Information Security Manager
Summary
Leads and implements Plesner’s information security framework, ensuring compliance with standards like ISO 27001, manages risk reporting, and develops security awareness programs while collaborating with IT and legal teams.
Are you Plesner's new Information Security Manager?
Information security is high on the agenda, and we are looking for an Information Security Manager to lead and embed our information security efforts across the organisation.
About the role
You will be based in our Risk Management & Compliance team while also working closely with the IT team.
The IT team owns the technical security architecture and operational IT security. Your responsibility will be to establish, maintain and continuously develop Plesner's framework for effective information security. The framework will be based on a recognised standard that you will help select and implement.
A key part of your role will be to identify security-related procedures and to document and implement agreed adjustments and new initiatives. You will recognise when existing procedures need to be reassessed and updated, and you will ensure that the changes are fully implemented.
As part of the Risk Management & Compliance team, you will contribute to the ongoing operation and development of the team's responsibilities. Our objective is to establish and maintain effective compliance procedures in close dialogue with the rest of the organisation.
Together with the client-facing departments, we work purposefully to maintain the right balance between the business's need to act quickly and efficiently in its day-to-day operations and the restrictions that are a natural consequence of complying with the guidelines and requirements imposed on the organisation by management, clients and authorities in the area of compliance.
Your responsibilities will include:
Information security
Lead the work to define, design and implement a standardised framework for Plesner's continued information security efforts, in close collaboration with the IT team
Ensure that Plesner reaches a level of information security that enables the organisation to decide whether to pursue formal certification
Maintain Plesner's information security framework so that the achieved certification level is sustained
Coordinate responses to client compliance questionnaires, with direct responsibility for the sections concerning Plesner's level of information security
Conduct security reviews of new and existing suppliers and business partners
Be responsible for the information security component of the GRC system
Business continuity and emergency preparedness
Develop and maintain Plesner's business continuity and emergency response plan, and plan and conduct at least one annual test of the organisation's preparedness
Take responsibility for the organisational and compliance-related management of, and follow-up on, information security incidents
Risk management and management reporting
Assist in identifying Plesner's risks and establish and maintain ongoing reporting to management on Plesner's information security level
Security culture and awareness
Develop and maintain Plesner's information security awareness programme, including training, guidance and campaigns
Ensure that information security forms part of the onboarding of new employees
Measure the effectiveness of awareness activities and continuously adjust them in response to the threat landscape and identified incidents
AI governance
Draft and maintain guidelines and policies for the responsible use of AI at Plesner
Ensure the documented, compliant and secure use of AI in accordance with applicable requirements, in close collaboration with the IT team
Monitor compliance with the guidelines and advise the organisation on AI-related risks
About you
You are open and approachable and are motivated to work closely with colleagues across Plesner. Your professional expertise and experience provide a strong foundation for constructive dialogue with colleagues who need to draw on your skills. You take a proactive, pragmatic and collaborative approach to the issues that naturally arise in day-to-day compliance work.
Your ability to combine insight into the legal framework with commercial understanding enables you to provide practical advice and guidelines that help your colleagues' day-to-day work run smoothly and efficiently.
Ideally, you have a relevant educational background focusing on information technology and organisation, as well as practical experience in establishing and operating information security management systems, such as ISO 27001 or NIST, and in using GRC tools. Relevant certifications such as CISM, CISA or ISO 27001 Lead Implementer are an advantage. You have a solid understanding of the GDPR and are familiar with the EU AI Act.
For Plesner and the service we provide to our clients, it is important that you communicate fluently in both Danish and English, in writing and verbally.
About us
You will join the Risk & Compliance team and report to Head of Risk Management, Robert Grønlund.
We are a team focused on ensuring that Plesner is and remains compliant. This involves establishing and following consistent procedures and continuously ensuring that the data we handle is accurate and properly documented.
At the same time, we work in a field that is constantly evolving, with ongoing changes to the regulatory framework that we must address and implement in an active and successful business.
You will become part of an inspiring, developmental and at times demanding working environment in which you will have considerable influence on how the team and its responsibilities evolve. In close dialogue with your immediate manager, you will also have excellent opportunities for personal and professional development.
We look forward to hearing from you
We would very much like you to join our team, so please upload your application, CV and any relevant educational certificates on our website as soon as possible. We conduct interviews on an ongoing basis and will continue the search until we have found the right candidate.
For more information about the position, please contact Head of Risk Management & Compliance Robert Grønlund on +45 30 93 72 06 or at rag@plesner.com. You are also welcome to contact HR Manager Monika Lalevic Gabel on +45 36 94 25 62 or at molg@plesner.com.
About Plesner
Plesner is Denmark's largest independent law firm, with more than 600 employees. We are driven by a desire to make a difference for our clients, for the business and for one another. Collaboration, quality and professional excellence are part of our DNA, and we believe that the best results are achieved together.