Information Security Assurance and Compliance Specialist

1 month ago


Glasgow, Glasgow City, United Kingdom Change Digital – Digital & Tech Recruitment Full time £65,000

Information Security Assurance and Compliance Specialist

This is an exciting opportunity to join a leading global law firm in the UK as an Information Security Assurance and Compliance Specialist. The successful candidate will be primarily supporting the team's mission by focusing on internal and client-related security governance, compliance, audit, due diligence, and management of risk.

The role will require the candidate to work as part of the team that manages overall information security assurance and compliance, maintaining an information security management system (ISMS), responding to client-driven information security questions, due diligence, and audit requests in a timely manner, represent the firm in external audit, and carries out internal audit and controls assurance.

Key Responsibilities:

  • Review proposed client engagement contracts, SLAs, and complete client due diligence questionnaires, audit requests, and competitive bids, working to client-oriented deadlines.
  • Maintain a repository of standard information security responses and design effectiveness evidence for external audit, client assessments, client RFPs, etc.
  • Maintain and uphold the firm's certifications and Information Security Management System in line with the standard, facilitate such internal and external audit exercises, and ensure timely remediation for any identified non-conformance as is necessary to keep compliance with the ISO 27001 certification.
  • Assess and recommend information security, governance, risk management, and compliance services and working practices that reflect emerging client expectations and best meet, develop, and improve the firm's current and future information security environment.
  • Carry out periodic assurance of controls to ascertain design effectiveness and maturity.
  • Assist members of the team to carry out other workloads relating to the operation of the Information Security department during periods of higher demand or where additional resources are required.
  • Facilitate continual improvement by investigating and utilizing the latest technologies, such as Artificial Intelligence/Machine Learning, and other process methodologies to help transform the delivery of services with a focus on greater efficiency and accuracy.
  • Identify emerging client implications and requirements for consideration into the firm's information security frameworks, strategy, roadmap, policies, and into IT initiatives roadmap.
  • Stay abreast of technical, industry, regulatory, and company changes and/or trends as they relate to cybersecurity, the legal industry, information management, InfoSec, technological standards/trends, and IT efficiencies.
  • Facilitate/establish and report on monthly metrics and Key Performance/Risk Indicators relating to client due diligence work.
  • Provide education and insight to members of IT and other relevant areas, relating to the requirements and expectations of clients.
  • Build and maintain relationships with the team and relevant members of the Risk and Client Operations departments, share best practice, and ensure that due diligence activities are coordinated and executed efficiently.

Essential Skills and Experience:

  • Proven experience of working in an Information Security and IT Risk Management role within a fast-paced environment. Experience within the legal industry is ideal, but not essential.
  • Operational knowledge of one or more international information security standards, risk management, and control frameworks/practices, e.g., ISF SOGP, ISO 27001/2, ISO 31000, IRAM 2, NIST 800-53, and cybersecurity framework. COBIT, CPS-234, etc.
  • Strong organizational skills and the ability to handle multiple conflicting priorities.
  • Able to work to very tight deadlines under pressure and to assimilate information quickly.
  • Strong interpersonal skills, including confidence, positivity, diplomacy, the ability to influence and persuade, maintain an open viewpoint, and to gain credibility quickly across the firm and with clients.
  • Excellent verbal and written communication skills, with the ability to simplify technical points where required, and to present effectively to senior stakeholders and managers.
  • Demonstrates attention to detail with a high level of accuracy.
  • Positive and tenacious with the ability to proactively drive initiatives forward and motivate resources within and outside their team.


  • Glasgow, Glasgow City, United Kingdom Clyde & Co Full time

    Job SummaryClyde & Co is seeking a highly skilled Information Security Assurance and Compliance Specialist to join our team. As a key member of our Information Security department, you will be responsible for ensuring the firm's information security management system is in line with industry standards and regulations.Key ResponsibilitiesReview and assess...


  • Glasgow, Glasgow City, United Kingdom Clyde & Co Full time

    Job SummaryClyde & Co is seeking an experienced Information Security Assurance and Compliance Specialist to join our team. As a key member of our Information Security department, you will be responsible for ensuring the firm's information security management system is compliant with industry standards and regulations.Key ResponsibilitiesReview and assess...


  • Glasgow, Glasgow City, United Kingdom Change Digital – Digital & Tech Recruitment Full time £65,000

    Job Title: Information Security Compliance SpecialistJob Summary:We are seeking an experienced Information Security Compliance Specialist to join our team at Change Digital – Digital & Tech Recruitment. As a key member of our Information Security department, you will play a crucial role in ensuring the firm's compliance with international information...


  • Glasgow, Glasgow City, United Kingdom CLYDE UK SERVICES COMPANY Full time

    Information Security and Compliance SpecialistLocation: Glasgow.Job type: Full time - Permanent.Working: Hybrid - 2 days in the office per week.Hours: 09:00-17:00.The RoleThe mission of the firm's Information Security and Risk team is to establish a risk-managed environment that enables the firm to adequately and reasonably protect the confidentiality,...


  • Glasgow, Glasgow City, United Kingdom Change Digital – Digital & Tech Recruitment Full time £65,000

    Job Title: Information Security Compliance SpecialistAbout the Role:We are seeking an experienced Information Security Compliance Specialist to join our team at Change Digital – Digital & Tech Recruitment. As a key member of our Information Security department, you will play a vital role in ensuring the firm's information security management system (ISMS)...


