Enable job alerts via email!

Information Security Analyst

Locke & Mccloud

Manchester

Hybrid

GBP 55,000 - 66,000

Full time

12 days ago

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

Join a forward-thinking law firm as an Information Security Analyst, where you'll play a crucial role in enhancing security resilience during a major cyber transformation. In this dynamic position, you'll maintain and improve the Information Security Management System (ISMS), ensure compliance with ISO 27001 across various jurisdictions, and conduct internal audits while leading remediation efforts. This innovative firm offers a hybrid working model, allowing you to balance onsite collaboration with flexible working arrangements. If you're passionate about information security and eager to contribute to a strategic cyber investment, this opportunity is perfect for you.

Qualifications

  • Experience in information security or compliance-based roles.
  • Knowledge of ISO 27001, Cyber Essentials, NIST or similar frameworks.

Responsibilities

  • Maintain and improve the ISMS, including policies and procedures.
  • Conduct internal audits and lead remediation efforts.

Skills

Information Security
Compliance
Communication
Collaboration
Incident Management

Education

Certifications like CISMP, CISSP or ISO 27001 Lead Auditor

Tools

ISO 27001
Cyber Essentials
NIST
Microsoft 365

Job description

Information Security Analyst

Hybrid (Manchester, 3 Days Onsite + Flexible Working) | £55,729–£65,729 + Strong UK Benefits | Strategic Cyber Investment

Be part of a forward-thinking law firm undergoing a major cyber transformation. As an Information Security Analyst, you’ll support governance, lead audits, and build security resilience across multiple jurisdictions.

What You’ll Be Doing
  1. Maintain and improve the ISMS, including policies, procedures, and guidelines
  2. Ensure ongoing ISO 27001:2022 alignment across UK and international offices
  3. Conduct internal audits, lead remediation efforts, and support third-party reviews
  4. Run supplier due diligence and respond to client risk assessments
  5. Investigate and escalate incidents, contributing to ongoing threat awareness
  6. Deliver awareness training and drive adoption of secure behaviours
What You’ll Bring
  1. Experience in information security or compliance-based roles
  2. Knowledge of ISO 27001, Cyber Essentials, NIST or similar frameworks
  3. Ability to communicate and collaborate across business functions
  4. Comfortable working in cloud and Microsoft 365 environments
  5. Certifications like CISMP, CISSP or ISO 27001 Lead Auditor are a bonus
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.