Overview
As an Information Security Analyst, you will support the ISMS and governance framework within a leading law firm. You’ll work with stakeholders across the firm to advance information security governance, risk management, supplier assurance, audits, and policy management. The role focuses on maintaining the ISMS, producing metrics, and driving security awareness. You will contribute to ISO 27001 activities and client due diligence, helping the firm strengthen its risk and compliance posture.
Responsibilities
- Administer and improve the Information Security Management System (ISMS)
- Assist ISO 27001 certification, surveillance and internal audits
- Coordinate audit evidence collection and remediation tracking
- Maintain information security policies, standards, procedures and documentation
- Track information security risk, treatment actions and exceptions
- Coordinate client information security due diligence questionnaires and assurance requests
- Support third-party supplier assurance and risk assessment activities
- Produce information security metrics, dashboards and management reporting
- Support ISMS objectives and governance reporting
- Assist with security awareness, communications and training initiatives
- Maintain governance documentation, registers and tracking mechanisms
- Collaborate with stakeholders to meet information security and compliance needs
Key requirements
- Understanding of information security, risk management and governance principles
- Strong organisational and administrative skills
- Excellent written and verbal communication skills
- Attention to detail and methodical approach
- Ability to manage multiple priorities and deadlines
- Strong analytical and problem-solving abilities
- Good working knowledge of Microsoft Office (Word, Excel, PowerPoint, Outlook)
- Ability to build effective relationships with stakeholders
- Self-motivated and eager to learn in Information Security and GRC
- Communication
- Attention to detail
- Stakeholder management
- Information security governance
- Risk management
- ISO 27001 understanding
…
