About this role
Salary: £38,000 - 48,000 per year
Requirements: Understanding of information security governance, risk and compliance principles.Knowledge of ISO 27001 or other recognised information security frameworks.Some experience within Information Security, GRC, Risk, Compliance or a related area.Exposure to audits, compliance reviews or governance processes would be beneficial.Understanding of supplier assurance or third-party risk management would be advantageous.Experience producing reports, dashboards or management information.Proficiency in Microsoft Office, particularly Excel, Word and PowerPoint.Relevant information security or GRC qualifications, such as ISO 27001 Foundation or CISM, would be advantageous. Responsibilities: Support the administration and continual improvement of the Information Security Management System (ISMS).Assist with ISO 27001 certification, surveillance and internal audit activities.Coordinate audit evidence collection and track remediation actions.Maintain information security policies, procedures, standards and governance documentation.Support information security risk assessments, treatment plans and exception tracking.Coordinate client security due diligence questionnaires and assurance requests.Support supplier assurance and third-party risk assessments.Produce information security metrics, dashboards and management reporting.Support security awareness, communications and training activities. Technologies: ExcelSupportSecurity More:
We are a London-based law firm offering a hybrid working pattern and a salary of £38,000-£48,000 for this Information Security GRC Analyst role. This is an excellent opportunity for someone at the early stages of their GRC career to build practical experience within a professional services environment, with exposure to ISO 27001, information security risk, compliance and assurance. You will join our Risk and Information Security team and contribute to our information security governance and assurance activities.
last updated 32 week of 2026