21 Aug
|
Herbertsmithfreehills
|
City of Sydney
21 Aug
Herbertsmithfreehills
City of Sydney
Herbert Smith Freehills Kramer: Your goals. Our ambition
Herbert Smith Freehills Kramer is a world-leading global law firm, where our ambition is to help you achieve your goals.
Exceptional client service and the pursuit of excellence are at our core. We invest in and care about our client relationships, which is why so many are longstanding. We enjoy breaking recent ground, as we have for over 170 years.
As a fully integrated transatlantic and transpacific firm, we are where you need us to be. Our footprint is extensive and committed across the world's largest markets, key financial centres and major growth hubs.
At our best tackling complexity and navigating change, we work alongside you on demanding litigation, exacting regulatory work and complex public and private market transactions. We are recognised as leading in these areas.
We are immersed in the sectors and challenges that impact you. We are recognised as standing apart in energy, infrastructure and resources. And we're focused on areas of growth that affect every business across the world.
All of this is achieved by supporting the growth of our people, who help us deliver on our ambition - which is to help you achieve yours.
The Opportunity
We are seeking a proactive and detail-oriented Information Security & Privacy Analyst to support the delivery of the firm's security, privacy, risk and compliance programs across Australia and Asia.
This role will report to Information Security and Privacy team and will work closely with stakeholders across Risk, IT, HR and Legal teams. You will help manage security and privacy initiatives, support client and regulatory compliance requirements, contribute to ISO 27001 certification activities, and assist with risk assessments, awareness programs and operational security processes.
This role is ideal for a professional with experience in information security, privacy, risk or compliance who is passionate about protecting data, enabling secure business practices, and staying ahead of emerging technologies and evolving regulatory requirements.
What you'll do
- Support client security and privacy requests, audits, and certification activities.
- Assist in maintaining and expanding the firm's ISO 27001 certification and Information Security Management System (ISMS).
- Conduct and support security and privacy risk assessments for new technologies, processes, and ways of working.
- Assess compliance with client-specific security and privacy requirements across business teams.
- Support the delivery of the firm's global privacy program, including risk reviews, awareness initiatives, and regional implementation.
- Monitor and manage user behaviour and data leakage alerts, escalating issues as required.
- Deliver security and privacy training, awareness, and communications activities.
- Provide practical security and privacy guidance to stakeholders and support operational issue resolution.
- Help embed security and privacy controls into business processes and data handling practices.
- Build strong relationships with key stakeholders across Risk, IT, HR, and legal teams.
- Monitor emerging security, privacy, regulatory, and client requirements to support ongoing compliance and risk management.
What you'll bring
- This role focuses on governance,
risk and compliance aspects of information security and privacy. It is not a technical cyber security operations role, although a strong understanding of IT and cyber security concepts is required.
- Degree qualified or equivalent experience in information security, privacy, risk, compliance, audit, or a related field.
- Experience in skilled services (desirable but not required).
- Approximately 3+ years' experience in information security, privacy, risk, compliance, or audit ( candidates with less experience and strong capability will also be considered ).
- Working knowledge of ISO 27001, information security management systems, or similar security frameworks and standards.
- Understanding of privacy and data protection requirements, particularly across Australia and Asia.
- Strong ability to assess, communicate, and manage security and privacy risks and controls.
- Excellent written and verbal communication skills, with the ability to engage both technical and non-technical stakeholders.
- Strong stakeholder management, relationship-building, and collaboration skills.
- Highly organised, detail-oriented, and able to manage competing priorities in a global environment.
- Relevant professional certifications, or progress towards them, such as CISA, CISM, CISSP, ISO 27001 Lead Auditor, CIPM, CIPP/E or equivalent ( desirable but not required ).
- Is curious about new tech and open to learning, even better if you're excited about AI!
What you can expect from us
We're a world leading international law firm with a global team of over 6,000 professionals across 26 offices. As the market leader in Australia, we are committed to high performance, collaboration, diversity and digital innovation.
#J-18808-Ljbffr
📌 Analyst, Privacy & Information Security (City of Sydney)
🏢 Herbertsmithfreehills
📍 City of Sydney