Senior Cyber and Information Security Manager
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
As our Senior Cyber and Information Security Manager, you’ll lead the continued development of our cyber and information security function within our growing national law firm.
In this role, you’ll:
- Define and deliver our cyber and information security strategy and roadmap.
- Act as a trusted advisor to senior leaders on cyber risk, governance and compliance.
- Own and continually enhance our Information Security Management System (ISMS).
- Lead our approach to ISO 27001, NIST CSF, Cyber Essentials Plus and wider security best practice.
- Oversee security operations, incident response and threat management activities.
- Manage key security suppliers, partners and managed service providers.
- Support client audits, due diligence requests and regulatory requirements.
- Drive security awareness and embed a security-first culture across the firm.
- Lead and develop a small team of Cyber and Information Security professionals.
- Work collaboratively with Technology, Risk, Compliance and business teams to strengthen our security posture.
This is a highly visible role offering the opportunity to influence strategy, shape security culture and play a key role in our ongoing growth journey.
Requirements
We’re looking for an experienced cyber and information security professional who combines technical expertise with strong stakeholder management and leadership skills.
You’ll bring:
- Significant experience in a senior cyber or information security role.
- Experience within a regulated or professional services environment.
- Strong knowledge of ISO 27001, NIST CSF, Cyber Essentials Plus and security governance frameworks.
- Hands-on experience across risk management, incident response and security operations.
- Proven ability to engage, influence and build credibility with senior stakeholders.
- Experience leading, mentoring or developing security professionals.
- A strong understanding of GDPR and data protection principles.
- A proactive, pragmatic and solutions-focused approach., * CISM certification (required).
- CISSP and/or ISO 27001 Lead Implementer/Auditor certification desirable.
- Commitment to ongoing professional development.
Desirable experience
- Leading ISO 27001 implementation and certification programmes.
- Legal sector experience.
- Managing external audits, client assurance activities and third-party security assessments.
Benefits & conditions
We believe our people are our greatest asset. That’s why we offer a comprehensive benefits package designed to support your professional growth and personal wellbeing, including:
- Competitive salary and performance-linked bonus.
- Enhanced parental leave policies.
- Private healthcare and wellbeing initiatives.
- An open, flexible working environment.
- Find out more about our benefits and work environment here
About the company
We’re one of the UK’s most forward-thinking law firms, built on a foundation of innovation, collaboration, and ambition. Join us, and let’s shape the future together.
Being refreshingly human starts with how we hire. We believe a diverse mix of perspectives makes us stronger, not just as a business, but in creating a culture where we all feel we truly belong and can thrive. That’s why we’re committed to removing barriers and creating fair opportunities for everyone., At Foot Anstey, we’re committed to making a difference for our people, our clients, and society. Here’s what makes us stand out:
- An ambitious growth strategy that opens up opportunities for our people to make their mark.
- A client base that spans household names, thriving startups, and ambitious enterprises.
- A culture built on our values of being refreshingly human, entrepreneurial, inclusive and collaborative.
- A strong focus on being a responsible business with a commitment to sustainability and giving back to our communities.
- Comprehensive professional development and training - whatever your role and level we have training that will support you to achieve your goals.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Best Companies to work for in London: Top 25 Companies in 2023
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
IT Salaries in UK
Fully Remote Software Engineer Jobs