Head of Information Security

Head of Information Security

London | £100,000 to £110,000 | Hybrid, 3 days office

Are you an experienced Information Security leader who can combine cyber strategy with hands-on operational leadership in a highly regulated professional services environment?

We are recruiting a Head of Information Security for a leading London law firm. Reporting directly to the CIO, you will take ownership of the firm's cyber security strategy, security operations, cyber risk and assurance, while leading the continued development of its security capability.

This is a broad leadership position covering everything from the outsourced SOC and incident response through to ISO 27001, Cyber Essentials Plus, cloud security, supplier assurance and the secure adoption of AI.

What’s on offer:

• Hybrid working, 3 days per week in the London office

• Direct reporting line to the CIO

• Senior ownership of the firm's cyber security strategy and roadmap

• Opportunity to influence security across technology, cloud, data and AI

• Leadership of internal security capability and external security partners

• High visibility across senior leadership and the wider business

What you’ll be responsible for:

• Develop and deliver the firm's cyber security strategy and maturity roadmap

• Own and continuously improve security operations and the outsourced SOC

• Lead cyber incident investigation and response

• Oversee vulnerability management, penetration testing and remediation programmes

• Maintain ownership of ISO 27001 and Cyber Essentials Plus

• Establish security architecture principles across infrastructure, cloud, SaaS, data and business applications

• Embed security and privacy by design into technology projects

• Own third-party and supplier security assurance

• Produce clear cyber risk and control reporting for senior leadership

• Support business continuity, disaster recovery and operational resilience

• Work closely with IT Operations, Data, Innovation, Legal and the DPO

• Advise on security and governance risks surrounding AI and emerging technologies

• Support client security audits, tenders and due diligence exercises

• Lead, mentor and develop Information Security team members and external partners

What we’re looking for:

• Strong Information Security leadership experience, ideally within legal, professional services or another regulated environment

• CISSP or CISM certification

• Proven ownership of ISO 27001 certification and continuous improvement

• Strong experience managing outsourced SOC and specialist security providers

• Excellent understanding of incident response, threat detection, vulnerability management and remediation

• Strong Microsoft/Azure, cloud, infrastructure and SaaS security knowledge

• Experience providing security assurance across technology projects and architecture

• Understanding of UK GDPR, data protection and regulatory security requirements

• Experience advising senior stakeholders on cyber risk

• Understanding of security risks associated with AI and data platforms

• Strong people leadership and stakeholder management skills

• Ability to operate strategically while remaining close enough to security operations to provide practical leadership

If you’re looking for a senior security role where you can genuinely shape cyber strategy, maturity and culture, apply today to find out more.

Our client is an equal opportunity employer. They celebrate diversity and are committed to creating an inclusive workplace where all employees feel valued and respected. We encourage applications from candidates of all backgrounds.

Due to the high volume of applications, if you haven’t heard from us within 72 hours, please assume your application has been unsuccessful on this occasion.

Job Details

Company
Picture More
Location
London, South East England, United Kingdom
Hybrid / Remote Options
Employment Type
Full-Time
Salary
Salary negotiable
Posted