DLA Piper
Information Security Governance Lead

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Role Overview
To lead the firm's information security assurance activities, maintain the firm's information security certifications by coordinate of certification activities, and provide independent assessment of security control effectiveness. To also assist in the firm's information security risk management framework, working with the enterprise risk team.
The role helps ensure that security controls continue to protect the organisation, support client commitments and enable the firm to meet its regulatory and contractual obligations within its risk tolerance.
Main Duties and Responsibilities
- Own and maintain the ISO 27001:2022 Information Security Management System
- Coordinate internal and external certification audits
- Manage the lifecycle of policies, standards and supporting documentation
- Facilitate management reviews and support continual improvement activities
- Ensure security governance processes remain aligned to business objectives and evolving risk
- Design and operate a programme of security control testing and assurance activities
- Assess the effectiveness of administrative, technical and operational controls
- Produce assurance reports and communicate outcomes to relevant stakeholders
- Monitor remediation activities and support closure of identified weaknesses
- Develop assurance dashboards, metrics and management reporting
- Support the ongoing maturity of the security governance framework
- Review the impact of regulatory, industry and client requirements on the control environment
- Contribute to internal security awareness and governance initiatives
- Support external client requests relating to security assurance and certification activities where required
- Facilitate identification, assessment and evaluation of security risks
- Provide analysis and recommendations to support risk-based decisions
- Monitor risk treatment activities and provide challenge where appropriate
- Support risk acceptance and exception management processes
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Essential
About You
- Experience operating or supporting an ISO 27001 Information Security Management System
- Knowledge of information security control frameworks and assurance methodologies
- Knowledge of Cyber Essentials Plus
- Ability to assess the effectiveness of security controls and identify improvement opportunities
- Experience coordinating audit, certification or assurance activities
- Ability to translate technical and governance topics into practical business outcomes
- Experience presenting security findings, recommendations and risk information to stakeholders
- Experience identifying, assessing and managing information security risks
- Understanding of information security threats, vulnerabilities and control environments
- Experience applying risk management principles, frameworks and methodologies
- Ability to evaluate the potential business impact of security risks and control gaps
Valuable Experience
- Internal audit, risk management, compliance, technology assurance or operational resilience experience
- Knowledge of frameworks such as NIST CSF, CIS Controls, SOC 2 or similar industry standards
- Experience within regulated or client-facing environments
- Relevant professional qualifications such as ISO 27001 Lead Implementer, Lead Auditor, CISSP, CISM, CRISC or equivalent


Get help with your application
Your very own career expert that helps elevate your application to the next level.
About Us
We're a global law firm helping our clients achieve their goals wherever they do business. Our pursuit of innovation has transformed our delivery of legal services. With offices in the Americas, Europe, the Middle East, Africa and Asia Pacific, we deliver exceptional outcomes on cross-border projects, critical transactions and high-stakes disputes.
At DLA Piper, we understand that inclusion is not a one-size-fits-all concept. We embrace and celebrate the range of perspectives, backgrounds and experiences that each individual brings to our firm. By fostering a culture that welcomes and appreciates all aspects of our individuality, we ensure that everyone has the opportunity to succeed.
Our commitment to inclusion and positive social impact enables us to provide exceptional service to our clients and communities, while nurturing a unique and inclusive culture for all our people. We welcome the unique contribution that you will bring to our firm and actively encourage applications from all talented people – however your talent is packaged, whatever your background or circumstance and regardless of how you identify.
We are committed to being accessible and accommodating any reasonable adjustments needed throughout the recruitment process to ensure an inclusive experience for all. If you need any support or adjustments, please let us know.
Where local legislation permits, we will conduct relevant pre-engagement screening checks prior to your first day.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Location