Legatics
Information Security Manager (12 month fixed-term maternity cover)

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Role Purpose
Legatics handles some of the world’s most complex and confidential legal transactions, so information security is core to the product and to client trust. The Information Security Manager owns information security across Legatics — setting the vision and strategy, maintaining our ISO 27001 certified ISMS, working hand-in-hand with engineering to embed security into our client-facing products, and acting as the security point of contact for our clients and business teams.
Reporting to the Head of Engineering, the role spans technical security, compliance and governance, client assurance, and the day-to-day operation of our security and IT tooling. It is a broad, hands-on role with a high degree of autonomy to shape direction as Legatics scales.
This is a fixed-term appointment covering a period of maternity leave. The expected duration is approximately 12 months from the start date, although the actual end date will depend on the return date of the current postholder and may fall slightly earlier or later. You will have full ownership of the remit set out below for the duration of the contract, with the same autonomy, access and support as a permanent member of the team.
About Legatics
Legatics is one of the world’s leading LegalTech scale-ups. Our legal transaction management platform enables law firms and their clients to collaborate on and close deals in an interactive online environment, providing clarity, reducing risk and saving time.
Our customers include some of the world’s top law firms, such as Allen & Overy Shearman, Hogan Lovells, Herbert Smith Freehills, and King & Wood Mallesons. And we’ve been used on transactions in more than 60 countries on transactions worth over $1 trillion.
The contract
This role is offered on a fixed-term basis to provide cover during a colleague's maternity leave, with an anticipated duration of around 12 months.
A few things worth knowing:
- You will be employed on the same terms and benefits as our permanent employees, including private medical insurance, health cash plan and pension.
- The contract may be extended if the period of cover changes, and we will always give you as much notice as we can of the confirmed end date.
- Where a suitable permanent role exists at the end of the contract, we will discuss it with you. We are being deliberate in not promising this, because we would rather be straight with you than imply something we cannot guarantee.
- Fixed-term does not mean holding the fort. We are looking for someone who will genuinely own and advance our security posture during their time here, and we expect the work you do to outlast the contract.
Key responsibilities
Security strategy, posture and governance
- Own the vision, direction and roadmap for information security at Legatics, and continue developing the overall security posture, processes, systems and controls.
- Maintain up-to-date knowledge of the threat landscape, emerging best practice and tooling, and translate this into Legatics’ security priorities.
- Develop and run a strategy for continuous security and resilience testing — for example penetration testing, red-team exercises and threat modelling (such as self-hosted GitLab versus consumed SaaS).
- Build relationships with relevant industry bodies and security peers at similar organisations.
ISO 27001 and compliance (ISMS ownership)
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
- Own ISO 27001 certification and the Information Security Management System (ISMS), including ongoing maintenance and continuous audit readiness; align the ISMS to ISO 27001:2022.
- Maintain the Master Document List, version control and approvals across all policies, and keep ISO documentation tracked in a central system (e.g. the Notion ISO database).
- Finalise and maintain the Statement of Applicability (SoA), and keep the ISMS Manual current.
- Review and maintain core policies — including the Acceptable Use Policy, Access Control Policy, and Incident Response & Breach procedure — and keep the ISMS Risk Register up to date.
- Document and operate the threat intelligence process; maintain the Interested Parties register and the analysis of internal/external issues (PESTLE).
- Produce and maintain the ISMS Communication Plan and associated tracking (e.g. CROO and SoA).
- Run periodic user access reviews across Google Workspace and SaaS platforms.
- Collect, organise and maintain audit evidence, including:
- Change-control tickets with security approval evidence
- Incident log and resolution documentation
- Vendor security assessments and contracts
- Backup restore test evidence
- Vulnerability scan results and mitigation logs
- Business continuity scenario tests (e.g. power/internet outage, key-person unavailability, data exposure, phishing)
- Fire safety report and extinguisher servicing log; Employers’ Liability insurance certificate
- Security induction and ongoing training completion, and employee policy acknowledgements
- Prepare staff and evidence for external surveillance and recertification audits.
