> Markdown version of [/jobs/ext/2801195-information-security-analyst](https://www.wearedevelopers.com/jobs/ext/2801195-information-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Analyst - **Company:** Howard Limited - **Location:** Greater London, UK - **Contract:** Permanent contract - **Skills:** Microsoft Online Services, Cyber Security, Intrusion Detection Systems, Web Application Security, Software Vulnerability Management, Firewalls (Computer Science) - **Published:** September 9, 2026 - **Apply:** https://www.collegerecruiter.com/job/2858100148-information-security-analyst ## About the Role We are seeking an Information Security Analyst to join our Cyber Security team. This is a varied and hands-on role, offering an excellent opportunity for a motivated security professional to develop their career within a forward thinking professional services environment., Ideally you will be able to demonstrate; * Experience in an information or cyber security role covering protection, monitoring, response, and advisory work; law firm or professional services experience is desirable. * Comfort and experience operating with real autonomy and ownership, ideally within a small or lean security team rather than a large structure. * Broad technical knowledge across networking, systems administration, infrastructure, applications, and security, with the ability to challenge designs and identify real risk. * Hands-on experience with common security technologies and controls (e.g. endpoint protection, email/web security, firewalls, IDS/IPS). * Good working knowledge of Microsoft platforms and security capabilities. * Sound understanding of information risk, with the ability to assess conditions and consequences rather than rely solely on generic severity ratings. * Knowledge of relevant standards, good practice, and regulatory requirements, including UK GDPR and the Data Protection Act 2018. * Strong analytical skills with the ability to translate business requirements into proportionate security controls. * Excellent written and verbal communication skills, with the ability to engage both technical and non-technical stakeholders. * Organised, methodical, and accurate approach, with strong attention to detail and a willingness to learn and develop. * High levels of integrity and discretion when handling sensitive information. * Pragmatic, business-focused mindset with the ability to balance risk and usability. * Curiosity and pro-activity, with a continuous improvement mindset and willingness to challenge assumptions constructively. * A collaborative and service-oriented approach, with an understanding of the pressures of a legal services environment. * The ability to work calmly and methodically particularly when managing incidents or competing priorities. ## Description Working across technical security, risk and governance, compliance, and continuous improvement, you will gain broad exposure to all aspects of information security while supporting a business that places technology, security, and client trust at its core. As part of the Information Security function, you will play a key role in protecting the firm's information, systems, and digital services, helping to ensure legal services are delivered securely, reliably, and in line with regulatory, contractual, and client expectations. Working closely with IT teams, Partners, lawyers, Business Services colleagues, suppliers, and security partners, you will help identify, assess, and manage risks, while providing practical security guidance that enables secure and productive ways of working., Protect * Operate, review, and improve security controls, risk treatment activity, and security processes within approved policies, standards, and change governance. * Assist with identity and access management, including joiners/movers/leavers processes, access review evidence, and approved privileged access activities. * Support vulnerability management by coordinating evidence, prioritising remediation by business context and consequence, and tracking issues to closure. * Support the implementation and operation of security technologies and upgrades in line with agreed standards. * Review technical designs, configurations, and change proposals to identify security risk. * Support the definition and implementation of security requirements for new systems and material changes. * Work with suppliers and managed service providers to keep operational controls effective. Monitor & Respond * Monitor security and threat detection systems, investigate alerts, and identify trends that need a response. * Respond to security policy breaches and provide practical guidance on secure working practices. * Act as an escalation point for security queries from the Service Desk, IT, and Risk and Compliance teams, including DSAR evidence gathering where appropriate. * Support incident response activities including triage, investigation, containment, documentation, remediation tracking, and post-incident review. * Support business continuity and disaster recovery activity, helping restore protected services quickly after disruption. * Monitor emerging threats and vulnerabilities and recommend appropriate mitigations. Advise * Maintain the information security risk register so it reflects current risks, controls, actions, and escalation requirements. * Support audits, client due diligence, ISO 27001 assurance, and governance reporting through evidence collation, metrics, and action tracking. * Support third-party risk management, including onboarding, questionnaires, contract evidence, and ongoing supplier assurance. * Work with the Data Protection Officer on data protection incidents and assessments in line with UK GDPR, the Data Protection Act 2018, and SRA expectations where applicable. * Produce clear reports for technical and non-technical stakeholders. * Assist with the creation and delivery of cyber security awareness and training for colleagues., We are proud to be an equal opportunities employer. We welcome applications from individuals of all backgrounds and identities, and we're committed to ensuring that our recruitment process is fair, transparent, and accessible to all. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Bulletproof Web Applications: The 2025 OWASP Top Ten](https://www.wearedevelopers.com/videos/100072-bulletproof-web-applications-the-2025-owasp-top-ten) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Forecasting Cyber Attacks with Glassdoor Reviews - Lianne Potter](https://www.wearedevelopers.com/videos/2143-forecasting-cyber-attacks-with-glassdoor-reviews-lianne-potter) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) ## Related Articles - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [UK Business Culture and Etiquette](https://www.wearedevelopers.com/magazine/326-uk-business-culture-and-etiquette) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [Software Engineer Salary London](https://www.wearedevelopers.com/magazine/252-software-engineer-salary-london)