Overview
In this role you will deputise for the Head of Information Security and provide strategic governance across the Information Security function. You will shape and mature the security strategy, align it with firm objectives, and establish effective governance. You will oversee policy, regulatory mapping (GDPR, ISO 27001), risk and assurance, and executive reporting to drive risk-informed decision making. This is a senior, cross-functional leadership role that places you at the core of regulatory readiness, audit engagement, and board-level visibility.
Pay / Benefits
- hybrid working
Responsibilities
- Deputise for the Head of Information Security at key governance bodies (ITLT, OpCom, RiskCom, Advisory Board)
- Define and mature Information Security Strategy aligned to Technology Directorate and firm objectives
- Establish governance mechanisms for security oversight
- Maintain Information Security Terms of Reference
- Ensure security roles, responsibilities and training plans are defined
- Own Information Security Policy framework and supporting standards
- Map regulatory/industry standards (GDPR, ISO 27001) to firm policies
- Oversee policy attestation and compliance reporting
- Lead audit readiness and regulatory engagement
- Manage information security risks, escalation and remediation
- Oversee third-party security assessment programme
- Provide executive reporting on security posture, risk exposure and compliance
- Maintain evidence framework for compliance and traceability
- Support Information Security budget and business case development
- Prioritise and manage demand across the InfoSec portfolio
- Ensure compliance with applicable legal and regulatory obligations including SRA standards
Key requirements
- 8–12+ years in Information Security with governance leadership experience
- Strong knowledge of ISO 27001, GDPR; experience in a law firm or regulated professional services environment preferred
- Experience presenting to executive committees
- Strong commercial and financial awareness
- Ability to operate at strategic and tactical levels
- executive communication
- strategic leadership
- stakeholder management
- ISO 27001
- GDPR
- regulatory compliance
…
