Chief Information Security Officer (CISO)
Requirements
The role requires significant leadership experience in information security, including expertise in cyber incident response and digital forensics. Candidates must possess a strong understanding of UK regulatory requirements, GDPR, and security technologies, particularly within Microsoft Azure environments.
Job Description
Department: CSG - Business Operations (Audit / Risk / Client Account Management / Finance / Legal / People / Procurement / Property and Facilities / Sales and BD / IT)
Location: Remote - England and Wales
Are you an experienced information security leader looking to make a real impact? We're seeking a Chief Information Security Officer (CISO) to take ownership of our information security strategy, regulatory compliance, and cyber resilience framework.
As CISO, you will play a pivotal role in protecting sensitive client data, legal case information, and financial records while ensuring compliance with GDPR, SRA requirements, and broader regulatory obligations. This is a strategic leadership position offering the opportunity to shape and mature our security posture across the organisation.
About the Role
Working closely with the Chief Technology Officer and senior leadership team, you will develop and implement a comprehensive security strategy that protects the business from evolving cyber threats while maintaining regulatory compliance and client trust.
You will act as the organisation's subject matter expert for information security, data protection, risk management, and incident response.
What you will do?
- Develop and own the organisation's information security strategy, roadmap, and risk management framework.
- Working with our MSSP, lead the response to security incidents, coordinating investigations, remediation activities, and stakeholder communications.
- Working with our Group Legal and colleagues, implement effective risk and compliance governance to ensure GDPR and data protection compliance, including DPIAs, data processing agreements, and data subject requests.
- Ensure compliance with Solicitors Regulation Authority (SRA) requirements and relevant information security standards.
- Manage third-party security assessments and vendor risk reviews, including technology, finance, and AI solution providers.
- Establish and maintain security controls covering data classification, access management, encryption, monitoring, and logging.
- Drive a culture of security awareness through training, education, and incident response exercises.
- Manage relationships with external Managed Security Service Providers (MSSPs) to ensure effective service delivery and governance.
- Provide clear, business-focused reporting on security risks to executive leadership and regulators where required.
- Significant experience in information security, including leadership experience at CISO, Head of Security, or equivalent level.
- Strong knowledge of GDPR, UK GDPR, the Data Protection Act 2018, and wider UK regulatory requirements.
- Experience operating within highly regulated environments.
- Proven experience in cyber incident response, breach management, and digital forensics.
- Strong understanding of the latest information security technologies and best practice deployment, particularly within Microsoft Azure environments.
- Excellent communication and stakeholder management skills with the ability to translate technical risks into business language.
- Experience developing security strategies, policies, and governance frameworks.
- High levels of flexibility and a great work life balance - https://www.dacbeachcroft.com/en/Work-with-us/Whats-in-it-for-you
- A well-rounded remuneration package (which includes private medical insurance, income protection insurance and discounted gym membership, amongst many other benefits)
- Opportunities for growth and progression including professional funding
- In person and remote social events
- Opportunity to get involved in a range of Environmental, Social and Governance (ESG) activities
We are happy to talk flexible working with our Flex Forward scheme. We would encourage you to talk to us about our approach to flexible working during the hiring process if you would like to explore this further.
Note for Recruitment Agencies
DAC Beachcroft manages all vacancies via our in-house recruitment teams, prioritising direct sourcing and referrals. When external support is required, roles are released to selected agencies on our Preferred Supplier List (PSL).
Speculative CVs sent to any DAC Beachcroft employee without prior instruction from our recruitment teams (LLP and CSG) will not be accepted, and no fees will be payable.
For PSL queries, please contact: recruitment@dacbeachcroft.com or csgrecruitment@dacbeachcroft.com
Skills
About DAC Beachcroft
DAC Beachcroft is a leading international legal business with offices across Europe, Latin America, North America and Asia Pacific. We partner with our clients to help them achieve sustainable growth and to defend their business and reputation. We do this by taking a tailored approach to providing commercial, transactional, claims, risk and advisory legal services. We are recognised leaders in Insurance, Health and Real Estate and draw on the knowledge, industry experience and commercial expertise of our outstanding 3,000 lawyers and support colleagues in these sectors and beyond. We are forward-thinking, flexible and easy to engage with and we're proud that our clients tell us regularly that we're great to work with. We know that our clients value advice that is innovative, practical and personal to them, and we pride ourselves on getting to the heart of their businesses. We measure our performance against their expectations and embrace change as a necessary stage in evolving and strengthening our relationships. The close working relationship we enjoy with our clients has not been built overnight but honed carefully over the last 250 years. This means today our clients can remain confident they have the very best legal expertise available.
View company profile →