Chief Information Security Officer (CISO)
Summary
DAC Beachcroft, a UK law firm, is hiring a Chief Information Security Officer to own the information security strategy, cyber incident response (with MSSPs), and regulatory compliance (GDPR, UK GDPR, SRA). The role covers risk management, vendor security reviews, and security controls, with a focus on Microsoft Azure environments.
- Develop and own the organisation's information security strategy, roadmap, and risk management framework.
- Working with our MSSP, lead the response to security incidents, coordinating investigations, remediation activities, and stakeholder communications.
- Working with our Group Legal and colleagues, implement effective risk and compliance governance to ensure GDPR and data protection compliance, including DPIAs, data processing agreements, and data subject requests.
- Ensure compliance with Solicitors Regulation Authority (SRA) requirements and relevant information security standards.
- Manage third-party security assessments and vendor risk reviews, including technology, finance, and AI solution providers.
- Establish and maintain security controls covering data classification, access management, encryption, monitoring, and logging.
- Drive a culture of security awareness through training, education, and incident response exercises.
- Manage relationships with external Managed Security Service Providers (MSSPs) to ensure effective service delivery and governance.
- Provide clear, business-focused reporting on security risks to executive leadership and regulators where required.
- Significant experience in information security, including leadership experience at CISO, Head of Security, or equivalent level.
- Strong knowledge of GDPR, UK GDPR, the Data Protection Act 2018, and wider UK regulatory requirements.
- Experience operating within highly regulated environments.
- Proven experience in cyber incident response, breach management, and digital forensics.
- Strong understanding of the latest information security technologies and best practice deployment, particularly within Microsoft Azure environments.
- Excellent communication and stakeholder management skills with the ability to translate technical risks into business language.
- Experience developing security strategies, policies, and governance frameworks.
- High levels of flexibility and a great work life balance - https://www.dacbeachcroft.com/en/Work-with-us/Whats-in-it-for-you
- A well-rounded remuneration package (which includes private medical insurance, income protection insurance and discounted gym membership, amongst many other benefits)
- Opportunities for growth and progression including professional funding
- In person and remote social events
- Opportunity to get involved in a range of Environmental, Social and Governance (ESG) activities
