Head of Cyber Security & Infrastructure – International Law firm, London, City
Salary 90-100k + Excellent Benefits
London City Law firm have a fantastic opening for a Head Of Cyber Security & Infrastructure.
Duties & Responsibilities
Provide leadership the Cyber Security and Infrastructure teams in the course of delivering IT services in support of the firm’s business strategy.
Develop security and infrastructure strategies commensurate with business needs.
Maintain the cyber security framework, providing ongoing analysis of emerging threats, risks and control gaps.
Define and steer the Cyber Security programme to implement technical security solutions and controls aligned to industry best practice and the emerging threat landscape.
Advise on information security at appropriate risk oversight committees and boards.
Collaborate with the wider IT department, in the development, implementation and ongoing assessment of security policies, procedures and standards across the Firm’s IT estate and business.
Provide information security and infrastructure requirements to IT projects and ensure their appropriate implementation.
Act as 1st line of defence for information security, partnering with and providing challenge, support and advice to the business and IT teams to identify and manage the mitigation of security risks.
Collaborate with IT and business peers to manage security vulnerabilities, events or investigations.
Act as control and process owner for security incident management and response. Work closely with key stakeholders to ensure incident response plans are up to date and are effectively tested, including facilitation of tabletop exercises to simulate incident response.
Manage relationships and oversee the day-to-day activities of security and infrastructure outsourced suppliers.
Participate in internal security assessments, internal audits, client audits, compliance certifications, third-party risk management and client security questionnaire responses.
Manage an Cyber Security team in support of IT security operations and the delivery of IT security solutions to the business.
Progress the professional development of the security and infrastructure teams to ensure they remain current in trends, techniques and technologies.
Key Skills & Experience Required
At least 5 years relevant experience in a law firm or comparable organisation operating in a regulated environment.
Technical certifications such as CISM, CISSP.
Proven experience of working with IT security systems and information security governance, i.e., control frameworks, incident management, operations and application of security best-practices.
Experience of security engineering, in support of technologies and controls such as Network and Application firewalls, IDS/IPS, Web Proxy, Vulnerability Scanners, Microsoft Active Directory services, Security Service Edge (SSE), Endpoint Protection and Encryption technologies.
Strong analytical and problem-solving skills and can interpret and apply complex technical information and is able to explain security functionality to other members of the business.
Solid management experience working to support the development and direction of both directly employed and third party employed IT security professionals.