Jobs

Information Security Assurance and Compliance Specialist


Job details
  • Clyde & Co
  • Glasgow
  • 5 months ago

Key Responsibilities



Review proposed Client engagement contracts, SLAs and complete client due diligence questionnaires, audit requests and competitive bids, working to Client orientated deadlines. Maintain repository of standard information security responses and design effectiveness evidence for external audit, client assessments, client RFPs, etc Maintain and uphold the firm's certifications and Information Security Management System in line with the standard, facilitate such internal and external audit exercises plus ensure timely remediation for any identified non-conformance as is necessary to keep compliance with the ISO27001 certification. Assess and recommend information security, governance, risk management, and compliance services and working practices that reflect emerging Client expectations and best meet, develop and improve the firm's current and future information security environment. Assist the Information Security, IT and other departments with the identification and measurement of security risks and help identify appropriate controls. Carry out periodic assurance of controls to ascertain design effectiveness and maturity. Assist members of the team to carry out other workloads relating to the operation of the Information Security department during periods of higher demand, or where additional resources are required. Facilitate continual improvement by investigating and utilising latest technologies such as Artificial Intelligence/Machine Learning and other process methodologies to help transform the delivery of the services with a focus on greater efficiency and accuracy. Identify emerging Client implications and requirements for consideration into the firm's information security frameworks, strategy, roadmap, policies and into IT initiatives roadmap. Stay abreast of technical, industry, regulatory and company changes and/or trends as they relate to cyber security, the legal industry, information management, InfoSec, technological standards/trends and IT efficiencies. Facilitate/establish and report on monthly metrics and Key Performance/Risk Indicators relating to Client due diligence work. Provide education and insight to members of IT and other relevant areas, relating to the requirements and expectations of Clients. Build and maintain relationship with the team and relevant members of the Risk and Client Operations departments share best practice and ensure that due diligence activities are coordinated and executed efficiently.

Essential Skills and Experience

Proven experience of working in an Information Security and IT Risk Management role within a fast-paced environment. Experience within the legal industry is ideal, but not essential. Operational knowledge of one or more international information security standards, risk management and control frameworks/practices g. ISF SOGP, ISO27001/2, ISO31000, IRAM2, NIST 800-53 and cybersecurity framework. COBIT, CPS-234 etc. Strong organisational skills and the ability to handle multiple conflicting priorities. Able to work to very tight deadlines under pressure and to assimilate information quickly. Strong interpersonal skills including confidence, positivity, diplomacy, the ability to influence and persuade, maintain an open viewpoint, and to gain credibility quickly across the Firm and with Clients. Excellent verbal and written communication skills, with the ability to simplify technical points where required, and to present effectively to senior stakeholders and managers. Demonstrates attention to detail with a high level of accuracy. Positive and tenacious with the ability to pro-actively drive initiatives forward and motivate resources within and outside their team. Work with external teams where it is required, to comply with certification and due diligence requirements, exercising diligence and due consideration to their prevailing workloads.

Business Services Competencies

Clyde & Co is committed to providing extensive, personal, and professional development opportunities for our people enabling them to be highly effective in their current role as well as assisting them to fulfil their career aspirations.

The competencies are used to inform all aspects of Business Services career development. They vary across levels and different business areas and fall under the following areas:

Technical Excellence People and Team Client/Stakeholder Relationships Service Delivery and Commercial Awareness Personal Effectiveness

#LI-KH1

Sign up for our newsletter

The latest news, articles, and resources, sent to your inbox weekly.

Similar Jobs

Red Team Operator - Cloud

Description:Working in Cybersecurity takes pure passion for technology, speed, a constant desire to learn, and above all, vigilance in keeping every last asset safe and sound. You’ll be on the front lines of innovation, working with a highly-motivated team laser-focused on analyzing, designing, developing and delivering solutions built to stop...

JPMorgan Chase & Co. Glasgow

Red Team Operator - Cloud

Description:Working in Cybersecurity takes pure passion for technology, speed, a constant desire to learn, and above all, vigilance in keeping every last asset safe and sound. You’ll be on the front lines of innovation, working with a highly-motivated team laser-focused on analyzing, designing, developing and delivering solutions built to stop...

JPMorgan Chase & Co. London

Principal Enterprise Architect AppSec Vuln

Big Bank Funding. FinTech Thinking.Join a digital-first bank that’s powered by people. Our technology team builds innovative digital solutions rapidly and at scale to deliver the next generation of banking services for our customers around the world. Help shape the future of digital-first banking for our customers. We are currently...

HSBC Global Services Limited Sheffield

Database Administrator

DescriptionAbout NapierNapier’s mission is to become the recognized leader in ‘Intelligent Compliance’software for all regulated industries. We will achieve this through delivery of our best-in-class Anti-Money Laundering (AML) solutionContinuum. Napier is currently Great Place to Work 2022 certified and has been ranked in Best Workplace in Tech (small organisations) 2022. ...

Napier AI Belfast

Data Engineer

"Want to know what it means to care better? Then working with us is a great choice". Join us at Nourish and experience a workplace where care, impact, and fun all come together. Our PurposeNourish Care is a leading digital social care record company and is dedicated to harnessing data-driven...

Nourish Care Bournemouth

Senior Data Analyst

Contract Type:Full-time, PermanentLocation: Brighton - RemoteWe are seeking a Senior Data Analyst to offer analytics support to crucial business sectors, with a focus on delivering valuable management information and insights to a diverse range of internal and external stakeholders. Key to this position is the capacity to collaborate with stakeholders...

Study Group Brighton and Hove