Rodeo
Get started

Howard Kennedy LLP

Information Security Analyst

London
Posted about 21 hours ago
Sign up to applySee more jobs like this
Get notified of more jobs like this · No spam, ever

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

The Role

We are seeking an Information Security Analyst to join our Cyber Security team. This is a varied and hands-on role, offering an excellent opportunity for a motivated security professional to develop their career within a forward-thinking professional services environment.

Working across technical security, risk and governance, compliance, and continuous improvement, you will gain broad exposure to all aspects of information security while supporting a business that places technology, security, and client trust at its core. As part of the Information Security function, you will play a key role in protecting the firm’s information, systems, and digital services, helping to ensure legal services are delivered securely, reliably, and in line with regulatory, contractual, and client expectations.

Working closely with IT teams, Partners, lawyers, Business Services colleagues, suppliers, and security partners, you will help identify, assess, and manage risks, while providing practical security guidance that enables secure and productive ways of working.

The role spans security monitoring, incident response, vulnerability management, supplier assurance, compliance, reporting, and security awareness. You will contribute to the ongoing development of the firm’s security capabilities, helping to strengthen controls, improve resilience, and support a strong culture of information security across the business.

Role Responsibility

Protect

  • Operate, review, and improve security controls, risk treatment activity, and security processes within approved policies, standards, and change governance.
  • Assist with identity and access management, including joiners/movers/leavers processes, access review evidence, and approved privileged access activities.
  • Support vulnerability management by coordinating evidence, prioritizing remediation by business context and consequence, and tracking issues to closure.
  • Support the implementation and operation of security technologies and upgrades in line with agreed standards.
  • Review technical designs, configurations, and change proposals to identify security risk.
  • Support the definition and implementation of security requirements for new systems and material changes.
  • Work with suppliers and managed service providers to keep operational controls effective.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

Monitor & Respond

  • Monitor security and threat detection systems, investigate alerts, and identify trends that need a response.
  • Respond to security policy breaches and provide practical guidance on secure working practices.
  • Act as an escalation point for security queries from the Service Desk, IT, and Risk and Compliance teams, including DSAR evidence gathering where appropriate.
  • Support incident response activities including triage, investigation, containment, documentation, remediation tracking, and post-incident review.
  • Support business continuity and disaster recovery activity, helping restore protected services quickly after disruption.
  • Monitor emerging threats and vulnerabilities and recommend appropriate mitigations.

Advise

  • Maintain the information security risk register so it reflects current risks, controls, actions, and escalation requirements.
  • Support audits, client due diligence, ISO 27001 assurance, and governance reporting through evidence collation, metrics, and action tracking.
  • Support third-party risk management, including onboarding, questionnaires, contract evidence, and ongoing supplier assurance.
  • Work with the Data Protection Officer on data protection incidents and assessments in line with UK GDPR, the Data Protection Act 2018, and SRA expectations where applicable.
  • Produce clear reports for technical and non-technical stakeholders.
  • Assist with the creation and delivery of cyber security awareness and training for colleagues.

About You

Ideally you will be able to demonstrate;

  • Experience in an information or cyber security role covering protection, monitoring, response, and advisory work; law firm or professional services experience is desirable.
  • Comfort and experience operating with real autonomy and ownership, ideally within a small or lean security team rather than a large structure.
  • Broad technical knowledge across networking, systems administration, infrastructure, applications, and security, with the ability to challenge designs and identify real risk.
  • Hands-on experience with common security technologies and controls (e.g. endpoint protection, email/web security, firewalls, IDS/IPS).
  • Good working knowledge of Microsoft platforms and security capabilities.
  • Sound understanding of information risk, with the ability to assess conditions and consequences rather than rely solely on generic severity ratings.
  • Knowledge of relevant standards, good practice, and regulatory requirements, including UK GDPR and the Data Protection Act 2018.
  • Strong analytical skills with the ability to translate business requirements into proportionate security controls.
  • Excellent written and verbal communication skills, with the ability to engage both technical and non-technical stakeholders.
  • Organised, methodical, and accurate approach, with strong attention to detail and a willingness to learn and develop.
  • High levels of integrity and discretion when handling sensitive information.
  • Pragmatic, business-focused mindset with the ability to balance risk and usability.
  • Curiosity and pro-activity, with a continuous improvement mindset and willingness to challenge assumptions constructively.
  • A collaborative and service-oriented approach, with an understanding of the pressures of a legal services environment.
  • The ability to work calmly and methodically particularly when managing incidents or competing priorities.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

About Us

At Howard Kennedy we believe that everyone deserves the space to thrive. We’re committed to creating an inclusive recruitment experience that reflects the diversity of both our people and our clients.

We are proud to be an equal opportunities employer. We welcome applications from individuals of all backgrounds and identities, and we’re committed to ensuring that our recruitment process is fair, transparent, and accessible to all.

We understand that every candidate’s needs are different. If there’s anything we can do to make your application journey more comfortable— whether for interviews, assessments, or onboarding—please let us know. We’ll work with you to remove any barriers and ensure our recruitment process is comfortable for you.

Contact our recruitment team at recruitment@howardkennedy.com to discuss any support you might need.

Agency Introductions

Please note that we are not accepting applications via agencies for this role at this time. Before sharing any named candidate CVs, please contact your recruitment representative. If any named CVs are sent from agencies without approval from our recruitment team, they will not be deemed valid introductions, and no agency fee will be paid.

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Skills

Information Security
Cyber Security
Risk Management
Governance
Compliance
Vulnerability Management
Incident Response
Identity and Access Management
ISO 27001
UK GDPR
Network Security
Microsoft Security Platforms
Third-Party Risk Management
Security Monitoring
Security Awareness Training
Technical Design Review

Location

London, England, United Kingdom

Sign up to applySee more jobs like this