  • Glasgow, Glasgow City, United Kingdom Orion Engineering Services Full time

    Job Title: Information Security Governance SpecialistDescription:Aberdeen-based position at Orion Engineering Services is seeking an experienced Information Security Governance Specialist to support global IS governance activities. The ideal candidate will have significant experience in implementing, managing, reviewing, and improving internal controls for...


  • Glasgow, Glasgow City, United Kingdom Clyde & Co Full time

    Clyde & Co is a leading international law firm seeking an experienced Information Security Assurance and Compliance Specialist to join our team.Job SummaryThis role will involve reviewing proposed client engagement contracts, SLAs, and completing client due diligence questionnaires, audit requests, and competitive bids. You will also maintain a repository of...


  • Glasgow, Glasgow City, United Kingdom https:www.energyjobline.comsitemap Full time

    Cyber Security Assurance and Compliance LeadAbout the RoleWe are seeking a highly skilled Cyber Security Assurance and Compliance Lead to join our team at ScottishPower. As a key member of our Cyber Security team, you will be responsible for defining, implementing, and managing the Cyber Security Assurance Model and tracking the Regulatory Compliance posture...


  • Glasgow, Glasgow City, United Kingdom ScottishPower Full time

    Cyber Security Assurance and Compliance RoleAbout the RoleWe are seeking a skilled Cyber Security Assurance and Compliance professional to join our team at ScottishPower. This is an exciting opportunity to contribute to the development and implementation of our Cyber Security Assurance Model and to track our Regulatory Compliance posture.Key...


  • Glasgow, Glasgow City, United Kingdom Iberdrola Full time

    Cyber Security Assurance and Compliance LeadAbout the RoleThis is an exciting opportunity to join ScottishPower as a Cyber Security Assurance and Compliance Lead. As a key member of our team, you will play a critical role in defining, implementing, and managing the Cyber Security Assurance Model and tracking the Regulatory Compliance posture across...


  • Glasgow, Glasgow City, United Kingdom Clyde & Co Full time

    Job OverviewClyde & Co is seeking a seasoned Cybersecurity Assurance and Compliance Specialist to join our team. In this critical role, you will be responsible for ensuring the firm's information security management system meets international standards.About YouWe are looking for an individual with extensive experience in Information Security and IT Risk...


  • Glasgow, Glasgow City, United Kingdom Morris & Spottiswood Ltd Full time

    Job DescriptionThe Security Compliance Specialist will play a critical role in ensuring that Morris & Spottiswood Ltd complies with our client's security vetting and compliance requirements. This involves coordinating and conducting thorough security checks, managing employee, worker and supply chain information in an accurate, timely and confidential...


  • Glasgow, Glasgow City, United Kingdom ScottishPower Full time

    Cyber Security Assurance and Compliance LeadLocation: GlasgowSalary: £54-£68K, plus benefits (15% bonus & healthcare)Hybrid workingHelp us create a better future, quicker.ScottishPower is embarking on a Cyber Security Transformation Programme. We're looking for a Cyber Assurance and Compliance Lead to help define, implement, and manage the Cyber Security...

  • Security Specialist

    4 days ago


    Glasgow, Glasgow City, United Kingdom Securitas Security Services Full time

    Are you a highly organized and detail-oriented individual with a passion for security and risk management? Do you have excellent communication skills and the ability to work independently? We are seeking a talented Security Controller to join our team at Securitas Security Services.About the RoleThis is a challenging and rewarding opportunity to provide...


  • Glasgow, Glasgow City, United Kingdom Glasgow Caledonian University Full time

    Job DescriptionGlasgow Caledonian University is seeking a highly skilled Information Security Specialist to join its team. The successful candidate will play a key role in building and enhancing the information security landscape and culture within the University.Key Responsibilities:Incident response and managementRisk assessment and mitigationVulnerability...


  • Glasgow, Glasgow City, United Kingdom Clyde & Co Full time

    Key Responsibilities Clyde & Co is seeking an experienced professional to lead our Cybersecurity Assurance and Compliance team. As a key member of our Business Services team, you will be responsible for ensuring that our clients receive the highest level of security and compliance services. Key responsibilities include: Reviewing proposed client...


  • Glasgow, Glasgow City, United Kingdom EnerMech Full time

    EnerMech is recruiting for an Information Assurance Manager to develop and implement effective information security strategies across the business.The successful candidate will be responsible for managing the organisation's risk posture and developing a comprehensive information security program. They will work closely with the Infrastructure team to design...


  • Glasgow, Glasgow City, United Kingdom Scottish Power Full time

    Cyber Security Transformation ProgrammeScottish Power is embarking on a Cyber Security Transformation Programme to enhance our cyber security posture. We're seeking a Cyber Assurance and Compliance Lead to help define, implement, and manage the Cyber Security Assurance Model and track the Regulatory Compliance posture across ScottishPower.The role will lead...


  • Glasgow, Glasgow City, United Kingdom Three Full time

    About the RoleAt Three, we're looking for a Quality Assurance Compliance Specialist to join our team. This role plays a vital part in ensuring that our Contact Centre and Retail teams are meeting regulatory requirements when interacting with our customers.Key Responsibilities:Conduct monthly audits on customer interactions using the FCA Compliance Framework...


  • Glasgow, Glasgow City, United Kingdom iberdrola Full time

    Role OverviewWe are seeking an experienced Information Security Technical Lead to join our team at Iberdrola. This role will be responsible for leading the technical aspects of information security across various disciplines, including architecture, networking, and application development.About the JobThis is a permanent, full-time position with a salary...