Vacancy No
VN1200
Location
London
Employment Type
Perm
Basis
Full Time
Fixed Term Duration
Overview
Join Chambers as our next Cyber Security Analyst/Lead, a pivotal role at the heart of our commitment to safeguarding information and maintaining trust. A hands-on role, you’ll lead the development and delivery of our information security programme, protecting our systems, data, and digital assets from evolving threats. This is an exciting opportunity to drive key security initiatives, oversee cutting-edge technologies, and ensure compliance with leading industry frameworks within a globally respected organisation. This is a hybrid role, with two days a week expected in the London office.
Main Duties and Responsibilities
- Develop, implement, and maintain the organisation's information security strategy, policies, standards, and procedures in alignment with business objectives and regulatory requirements.
- Lead the development and implementation of an Information Security Management System (ISMS), based on ISO 27001
- Conduct regular security risk assessments, identify vulnerabilities, and recommend appropriate mitigation strategies.
- Provide expert advice and guidance on information security matters to various stakeholders across the organisation.
- Oversee the day-to-day operation of security systems and tools, including firewalls, intrusion detection/prevention systems (IDS/IPS), antivirus, anti-malware, SIEM (Security Information and Event Management), vulnerability scanners, and data encryption solutions.
- Manage vulnerability management programs, including regular scanning, penetration testing, and remediation of identified weaknesses.
- Lead and manage security incident response, including detection, analysis, containment, eradication, recovery, and post-incident review.
- Develop and maintain robust disaster recovery and business continuity plans related to information security.
- Monitor security alerts, logs, and reports for suspicious activity and potential threats.
- Ensure the organization's adherence to relevant information security regulations, laws, and industry standards (e.g. HIPAA, PCI DSS, NIST, CIS, ISO 27001, Cyber Essentials+).
- Coordinate and participate in internal and external security audits, provide evidence, and ensure timely remediation of audit findings.
- Develop and implement security awareness training programs for all employees to foster a security-conscious culture.
- Collaborate with IT Operations and Infrastructure teams to ensure security is embedded in the design, implementation, and maintenance of all IT infrastructure, including cloud environments (e.g., Azure, AWS, GCP), networks, servers, and endpoints.
- Manage access controls, identity management (e.g., Entra ID/Azure AD), and privileged access management (PAM) systems.