoption.
- Stakeholder Collaboration
- Build strong relationships with IT, Risk, HR, and legal teams to embed security into business processes
- Provide practical security advice to internal stakeholders.
Requirements
- Degree educated (technical degree or similar).
- We would expect the successful candidate to have around three years' experience in information security but may consider those with less experience providing they can demonstrate they meet the required competencies.
- Strong knowledge of ISO 27001 implementation and certification.
- Power BI analytics and reporting.
- One or more of the following desired - MSc in security or similar; CISSP; CISA/CISM; ISO 27001 Lead Auditor.
- Professional Services experience preferable.
- Adaptable, diligent and works with initiative.
- Strong relationship builder - internal and external.
- Familiarity with security tools and systems would be advantageous (e.g., Email DLP, UEBA, phishing simulation).
- Experience working as part of a global team.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.collegerecruiter.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
EM
Eli McGarvie
about 3 years ago
EM
Eli McGarvie
IT Salaries in UK
almost 3 years ago
EM
Eli McGarvie
Best Companies to work for in London: Top 25 Companies in 2023
over 3 years ago
LM
Luis Minvielle
The Most Popular IT Jobs on the Market
over 2 years ago
EM
Eli McGarvie
Data Engineer Salary UK
about 3 years ago
LM
Luis Minvielle
Top-Paying Tech Jobs (with Salaries)
over 2 years ago