Senior Cyber and Information Security Manager

Foot Anstey LLP
Southampton, UK
12 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours
Job source

Tech stack

Cyber Security Information Security Management System

Job description

As our Senior Cyber and Information Security Manager, you’ll lead the continued development of our cyber and information security function within our growing national law firm.

In this role, you’ll:

  • Define and deliver our cyber and information security strategy and roadmap.
  • Act as a trusted advisor to senior leaders on cyber risk, governance and compliance.
  • Own and continually enhance our Information Security Management System (ISMS).
  • Lead our approach to ISO 27001, NIST CSF, Cyber Essentials Plus and wider security best practice.
  • Oversee security operations, incident response and threat management activities.
  • Manage key security suppliers, partners and managed service providers.
  • Support client audits, due diligence requests and regulatory requirements.
  • Drive security awareness and embed a security-first culture across the firm.
  • Lead and develop a small team of Cyber and Information Security professionals.
  • Work collaboratively with Technology, Risk, Compliance and business teams to strengthen our security posture.

This is a highly visible role offering the opportunity to influence strategy, shape security culture and play a key role in our ongoing growth journey.

Requirements

We’re looking for an experienced cyber and information security professional who combines technical expertise with strong stakeholder management and leadership skills.

You’ll bring:

  • Significant experience in a senior cyber or information security role.
  • Experience within a regulated or professional services environment.
  • Strong knowledge of ISO 27001, NIST CSF, Cyber Essentials Plus and security governance frameworks.
  • Hands-on experience across risk management, incident response and security operations.
  • Proven ability to engage, influence and build credibility with senior stakeholders.
  • Experience leading, mentoring or developing security professionals.
  • A strong understanding of GDPR and data protection principles.
  • A proactive, pragmatic and solutions-focused approach., * CISM certification (required).
  • CISSP and/or ISO 27001 Lead Implementer/Auditor certification desirable.
  • Commitment to ongoing professional development.

Desirable experience

  • Leading ISO 27001 implementation and certification programmes.
  • Legal sector experience.
  • Managing external audits, client assurance activities and third-party security assessments.

Benefits & conditions

We believe our people are our greatest asset. That’s why we offer a comprehensive benefits package designed to support your professional growth and personal wellbeing, including:

  • Competitive salary and performance-linked bonus.
  • Enhanced parental leave policies.
  • Private healthcare and wellbeing initiatives.
  • An open, flexible working environment.
  • Find out more about our benefits and work environment here

About the company

We’re one of the UK’s most forward-thinking law firms, built on a foundation of innovation, collaboration, and ambition. Join us, and let’s shape the future together.

Being refreshingly human starts with how we hire. We believe a diverse mix of perspectives makes us stronger, not just as a business, but in creating a culture where we all feel we truly belong and can thrive. That’s why we’re committed to removing barriers and creating fair opportunities for everyone., At Foot Anstey, we’re committed to making a difference for our people, our clients, and society. Here’s what makes us stand out:

  • An ambitious growth strategy that opens up opportunities for our people to make their mark.
  • A client base that spans household names, thriving startups, and ambitious enterprises.
  • A culture built on our values of being refreshingly human, entrepreneurial, inclusive and collaborative.
  • A strong focus on being a responsible business with a commitment to sustainability and giving back to our communities.
  • Comprehensive professional development and training - whatever your role and level we have training that will support you to achieve your goals.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

5:03 min

Navigating new cybersecurity compliance frameworks and laws

Kurt Eder · LIVE

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · World Congress 2026 Europe

4:27 min

Embracing a new perspective on mobile cyber attacks

Tom Tovar · World Congress 2023

Videos

See all

Related articles

See all