Point your AI agent at freehire and let it find you a job.

Get the CLI →

DAC Beachcroft

NewBe an early applicant

Chief Information Security Officer (CISO)

Posted
Discussion

Summary

DAC Beachcroft, a UK law firm, is hiring a Chief Information Security Officer to own the information security strategy, cyber incident response (with MSSPs), and regulatory compliance (GDPR, UK GDPR, SRA). The role covers risk management, vendor security reviews, and security controls, with a focus on Microsoft Azure environments.

Are you an experienced information security leader looking to make a real impact? We're seeking a Chief Information Security Officer (CISO) to take ownership of our information security strategy, regulatory compliance, and cyber resilience framework.

As CISO, you will play a pivotal role in protecting sensitive client data, legal case information, and financial records while ensuring compliance with GDPR, SRA requirements, and broader regulatory obligations. This is a strategic leadership position offering the opportunity to shape and mature our security posture across the organisation.

About the Role

Working closely with the Chief Technology Officer and senior leadership team, you will develop and implement a comprehensive security strategy that protects the business from evolving cyber threats while maintaining regulatory compliance and client trust.

You will act as the organisation's subject matter expert for information security, data protection, risk management, and incident response.

  • Develop and own the organisation's information security strategy, roadmap, and risk management framework.
  • Working with our MSSP, lead the response to security incidents, coordinating investigations, remediation activities, and stakeholder communications.
  • Working with our Group Legal and colleagues, implement effective risk and compliance governance to ensure GDPR and data protection compliance, including DPIAs, data processing agreements, and data subject requests.
  • Ensure compliance with Solicitors Regulation Authority (SRA) requirements and relevant information security standards.
  • Manage third-party security assessments and vendor risk reviews, including technology, finance, and AI solution providers.
  • Establish and maintain security controls covering data classification, access management, encryption, monitoring, and logging.
  • Drive a culture of security awareness through training, education, and incident response exercises.
  • Manage relationships with external Managed Security Service Providers (MSSPs) to ensure effective service delivery and governance.
  • Provide clear, business-focused reporting on security risks to executive leadership and regulators where required.

  • Significant experience in information security, including leadership experience at CISO, Head of Security, or equivalent level.
  • Strong knowledge of GDPR, UK GDPR, the Data Protection Act 2018, and wider UK regulatory requirements.
  • Experience operating within highly regulated environments.
  • Proven experience in cyber incident response, breach management, and digital forensics.
  • Strong understanding of the latest information security technologies and best practice deployment, particularly within Microsoft Azure environments.
  • Excellent communication and stakeholder management skills with the ability to translate technical risks into business language.
  • Experience developing security strategies, policies, and governance frameworks.

  • High levels of flexibility and a great work life balance - https://www.dacbeachcroft.com/en/Work-with-us/Whats-in-it-for-you
  • A well-rounded remuneration package (which includes private medical insurance, income protection insurance and discounted gym membership, amongst many other benefits)
  • Opportunities for growth and progression including professional funding
  • In person and remote social events
  • Opportunity to get involved in a range of Environmental, Social and Governance (ESG) activities
We are dedicated to building a diverse, inclusive and authentic workplace, which aligns closely to our cultural principles (Determined, Clear, Creative and Supportive). If you are excited about this role and being part of our culture, but your past experience does not align perfectly with every qualification in the job description, we encourage you to apply anyway. You may be just the right candidate for this or other roles!

Skills

What C-level Security jobs ask for — and how much of it you have →

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available