أبلاي إيدج ابدأ البحث عن عمل

Information Security Manager (12 month fixed-term maternity cover)

Legatics · London, England, United Kingdom

قدّم وتابع مع أبلاي إيدج
Role PurposeLegatics handles some of the world's most complex and confidential legal transactions, so information security is core to the product and to client trust. The Information Security Manager owns information security across Legatics — setting the vision and strategy, maintaining our ISO 27001 certified ISMS, working hand-in-hand with engineering to embed security into our client-facing products, and acting as the security point of contact for our clients and business teams.Reporting to the Head of Engineering, the role spans technical security, compliance and governance, client assurance, and the day-to-day operation of our security and IT tooling. It is a broad, hands-on role with a high degree of autonomy to shape direction as Legatics scales.This is a fixed-term appointment covering a period of maternity leave. The expected duration is approximately 12 months from the start date, although the actual end date will depend on the return date of the current postholder and may fall slightly earlier or later. You will have full ownership of the remit set out below for the duration of the contract, with the same autonomy, access and support as a permanent member of the team.About LegaticsLegatics is one of the world's leading LegalTech scale-ups. Our legal transaction management platform enables law firms and their clients to collaborate on and close deals in an interactive online environment, providing clarity, reducing risk and saving time.Our customers include some of the world's top law firms, such as Allen & Overy Shearman, Hogan Lovells, Herbert Smith Freehills, and King & Wood Mallesons. And we've been used on transactions in more than 60 countries on transactions worth over $1 trillion.The contractThis role is offered on a fixed-term basis to provide cover during a colleague's maternity leave, with an anticipated duration of around 12 months.A few things worth knowing:You will be employed on the same terms and benefits as our permanent employees, including private medical insurance, health cash plan and pensionThe contract may be extended if the period of cover changes, and we will always give you as much notice as we can of the confirmed end dateWhere a suitable permanent role exists at the end of the contract, we will discuss it with you. We are being deliberate in not promising this, because we would rather be straight with you than imply something we cannot guaranteeFixed-term does not mean holding the fort. We are looking for someone who will genuinely own and advance our security posture during their time here, and we expect the work you do to outlast the contractKey ResponsibilitiesSecurity strategy, posture and governanceOwn the vision, direction and roadmap for information security at Legatics, and continue developing the overall security posture, processes, systems and controlsMaintain up-to-date knowledge of the threat landscape, emerging best practice and tooling, and translate this into Legatics' security prioritiesDevelop and run a strategy for continuous security and resilience testing — for example penetration testing, red-team exercises and threat modelling (such as self-hosted GitLab versus consumed SaaS)Build relationships with relevant industry bodies and security peers at similar organisationsISO 27001 and compliance (ISMS ownership)Own ISO 27001 certification and the Information Security Management System (ISMS), including ongoing maintenance and continuous audit readiness; align the ISMS to ISO 27001:2022Maintain the Master Document List, version control and approvals across all policies, and keep ISO documentation tracked in a central system (e.g. the Notion ISO database)Finalise and maintain the Statement of Applicability (SoA), and keep the ISMS Manual currentReview and maintain core policies — including the Acceptable Use Policy, Access Control Policy, and Incident Response & Breach procedure — and keep the ISMS Risk Register up to dateDocument and operate the threat intelligence process; maintain the Interested Parties register and the analysis of internal/external issues (PESTLE)Produce and maintain the ISMS Communication Plan and associated tracking (e.g. CROO and SoA)Run periodic user access reviews across Google Workspace and SaaS platformsCollect, organise and maintain audit evidence, including:Change-control tickets with security approval evidenceIncident log and resolution documentationVendor security assessments and contractsBackup restore test evidenceVulnerability scan results and mitigation logsBusiness continuity scenario tests (e.g. power/internet outage, key-person unavailability, data exposure, phishing)Fire safety report and extinguisher servicing log; Employers' Liability insurance certificateSecurity induction and ongoing training completion, and employee policy acknowledgementsPrepare staff and evidence for external surveillance and recertification auditsClient security assuranceComplete client information security questionnaires (ISQs) and respond to customer security queries, including requests raised by the customer-facing team via SlackProvide client-facing security remediation updates (e.g. on penetration test findings) and discuss Legatics' security posture directly with clients and prospectsAttend client meetings, remotely or on-site, as requiredBuild and improve tooling to speed up and standardise questionnaire responses (e.g. an ISQ assistant / Claude plugin)Application and product securityConduct technical risk assessments on product features (e.g. data room file-viewer permission boundaries), assess compliance risk for legal-sector clients, and advocate for server-side enforcement of access controls rather than UI-only restrictionsPerform vulnerability and exploitability analysis (e.g. CVE triage within our detection services and end-of-life dependencies), and prioritise remediation based on real