Slaughter and May
IT Cyber Security Specialist

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Role overview
We are recruiting for an experienced IT Cyber Security Specialist to join the IT Infrastructure Engineering Team, part of the Technology Department within the wider Business Services function, based at the firm's head office in London.
The team is responsible for the security, and continual improvement of the firm's global IT infrastructure, systems, and cybersecurity capabilities, working closely alongside the Infrastructure Operations Team, which manages day-to-day service delivery and support.
As a project, engineering, and security-focused function, the Infrastructure Engineering Team delivers technology projects and programmes, as well as driving strategic infrastructure and cybersecurity enhancements across the firm's global offices.
Reporting to the IT Infrastructure Engineering Manager, the IT Cyber Security Specialist is a key technical role responsible for the ownership and continual development of the firm's cybersecurity controls and security architecture. The successful candidate will develop security policies, identify and mitigate vulnerabilities, investigate security incidents, and lead the response and resolution of major cyber incidents, helping to ensure the firm's technology environment remains secure, resilient, and aligned to business needs.
Key responsibilities
The key responsibilities of this role are set out below and there may be others which are not listed. You may be required on occasion to work outside our normal working hours of 9:30am to 5:30pm.
Cyber Security & Engineering
- Constantly review and improve the firm’s security posture and external security rating.
- Identify vulnerabilities in hardware and software to be remediated by Engineering\Operations teams.
- Understand current and emerging security threats.
- Assist and lead in Incident Response investigations and mitigation.
- Communicate threats and deliver training and awareness programmes to other team members.
- Produces quarterly privilege access slides, suggesting ongoing improvement for monthly operational security slides, measured using secure score.
- Evaluate, test and recommend security enhancements.
- Develop business continuity plans of critical business services in the event of a disaster.
- Lead CE+ accreditation.
- Identify security risks and exposures, determine the cause of security violations and suggest procedures to halt future incidents.
- Perform targeted regular and ad-hoc scans to identify potential breaches of the firm data and security and data protection policies.
- Identify, analyse, monitor and minimise areas of risk that pertain to Information technology.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Project Delivery
- Be able where relevant to participate in and lead varied IT Infrastructure lifecycle & security projects. Including HLD creation, solution costing and review.
- Ensure that proposed infrastructure architecture/design are aligned with Firms policies.
- Post project, participate in evaluating the success of the project, identifying best practices and lessons learned.
Third Level Support
- Provide Major Problem\Incident Support where Operations team need steering from a subject matter expert.
- Liaison with 3rd party suppliers on system issues.
- Ensuring that all members of 3rd level teams have the relevant skills sharing, procedures and documentation.
This role requires the ability to communicate complex ideas clearly and effectively. Strong soft skills, including active listening, presentation, and communication skills, are therefore essential.
Candidate profile
Candidates for this position must have:
- 10+ years of experience as a full time IT professional, 5 years in a similar role.
- Demonstrable experience in a Cyber Security position with a focus on incident response, threat monitoring, and vulnerability management.
- Hold at least one security related certifications such as CISSP, CEH, CCNA Security.
- Experience with threat prevention techniques and tools.
- Knowledge of best practices in modern security architectures and incident responses.
- Experience of Infrastructure Business Continuity or Disaster Recovery planning.
- Experience designing, integrating and managing complex infrastructure solutions.
- Excellent problem-solving ability including leading multi-disciplinary teams to identify, research and coordinate resource to diagnose & troubleshoot complex issues.
- Excellent skills with Windows Server 2016/2019/2022 (Active Directory multi-site, DHCP, DNS, Intune, Group Policy, AGPM, PKI, ABDA, DFS, Entra, Azure SSO).
- Strong written and oral communication skills, and the ability to effectively communicate with technical and non-technical audiences at all levels.
- Be able to work with 3rd parties to manage on premise and cloud services.
- Strong planning skills.
- Experienced in Information Technology Infrastructure Library (ITIL) processes, procedures, and roles.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
We are committed to ensuring that our recruitment processes are barrier-free and as inclusive as possible for everyone. This includes making adjustments for people who have a disability or long-term condition. If you have any questions or require any adjustments to be made to one or both of the application or interview processes, please contact the Recruitment Team.
We are a Disability Confident Committed employer and will offer an interview to applicants with a disability or long-term condition who best meet the minimum or essential criteria for our Business Services roles. If you would like to apply through the Disability Confident 'Offer An Interview' commitment, please apply via our online application form and not via LinkedIn. You are disabled under the Equality Act 2010 if you have a physical or mental impairment that has a ‘substantial’ and ‘long-term’ negative effect on your ability to do normal daily activities. For more information about the Disability Confident scheme, please see the government website here.
We welcome applications irrespective of race, colour, ethnic or national origin, disability, sex, gender identity, sexual orientation, age, religion, belief or marital status.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills
Location