Information Security Assurance Specialist
We are partnering with a prestigious international law firm to hire an Information Security Assurance Specialist to join its Information Security and Privacy team within the wider Legal, Risk, and Compliance function, based in London.
This is a newly created role reporting to the Information Security Manager, focused on strengthening the firm’s security posture. The role sits firmly in the second line of defence, with an emphasis on governance, policy, and assurance rather than day‑to‑day operations.
The core focus is security assurance testing, particularly penetration testing. You will ensure testing is appropriately scoped, meaningful, and followed through to resolution. You will also embed security assurance into IT projects and change initiatives by defining security requirements, reviewing designs, and working with technical teams to mitigate security risks arising from change.
A key aspect of the role is early engagement with projects. You’ll partner with architects, business analysts, and DevOps teams to challenge designs and influence security outcomes from the outset. The role requires strong technical understanding, without hands‑on engineering.
Key responsibilities include:
- Supporting architecture and design reviews
- Ensuring systems align with InfoSec policies and standards
- Helping evolve assurance frameworks as new technologies are adopted
- Supporting ISO 27001 certification and policy development
This is a strategic role with a broad, firm‑wide view rather than ownership of a single product or platform.
Required experience:
- 4+ years’ experience in information security or technical cyber security
- Strong knowledge of ISO 27001 and Cyber Essentials Plus (auditor or implementer experience desirable)
- Experience in regulated or private‑sector environments (law firm experience advantageous; FS/banking backgrounds welcome)
- Understanding of Lines of Defence models and second‑line assurance roles
Please note our advertisements use PQE/salary levels purely as a guide. However we are happy to consider applications from all candidates who are able to demonstrate the skills necessary to fulfil the role.
Please note that your personal information will be treated in accordance with our Privacy Policy.