exposureReview the security risk of proposed integrations and data flows (e.g. third-party automation routing source code or data externally), and maintain the vendor risk registerOperate and consolidate security scanning (e.g. Prowler, SonarQube, Grype/Syft) and evaluate aggregation tooling such as DefectDojo to centralise findingsCloud, identity and endpoint securityAudit and harden cloud and identity posture across Google Workspace (e.g. ScubaGoggles, GAMADV-XTD3) and Microsoft Entra ID, including SSO/SAML enforcement, conditional access, and onboarding/offboarding automationResolve identity and email-security issues such as OAuth/app-access controls, SAML enforcement, and email authentication (DMARC/DKIM)Own endpoint security — EDR (SentinelOne) across approximately 50 Windows and Mac endpoints — including detection policy tuning, phased rollout, developer-environment exclusions, and validation (e.g. EICAR testing)Design and maintain federated authentication (e.g. Google Credential Provider for Windows) with appropriate rollout guides and rollback proceduresSecurity monitoring and detectionDevelop, extend and maintain security monitoring, reporting and tracking tools covering the full technical estate, including SIEM, log aggregation and correlation (e.g. forwarding EDR alerts into Datadog)Tune monitoring rules and alert configurations to improve signal quality and reduce false positivesMaintain threat-awareness pipelines (e.g. automated security-news aggregation into a dedicated Slack channel)Incident responseLead detection, triage, containment and response for security incidents (e.g. supply-chain compromises affecting third-party tooling); assess blast radius and advise on practical containment given platform constraintsDraft and issue incident communications tailored to both technical and non-technical audiences, and maintain escalation and breach proceduresAI security and governanceSet Legatics' AI security posture, positioning security as an enabler for teams building with autonomous AI tools, and map controls to relevant frameworks (e.g. OWASP Top 10 for Agentic Applications)Implement access controls, security architecture and detection rules for internal AI systems (e.g. the AI Brain knowledge base)Research AI coding risks — such as generative monoculture, slopsquatting and hallucinated-package attacks — and feed findings into engineering practice and our AI coding risk postureHarden the AI tooling and automation surface used by security and engineering (e.g. secure Claude Code workflows, secrets scanning, and MCP integrations)IT operations and tooling supportHandle day-to-day IT support across the team, including MCP connector provisioning and permissions troubleshooting for staff integrating internal toolsAdminister Claude Team connectors and clarify pre-built versus custom connector provisioning for team membersSupport internal data tooling (e.g. BigQuery, service accounts, Google Sheets integration), including IAM role configuration, OAuth scope grants and external table managementRequirementsWhat we need from youThe ideal candidate will have a mix of technical, compliance and communication skills. You do not need every item below — if you have strong foundations and are keen to learn the rest, we'd like to hear from you.Experience in an information security or cyber-security role, as a lead or individual contributorStrong knowledge of fundamental internet technologies, Linux systems, cloud infrastructure and networking — and their real-world use and abuseExperience with SIEM, log and traffic analysis, monitoring, reporting and auditing approachesHands-on experience managing an ISMS and ISO 27001 compliance (ISO 27001:2022 desirable), including audit preparation and evidence managementConfident completing client information security questionnaires and discussing security posture directly with customers and prospectsFamiliarity with cloud and identity platforms (Google Workspace, Microsoft Entra ID, SSO/SAML) and endpoint/EDR toolingApplication security and vulnerability triage, and vendor / third-party risk assessmentAn interest in, or experience of, AI and agentic security risks (a growing part of the role)Solid communication skills, able to work with and influence both technical and non-technical stakeholdersExperience in a startup or scale-up environment is beneficialA right to work in the UK (unfortunately, we are not in a position to support visa sponsorship at this stage)An ability to work from our London office at least twice a weekBenefitsWhat we offer you:25 days holiday per year (plus public holidays)Early Finish Fridays - on the last Friday of every month, we finish around lunchtime!Pension with NESTPrivate Medical Insurance with Bupa, giving you fast access to diagnosis and treatment when you need itHealthshield Health Cash Plan, helping you claim money back on everyday healthcare like dental, optical and physioPersonal Learning & Development budgetAccess to Mental healthcare for you and your immediate familyEnhanced parental leave policies so you can spend more time with your familyLots of opportunities for accelerated professional development and career progressionWork alongside a supportive and talented team with the opportunity to grow one of the world's leading LegalTech scale-upsA warm, genuinely collaborative culture and an awesome team; andRegular socialsPower in diversityWe put users at the heart of our design to provide legal transaction experiences that everyone loves. In order to make that a reality, we seek to foster a diverse and inclusive working environment that can empower our people to be creative, effective and innovative, to build a brand we are proud of.We don't discriminate against gender, race, religion or belief, disability, age, marital status or sexual orientation. Whatever your background may be, we welcome anyone with talent, drive and emotional intelligence. We're committed to building a diverse team and are constantly looking for ways to improve our processes to help us do that.