Information Security Lead

Company: Charles Russell Speechlys LLP
Apply for the Information Security Lead
Location: London
Job Description:

To act as the senior deputy to the Head of Information Security, providing strategic leadership, governance oversight, and operational assurance across the Information Security function. This role deputises in the absence of the Head of Information Security and leads the firm’s security governance, regulatory compliance, and executive reporting activities.

Strategic & Governance Leadership

  • Deputise for the Head of Information Security at ITLT, OpCom, RiskCom and Advisory Board as required.
  • Define, maintain and mature the Information Security Strategy aligned to Technology Directorate and firm objectives.
  • Establish governance mechanisms to ensure effective security oversight.
  • Own annual review and update of Information Security Terms of Reference.
  • Ensure security roles, responsibilities and training plans are defined and maintained.

Regulatory & Policy Oversight

  • Own the Information Security Policy framework and supporting standards.
  • Ensure mapping of regulatory and industry standards (e.g. GDPR, ISO 27001) to firm policies.
  • Oversee annual policy attestation and compliance reporting.
  • Lead audit readiness and regulatory engagement.
  • Ensure all information security risks are documented, escalated and managed appropriately.
  • Oversee third‑party security assessment programme (regulatory and client‑driven).
  • Provide executive‑level reporting on security posture, risk exposure and compliance status.
  • Maintain evidence framework demonstrating compliance and traceability.
  • Support management of Information Security budget.
  • Oversee business case development for security initiatives.
  • Manage programme demand and prioritisation across the InfoSec portfolio.

Other

Comply with all relevant legal and regulatory obligations including the Solicitors Regulation Authority (SRA) Standards and Regulations, and Principles.

Person Specification

  • 8–12+ years in Information Security, with governance leadership experience.
  • Strong knowledge of ISO 27001, GDPR, law firm or regulated professional services environment preferred.
  • Experience presenting to executive committees.
  • Strong commercial and financial awareness.
  • Ability to operate at both strategic and tactical levels.

Hybrid working – We adopt a hybrid and flexible working approach, dependent on the requirements of the role and subject to manager approval.

#J-18808-Ljbffr…

Posted: June 1st, 2026