Information Security Manager; maternity cover
Listed on 2026-08-29
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Location: City Of London
Role Purpose
Legatics handles some of the world's most complex and confidential legal transactions, so information security is core to the product and to client trust. The Information Security Manager owns information security across Legatics - setting the vision and strategy, maintaining our ISO 27001 certified ISMS, working hand-in-hand with engineering to embed security into our client-facing products, and acting as the security point of contact for our clients and business teams.
Reporting to the Head of Engineering, the role spans technical security, compliance and governance, client assurance, and the day-to-day operation of our security and IT tooling. It is a broad, hands-on role with a high degree of autonomy to shape direction as Legatics scales.
This is a fixed-term appointment covering a period of maternity leave. The expected duration is approximately 12 months from the start date, although the actual end date will depend on the return date of the current postholder and may fall slightly earlier or later. You will have full ownership of the remit set out below for the duration of the contract, with the same autonomy, access and support as a permanent member of the team.
AboutLegatics
Legatics is one of the world's leading Legal Tech scale-ups. Our legal transaction management platform enables law firms and their clients to collaborate on and close deals in an interactive online environment, providing clarity, reducing risk and saving time.
Our customers include some of the world's top law firms, such as Allen & Overy Shearman, Hogan Lovells, Herbert Smith Freehills, and King & Wood Mallesons. And we've been used on transactions in more than 60 countries on transactions worth over $1 trillion.
The contractThis role is offered on a fixed-term basis to provide cover during a colleague's maternity leave, with an anticipated duration of around 12 months.
A few things worth knowing:
- You will be employed on the same terms and benefits as our permanent employees, including private medical insurance, health cash plan and pension.
- The contract may be extended if the period of cover changes, and we will always give you as much notice as we can of the confirmed end date.
- Where a suitable permanent role exists at the end of the contract, we will discuss it with you. We are being deliberate in not promising this, because we would rather be straight with you than imply something we cannot guarantee.
- Fixed-term does not mean holding the fort. We are looking for someone who will genuinely own and advance our security posture during their time here, and we expect the work you do to outlast the contract.
Security strategy, posture and governance
- Own the vision, direction and roadmap for information security at Legatics, and continue developing the overall security posture, processes, systems and controls.
- Maintain up-to-date knowledge of the threat landscape, emerging best practice and tooling, and translate this into Legatics' security priorities.
- Develop and run a strategy for continuous security and resilience testing - for example penetration testing, red-team exercises and threat modelling (such as self-hosted Git Lab versus consumed SaaS).
- Build relationships with relevant industry bodies and security peers at similar organisations.
- Own ISO 27001 certification and the Information Security Management System (ISMS), including ongoing maintenance and continuous audit readiness; align the ISMS to ISO 27001:2022.
- Maintain the Master Document List, version control and approvals across all policies, and keep ISO documentation tracked in a central system (e.g. the Notion ISO database).
- Finalise and maintain the Statement of Applicability (SoA), and keep the ISMS Manual current.
- Review and maintain core policies - including the Acceptable Use Policy, Access Control Policy, and Incident Response & Breach procedure - and keep the ISMS Risk Register up to date.
- Document and operate the threat intelligence process; maintain the Interested Parties register and the analysis of internal/external issues (PESTLE).
- Produce and maintain the ISMS Communication Plan and…
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: