×
Register Here to Apply for Jobs or Post Jobs. X

Information Security Analyst

Job in City Of London, Central London, Greater London, England, UK
Listing for: Howard Kennedy
Full Time position
Listed on 2026-08-30
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 55000 - 75000 GBP Yearly GBP 55000.00 75000.00 YEAR
Job Description & How to Apply Below
Location: City Of London

The role

We are seeking an Information Security Analyst to join our Cyber Security team. This is a varied and hands‑on role, offering an excellent opportunity for a motivated security professional to develop their career within a forward thinking professional services environment.

Working across technical security, risk and governance, compliance, and continuous improvement, you will gain broad exposure to all aspects of information security while supporting a business that places technology, security, and client trust at its core. As part of the Information Security function, you will play a key role in protecting the firm's information, systems, and digital services, helping to ensure legal services are delivered securely, reliably, and in line with regulatory, contractual, and client expectations.

Working closely with IT teams, Partners, lawyers, Business Services colleagues, suppliers, and security partners, you will help identify, assess, and manage risks, while providing practical security guidance that enables secure and productive ways of working.

The role spans security monitoring, incident response, vulnerability management, supplier assurance, compliance, reporting, and security awareness. You will contribute to the ongoing development of the firm's security capabilities, helping to strengthen controls, improve resilience, and support a strong culture of information security across the business.

Role responsibilityProtect
  • Operate, review, and improve security controls, risk treatment activity, and security processes within approved policies, standards, and change governance.
  • Assist with identity and access management, including joiners/movers/leavers processes, access review evidence, and approved privileged access activities.
  • Support vulnerability management by coordinating evidence, prioritising remediation by business context and consequence, and tracking issues to closure.
  • Support the implementation and operation of security technologies and upgrades in line with agreed standards.
  • Review technical designs, configurations, and change proposals to identify security risk.
  • Support the definition and implementation of security requirements for new systems and material changes.
  • Work with suppliers and managed service providers to keep operational controls effective.
Monitor & Respond
  • Monitor security and threat detection systems, investigate alerts, and identify trends that need a response.
  • Respond to security policy breaches and provide practical guidance on secure working practices.
  • Act as an escalation point for security queries from the Service Desk, IT, and Risk and Compliance teams, including DSAR evidence gathering where appropriate.
  • Support incident response activities including triage, investigation, containment, documentation, remediation tracking, and post-incident review.
  • Support business continuity and disaster recovery activity, helping restore protected services quickly after disruption.
  • Monitor emerging threats and vulnerabilities and recommend appropriate mitigations.
Advise
  • Maintain the information security risk register so it reflects current risks, controls, actions, and escalation requirements.
  • Support audits, client due diligence, ISO 27001 assurance, and governance reporting through evidence collation, metrics, and action tracking.
  • Support third-party risk management, including onboarding, questionnaires, contract evidence, and ongoing supplier assurance.
  • Work with the Data Protection Officer on data protection incidents and assessments in line with UK GDPR, the Data Protection Act 2018, and SRA expectations where applicable.
  • Produce clear reports for technical and non-technical stakeholders.
  • Assist with the creation and delivery of cyber security awareness and training for colleagues.
About you

Ideally you will be able to demonstrate;

  • Experience in an information or cyber security role covering protection, monitoring, response, and advisory work; law firm or professional services experience is desirable.
  • Comfort and experience operating with real autonomy and ownership, ideally within a small or lean security team rather than a large structure.
  • Broad technical knowledge across networking, systems administration, infrastructure, applications, and security, with the ability to challenge designs and identify real risk.
  • Hands‑on experience with common security technologies and controls (e.g. endpoint protection, email/web security, firewalls, IDS/IPS).
  • Good working knowledge of Microsoft platforms and security capabilities.
  • Sound understanding of information risk, with the ability to assess conditions and consequences rather than rely solely on generic severity ratings.
  • Knowledge of relevant standards, good practice, and regulatory requirements, including UK GDPR and the Data Protection Act 2018.
  • Strong analytical skills with the ability to translate business requirements into proportionate security controls.
  • Excellent written and verbal communication skills, with the ability to engage both technical and…
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary