Bird & Bird
Information Security Analyst

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Bird & Bird is seeking a motivated and experienced Information Security Analyst to join its global Information Security Team
This role is ideal for an individual who enjoys a broad range of security responsibilities spanning security operations, incident response, governance, risk management, compliance, supplier assurance, and security project delivery.
As a member of a small but highly effective global Information Security team, you will play a key role in protecting the confidentiality, integrity, and availability of the firm's information assets and client data. The successful candidate will work closely with IT infrastructure, service delivery, legal technology, risk and compliance teams, and external security providers to continuously enhance the firm's security posture. The Information Security team is responsible for maintaining and improving the firm's Information Security Management System (ISMS), ensuring compliance with industry standards, investigating security incidents, supporting audits, and promoting a strong security culture across the organisation.
Bird & Bird's Technology Team mission is to support the strong technology focus of the Firm, provide modern technology to support the business, and creative solutions for our Clients.
The team covers a broad range of technologies and specialisms including business architecture, business solutions, project and programme management, modern infrastructure, and they are all primarily focused on international projects working alongside colleagues in our 34 offices. Whether it's analyzing new solutions, driving innovation, developing client solutions, or providing a first-class, high-availability infrastructure and support, we are a diverse, energized group focused on service and contributing to both the internal and external use of technologies. We work extensively across the network and seek candidates who are keen to engage internationally and make wider contributions both internally and externally than just IT service and delivery.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Key Responsibilities
- Monitor, investigate, and respond to security alerts and incidents across on-premise and cloud environments.
- Lead incident triage, containment, remediation, and post-incident reviews to minimize business risk.
- Manage security operations workflows, ensuring issues are prioritized and resolved within agreed SLAs.
- Coordinate vulnerability management activities, driving remediation across infrastructure, applications, and cloud services.
- Conduct security assessments, technical reviews, and support penetration testing programs.
- Support and maintain the Information Security Management System (ISMS), including ISO 27001 and Cyber Essentials Plus compliance activities.
- Perform risk assessments and ensure security policies, standards, and procedures remain effective and up to date.
- Provide security guidance on new technologies, projects, cloud services, and AI adoption initiatives.
- Manage third-party security assurance activities, including supplier assessments, client questionnaires, and audits.
- Deliver security awareness training and promote a strong security culture across the organisation.
- Contribute to the continuous improvement of security controls, processes, reporting, and strategic security initiatives.
What You'll Bring
- Experience in information security, cyber security, security operations, or related disciplines.
- Experience investigating security incidents and managing security alerts.
- Good understanding of Microsoft 365, Azure/Entra ID, and cloud security principles.
- Experience working with vulnerability management programs.
- Knowledge of security frameworks and standards including:
- ISO/IEC 27001
- Cyber Essentials Plus
- NIST Cyber Security Framework
- CIS Controls
- Familiarity with risk assessment methodologies and security governance practices.
- Experience with security tooling such as SIEM, EDR/XDR, vulnerability scanners, and email security platforms.
- Experience within a law firm, professional services organization, financial services firm, or other highly regulated environment.
- Experience responding to client security questionnaires and audits.
- Knowledge of Microsoft Security technologies including Defender, Sentinel, Purview, and Entra ID.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
What's In It For You
We provide comprehensive support for our colleagues' health and wellbeing, including private medical cover, life assurance, critical illness cover, and regular health assessments. In addition, we offer a range of lifestyle benefits designed to help our team live their best lives, such as a cycle to work scheme, access to online GP appointments, discounted gym memberships, and an electric vehicle scheme.
If you require any assistance, please email us at talentacquisitionlondon@twobirds.com
To apply, click on the 'apply' button to submit your details.
Bird & Bird opens up a world of possible for lawyers and professionals everywhere. Working for a leading international law firm like Bird & Bird means working alongside people who are truly collegiate in the way they work with everyone. We work as one global team, with over 70% of work involving people from across the firm. And that's only increasing! It's this common purpose and shared approach that makes for a more productive and collaborative place to work. Your firm. Your future.
If you want to find out more, visit www.twobirds.com
As a disability and neurodiversity inclusive employer, we want to ensure that you have a barrier-free recruitment experience at Bird & Bird. If you require any adjustments during the recruitment process, please provide details to your recruitment contact who will be in touch to discuss any details provided and understand more about your individual adjustment needs.
Download
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills
Location