Description:
An excellent opportunity has arisen for a Junior Information Security Analyst to join a Law Firm. This role is ideal for someone looking to build a career within Information Security Governance, Risk & Compliance (GRC), gaining exposure to ISO 27001, risk management, supplier assurance, audit activities and information security best practices.
The Role
Working as part of the Information Security and Risk & Compliance function, you will support the maintenance and continual improvement of the Information Security Management System (ISMS), helping to ensure compliance with regulatory, client and information security requirements.
Key Responsibilities
- Support the administration and continual improvement of the Information Security Management System (ISMS).
- Assist with ISO 27001 certification, surveillance and internal audit activities.
- Coordinate audit evidence gathering and support remediation tracking.
- Maintain information security policies, standards, procedures and supporting documentation.
- Support information security risk management, treatment plans and exception registers.
- Manage client information security questionnaires and assurance requests.
- Support third-party supplier assurance and risk assessment activities.
- Produce information security metrics, dashboards and management reporting.
- Assist with security awareness, communications and training initiatives.
- Maintain governance documentation, registers and tracking mechanisms.
Skills & Experience
- At least 1-2yrs experience in a similar role.
- Understanding of information security, risk and governance principles.
- Strong organisational, analytical and communication skills with excellent attention to detail.
- Ability to manage multiple priorities and build effective stakeholder relationships.
- Proficient in Microsoft Office applications.
- Exposure to ISO 27001, audits, compliance, supplier assurance or third-party risk management would be advantageous.
- Self-motivated and eager to develop a career in Information Security GRC.