Information Security Manager
Date: 6 Feb 2025
Location: London, GB, EC3M 7AF
Company: Walkers Global
We are a leading international law and professional services firm providing legal, corporate and fiduciary services to global corporations, financial institutions, capital market participants and investment fund managers. With a global presence spanning the Americas, Europe, the Middle East and Asia, we advise on the laws of Bermuda, the British Virgin Islands, the Cayman Islands, Guernsey, Ireland and Jersey.
We treat everyone as the intelligent professional they are. Our approach is to trust and empower our people to deliver consistently, and enable them to succeed. Diversity is our secret weapon – it’s the sheer breadth of Walkers people that makes us who we are – gathered from across the globe and fluent in languages, jurisdictions and cultures that help us to mirror our clients and keep our own thinking in tune with the world in which we operate.
Overview of role
OFFICE: LONDON (HYBRID)
The Information Security Manager will be responsible for the management of the Information Security Management System (ISMS) across Walkers globally. This covers a broad range of information security activities including policy development, risk management, incident management and forensics, internal and external audit and compliance. It will involve communication with senior management across all regions, liaising with internal teams, management of third parties and development of the firm’s security capabilities to meet the changing needs of clients.
Duties, Responsibilities & Person Specification
ISMS Management
- Communicate to senior management on risks and requirements
- Understand business objectives and support development of budget for information security objectives
- Develop and maintain security compliance program
Provide support where necessary to local offices to update and maintain country specific IS documentation
- Establish security metrics to assess effectiveness
Coordinate and maintain the management review process
Make written and oral reports to ISSC
Manage internal and external audits and certifications
Manage third party providers including security consultants and assessors
- Client InfoSec relationship
Support any client compliance activities including security assessments
- Supplier Management
Manage supplier review process and provide support to local teams
- Security Awareness
Ownership of the Security Awareness Program and support of Security Culture Change
- Improvement management
Manage identified improvements through to completion
- Penetration Test management
Organize and manage system penetration testing
- Policy
- Develop, maintain and publish security strategies, policies and procedures
- Manage security policy and implementation
Support global IT departments on implementation of security policy and products
Education, Skills & Experience
Must-Have Knowledge, Skills and Experience:
- Proven experience in assessing information security risk and developing an ISMS.
- Experience of ISO 27001/2.
- Experience of risk frameworks such as ISO 27005/31000.
- Strong written, oral and presentation communication skills.
Desirable Knowledge, Skills and Experience:
- Knowledge of applicable data privacy practices and laws.
- Demonstrable experience in a similar role.
- ISO 27001 Lead Implementer / Lead Auditor certification.
- CISSP and CISM or equivalent certifications
Please note, although based from the London office, this opportunity requires a degree of international business travel. This could include potentially 5-10 visits to our other offices each year.
#LI-Hybrid
#LI-LQ1
Walkers global is an equal opportunity employer. Equality and diversity are key to our global identity and an integral part of our goal to continue being an employer of choice. We are committed to a work environment that supports all individuals irrespective of gender, ethnicity, nationality, race, religion, marital status, age, disability, pregnancy, sexual orientation, gender identity or any other applicable legally protected characteristics. We make every effort to ensure that employment opportunities are open and accessible to all purely on the basis of personal ability.