Client security assurance
- Complete client information security questionnaires (ISQs) and respond to customer security queries, including requests raised by the customer-facing team via Slack.
- Provide client-facing security remediation updates (e.g. on penetration test findings) and discuss Legatics’ security posture directly with clients and prospects.
- Attend client meetings, remotely or on-site, as required.
- Build and improve tooling to speed up and standardise questionnaire responses (e.g. an ISQ assistant / Claude plugin).
Application and product security
- Conduct technical risk assessments on product features (e.g. data room file-viewer permission boundaries), assess compliance risk for legal-sector clients, and advocate for server-side enforcement of access controls rather than UI-only restrictions.
- Perform vulnerability and exploitability analysis (e.g. CVE triage within our detection services and end-of-life dependencies), and prioritise remediation based on real exposure.
- Review the security risk of proposed integrations and data flows (e.g. third-party automation routing source code or data externally), and maintain the vendor risk register.
- Operate and consolidate security scanning (e.g. Prowler, SonarQube, Grype/Syft) and evaluate aggregation tooling such as DefectDojo to centralise findings.
Cloud, identity and endpoint security
- Audit and harden cloud and identity posture across Google Workspace (e.g. ScubaGoggles, GAMADV-XTD3) and Microsoft Entra ID, including SSO/SAML enforcement, conditional access, and onboarding/offboarding automation.
- Resolve identity and email-security issues such as OAuth/app-access controls, SAML enforcement, and email authentication (DMARC/DKIM).
- Own endpoint security — EDR (SentinelOne) across approximately 50 Windows and Mac endpoints — including detection policy tuning, phased rollout, developer-environment exclusions, and validation (e.g. EICAR testing).
- Design and maintain federated authentication (e.g. Google Credential Provider for Windows) with appropriate rollout guides and rollback procedures.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Security monitoring and detection
- Develop, extend and maintain security monitoring, reporting and tracking tools covering the full technical estate, including SIEM, log aggregation and correlation (e.g. forwarding EDR alerts into Datadog).
- Tune monitoring rules and alert configurations to improve signal quality and reduce false positives.
- Maintain threat-awareness pipelines (e.g. automated security-news aggregation into a dedicated Slack channel).
Incident response
- Lead detection, triage, containment and response for security incidents (e.g. supply-chain compromises affecting third-party tooling); assess blast radius and advise on practical containment given platform constraints.
- Draft and issue incident communications tailored to both technical and non-technical audiences, and maintain escalation and breach procedures.
AI security and governance
- Set Legatics’ AI security posture, positioning security as an enabler for teams building with autonomous AI tools, and map controls to relevant frameworks (e.g. OWASP Top 10 for Agentic Applications).
- Implement access controls, security architecture and detection rules for internal AI systems (e.g. the AI Brain knowledge base).
- Research AI coding risks — such as generative monoculture, slopsquatting and hallucinated-package attacks — and feed findings into engineering practice and our AI coding risk posture.
- Harden the AI tooling and automation surface used by security and engineering (e.g. secure Claude Code workflows, secrets scanning, and MCP integrations).
IT operations and tooling support
- Handle day-to-day IT support across the team, including MCP connector provisioning and permissions troubleshooting for staff integrating internal tools.
- Administer Claude Team connectors and clarify pre-built versus custom connector provisioning for team members.
- Support internal data tooling (e.g. BigQuery, service accounts, Google Sheets integration), including IAM role configuration, OAuth scope grants and external table management.
What we need from you
The ideal candidate will have a mix of technical, compliance and communication skills. You do not need every item below — if you have strong foundations and are keen to learn the rest, we’d like to hear from you.
- Experience in an information security or cyber-security role, as a lead or individual contributor.
- Strong knowledge of fundamental internet technologies, Linux systems, cloud infrastructure and networking — and their real-world use and abuse.
- Experience with SIEM, log and traffic analysis, monitoring, reporting and auditing approaches.
- Hands-on experience managing an ISMS and ISO 27001 compliance (ISO 27001:2022 desirable), including audit preparation and evidence management.
- Confident completing client information security questionnaires and discussing security posture directly with customers and prospects.
- Familiarity with cloud
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills
Location