Rodeo
Get started

Slaughter and May

Information Security Officer - Mandarin Speaking

London
Posted 2 days ago
Sign up to applySee more jobs like this
Get notified of more jobs like this · No spam, ever

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

Role overview

Reporting to the Senior Information Security Manager, the Information Security Officer for Asia will play a key role in maintaining the firm's ISO 27001 certification across its offices in Asia (Hong Kong and Beijing). This is a new role, based in London, that will primarily be responsible for the day-to-day management, administration and continual improvement of the Asia Information Security Management System (ISMS).

This is a hands-on individual contributor role, requiring a strong understanding of the ISO 27001 standard and the ability to work independently, building strong relationships with stakeholders across both Europe and Asia offices. The role will help ensure that information security practices in Asia remain aligned with both the firm's global standards and applicable local regulatory requirements.

The role will also provide security oversight and guidance for projects, technology changes, and operational activities across the firm's Asia offices, ensuring that information security risks are managed effectively. A strong background in information security Governance, Risk and Compliance (GRC) is essential.

The role requires fluency in both English and Mandarin, with Cantonese considered beneficial. Occasional travel to Hong Kong and Beijing will be required, typically two to four trips per year, each lasting several days. Given the requirement to collaborate regularly with colleagues across Asia, some flexibility in working hours is desirable, for example 8:00am to 4:00pm UK time.

Key responsibilities

The key responsibilities of this role are set out below and there may be others which are not listed. You may be required on occasion to work outside our normal working hours of 9:30am to 5:30pm.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

  • Manage the day-to-day operations of the firm’s Asia ISMS by:
    • Maintaining policies such that they align with the firm’s global standards but reflect local variations in both the regulatory landscape and working practice.
    • Maintain and continuously improve risk, incident and exceptions registers.
    • Track relevant metrics against ISMS objects and produce management review reports for Steering Group meetings.
    • Coordinate and facilitate internal and external ISO 27001 audits for the Hong Kong and Beijing offices, managing audit schedules, stakeholder engagement, and the completion of audit deliverables.
    • Coordinate with relevant Business Services teams and stakeholders to develop, implement, and monitor remediation plans for audit findings, and drive continuous improvement.
    • Collaborate with the wider Information Security and Privacy (ISP) team to support the delivery of information security awareness and training programmes, promoting a strong security culture across the Hong Kong and Beijing offices.
    • Provide advice and support to the Hong Kong and Beijing offices, as their primary information security representative.

Candidate profile

Candidates for this position must have:

  • Strong working knowledge of ISO 27001, e.g. ISO 27001 Lead Implementer or Lead Auditor.
  • Prior experience in an information security or GRC role, ideally within a regulated environment or an organisation aligned to ISO 27001.
  • A self-motivated, results-driven mindset with a strong sense of ownership and accountability.
  • Excellent organisational skills, with the ability to prioritise effectively in a fast-paced environment.
  • Proven ability to collaborate effectively, build strong professional relationships, and communicate confidently with senior leadership.
  • Fluent in both English and Mandarin. Cantonese speaking beneficial.
  • Ability and willingness to travel to Hong Kong and Beijing, typically two to four trips per year.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

Additional information

We are committed to ensuring that our recruitment processes are barrier-free and as inclusive as possible for everyone. This includes making adjustments for people who have a disability or long-term condition. If you have any questions or require any adjustments to be made to one or both of the application or interview processes, please contact the Recruitment Team.

We are a Disability Confident Committed employer and will offer an interview to applicants with a disability or long-term condition who best meet the minimum or essential criteria for our Business Services roles. If you would like to apply through the Disability Confident 'Offer An Interview' commitment, please apply via our online application form and not via LinkedIn. You are disabled under the Equality Act 2010 if you have a physical or mental impairment that has a ‘substantial’ and ‘long-term’ negative effect on your ability to do normal daily activities. For more information about the Disability Confident scheme, please see the government website here.

We welcome applications irrespective of race, colour, ethnic or national origin, disability, sex, gender identity, sexual orientation, age, religion, belief or marital status.

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Skills

ISO 27001
Information Security Management System (ISMS)
Governance Risk and Compliance (GRC)
English Fluency
Mandarin Fluency
Internal Auditing
External Auditing
Risk Management
Stakeholder Management
Regulatory Compliance
Security Awareness Training
Incident Management

Location

London, England, United Kingdom

Sign up to applySee more jobs like this