Michael James Associates
Head of Information Security

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Head of Information Security
Location: London
Sector: Legal / Professional Services
Type: Permanent
Working Model: Hybrid
The Opportunity
We are working with a leading international law firm on the appointment of a Head of Information Security to lead and further develop the firm's global Information Security function. This is a senior leadership position with responsibility for shaping the firm's Information Security strategy, strengthening its security governance and risk framework, and ensuring the organisation remains resilient against an increasingly sophisticated threat landscape.
The successful candidate will work closely with senior Technology and Business stakeholders, providing strategic direction while also ensuring that security initiatives are effectively delivered across the organisation.
Key Responsibilities
- Lead and develop the firm's global Information Security function, setting the strategy, roadmap and priorities.
- Own and evolve the Information Security strategy in line with wider business and technology objectives.
- Establish and maintain appropriate security governance, policies, standards, controls and assurance frameworks.
- Provide senior leadership with clear advice on cyber and information security risks, emerging threats and appropriate mitigation strategies.
- Work closely with the CIO, CISO, Technology leadership and wider business stakeholders to embed security across the organisation.
- Lead Information Security risk management, including risk assessment, treatment and reporting.
- Oversee security governance, compliance, audit and regulatory requirements.
- Partner with Cyber Security, Infrastructure, Cloud, Architecture, Data and Technology teams to ensure security is embedded across the technology estate.
- Provide oversight of third-party and supply-chain security risk.
- Support major technology and business transformation programmes, including cloud adoption, AI and emerging technology initiatives.
- Develop effective security metrics and reporting for senior leadership and governance forums.
- Lead, mentor and develop members of the Information Security team.
- Promote a strong security culture across the firm through awareness, education and stakeholder engagement.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Experience Required


Get help with your application
Your very own career expert that helps elevate your application to the next level.
We are looking for an experienced Information Security leader who has operated at a senior level within a complex and internationally distributed organisation.
You will ideally have:
- Significant experience leading Information Security, Cyber Security or a closely related function.
- Experience developing and delivering enterprise-wide Information Security strategy.
- Strong knowledge across security governance, risk, compliance and assurance.
- Experience managing and influencing senior business and technology stakeholders.
- Strong understanding of cloud security, IAM, infrastructure security and enterprise technology environments.
- Experience managing third-party and supply-chain security risk.
- Experience operating within a regulated, highly risk-se
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Location