Haystack
← Back to Jobs
full time
Legal
CR

Head of IT Security, Professional Services, Legal IT, London

Carrington Recruitment SolutionsWimbledon, South West London🇬🇧United KingdomPosted 23 Sept 2026

Why This Role Stands Out

This Head of IT Security role offers a fantastic opportunity to shape the cybersecurity strategy for a prestigious legal firm, blending hands-on technical expertise with strategic leadership in a hybrid London-based environment. You'll thrive here if you have a strong background in IT and cyber security, ideally within professional services, and possess proven leadership skills to drive impactful security initiatives and mentor a team. This position is ideal for someone looking to make a significant impact within a reputable organization while developing their career in a dynamic legal IT landscape.

Quick Overview

Seniority
Leader
Employment type
Full Time
Work mode
Hybrid
Location
Wimbledon, South West London, United Kingdom
Posted
Yesterday
Compliance

Job Description

Head of IT Security, Head of Cyber Security, ISO27001, NIST, CISM, CISO, Central London Head of IT Security required to work for an exciting Law Firm based in Central London. This will be a hybrid role where you will be expected to be in the office circa 2 days per week, along with travelling to other UK sites on occasions. We need someone with a blended Security background within IT Security, along with Cyber Security. You will be very familiar with CISO set-ups too and will be hands on, as well as strategic. Ideally we are looking for someone from a Law Firm background, or Professional Services at the very least. Ideally you will come from a technical background, whether this be Infrastructure or Security and have then blossomed into Leadership. You MUST have proven Leadership skills too. Experience Required: We are looking for someone who combines senior security expertise with pragmatic leadership and strong stakeholder engagement. You will bring:

  • Senior IT security leadership experience, ideally with exposure to CISO-level responsibilities.
  • Strong knowledge of security operations, identity and access management, cloud and network security, endpoint protection, email security and modern models such as Zero Trust / ZTNA.
  • Experience working with ISO27001, Cyber Essentials Plus and recognised security frameworks such as CIS Controls or NIST.
  • The ability to translate risk and compliance requirements into practical controls, services and improvement plans.
  • Experience managing teams, vendors and managed security services, ideally in a SaaS-focused professional services environment.
  • Clear communication skills, with the confidence to explain complex security topics to senior stakeholders, technical teams and external parties.
  • A pragmatic, outcome-focused and forward-looking approach, with the resilience to work effectively under pressure. This is a great opportunity and salary is dependent upon experience. Apply now for more details

Similar jobs