Quick Overview
Job Description
Role Purpose
Legatics handles some of the world’s most complex and confidential legal transactions, so information security is core to the product and to client trust. The Information Security Manager owns information security across Legatics — setting the vision and strategy, maintaining our ISO 27001 certified ISMS, working hand-in-hand with engineering to embed security into our client-facing products, and acting as the security point of contact for our clients and business teams.
Reporting to the Head of Engineering, the role spans technical security, compliance and governance, client assurance, and the day-to-day operation of our security and IT tooling. It is a broad, hands-on role with a high degree of autonomy to shape direction as Legatics scales.
This is a fixed-term appointment covering a period of maternity leave. The expected duration is approximately 12 months from the start date, although the actual end date will depend on the return date of the current postholder and may fall slightly earlier or later. You will have full ownership of the remit set out below for the duration of the contract, with the same autonomy, access and support as a permanent member of the team.
About Legatics
Legatics is one of the world’s leading LegalTech scale-ups. Our legal transaction management platform enables law firms and their clients to collaborate on and close deals in an interactive online environment, providing clarity, reducing risk and saving time.
Our customers include some of the world’s top law firms, such as Allen & Overy Shearman, Hogan Lovells, Herbert Smith Freehills, and King & Wood Mallesons. And we’ve been used on transactions in more than 60 countries on transactions worth over $1 trillion.
The contract
This role is offered on a fixed-term basis to provide cover during a colleague's maternity leave, with an anticipated duration of around 12 months.
A few things worth knowing:
- You will be employed on the same terms and benefits as our permanent employees, including private medical insurance, health cash plan and pension.
- The contract may be extended if the period of cover changes, and we will always give you as much notice as we can of the confirmed end date.
- Where a suitable permanent role exists at the end of the contract, we will discuss it with you. We are being deliberate in not promising this, because we would rather be straight with you than imply something we cannot guarantee.
- Fixed-term does not mean holding the fort. We are looking for someone who will genuinely own and advance our security posture during their time here, and we expect the work you do to outlast the contract.
Key responsibilities
Security strategy, posture and governance
- Own the vision, direction and roadmap for information security at Legatics, and continue developing the overall security posture, processes, systems and controls.
- Maintain up-to-date knowledge of the threat landscape, emerging best practice and tooling, and translate this into Legatics’ security priorities.
- Develop and run a strategy for continuous security and resilience testing — for example penetration testing, red-team exercises and threat modelling (such as self-hosted GitLab versus consumed SaaS).
- Build relationships with relevant industry bodies and security peers at similar organisations.
ISO 27001 and compliance (ISMS ownership)
- Own ISO 27001 certification and the Information Security Management System (ISMS), including ongoing maintenance and continuous audit readiness; align the ISMS to ISO 27001:2022.
- Maintain the Master Document List, version control and approvals across all policies, and keep ISO documentation tracked in a central system (e.g. the Notion ISO database).
- Finalise and maintain the Statement of Applicability (SoA), and keep the ISMS Manual current.
- Review and maintain core policies — including the Acceptable Use Policy, Access Control Policy, and Incident Response & Breach procedure — and keep the ISMS Risk Register up to date.
- Document and operate the threat intelligence process; maintain the Interested Parties register and the analysis of internal/external issues (PESTLE).
- Produce and maintain the ISMS Communication Plan and associated tracking (e.g. CROO and SoA).
- Run periodic user access reviews across Google Workspace and SaaS platforms.
- Collect, organise and maintain audit evidence, including:
- Change-control tickets with security approval evidence
- Incident log and resolution documentation
- Vendor security assessments and contracts
- Backup restore test evidence
- Vulnerability scan results and mitigation logs
- Business continuity scenario tests (e.g. power/internet outage, key-person unavailability, data exposure, phishing)
- Fire safety report and extinguisher servicing log; Employers’ Liability insurance certificate
- Security induction and ongoing training completion, and employee policy acknowledgements
- Prepare staff and evidence for external surveillance and recertification audits.
Client security assurance
- Complete client information security questionnaires (ISQs) and respond to customer security queries, including requests raised by the customer-facing team via Slack.
- Provide client-facing security remediation updates (e.g. on penetration test findings) and discuss Legatics’ security posture directly with clients and prospects.
- Attend client meetings, remotely or on-site, as required.
- Build and improve tooling to speed up and standardise questionnaire responses (e.g. an ISQ assistant / Claude plugin).
Application and product security
- Conduct technical risk assessments on product features (e.g. data room file-viewer permission boundaries), assess compliance risk for legal-sector clients, and advocate for server-side enforcement of access controls rather than UI-only restrictions.
- Perform vulnerability and exploitability analysis (e.g. CVE triage within our detection services and end-of-life dependencies), and prioritise remediation based on real exposure.
- Review the security risk of proposed integrations and data flows (e.g. third-party automation routing source code or data externally), and maintain the vendor risk register.
- Operate and consolidate security scanning (e.g. Prowler, SonarQube, Grype/Syft) and evaluate aggregation tooling such as DefectDojo to centralise findings.
Cloud, identity and endpoint security
- Audit and harden cloud and identity posture across Google Workspace (e.g. ScubaGoggles, GAMADV-XTD3) and Microsoft Entra ID, including SSO/SAML enforcement, conditional access, and onboarding/offboarding automation.
- Resolve identity and email-security issues such as OAuth/app-access controls, SAML enforcement, and email authentication (DMARC/DKIM).
- Own endpoint security — EDR (SentinelOne) across approximately 50 Windows and Mac endpoints — including detection policy tuning, phased rollout, developer-environment exclusions, and validation (e.g. EICAR testing).
- Design and maintain federated authentication (e.g. Google Credential Provider for Windows) with appropriate rollout guides and rollback procedures.
Security monitoring and detection
- Develop, extend and maintain security monitoring, reporting and tracking tools covering the full technical estate, including SIEM, log aggregation and correlation (e.g. forwarding EDR alerts into Datadog).
- Tune monitoring rules and alert configurations to improve signal quality and reduce false positives.
- Maintain threat-awareness pipelines (e.g. automated security-news aggregation into a dedicated Slack channel).
Incident response
- Lead detection, triage, containment and response for security incidents (e.g. supply-chain compromises affecting third-party tooling); assess blast radius and advise on practical containment given platform constraints.
- Draft and issue incident communications tailored to both technical and non-technical audiences, and maintain escalation and breach procedures.
AI security and governance
- Set Legatics’ AI security posture, positioning security as an enabler for teams building with autonomous AI tools, and map controls to relevant frameworks (e.g. OWASP Top 10 for Agentic Applications).
- Implement access controls, security architecture and detection rules for internal AI systems (e.g. the AI Brain knowledge base).
- Research AI coding risks — such as generative monoculture, slopsquatting and hallucinated-package attacks — and feed findings into engineering practice and our AI coding risk posture.
- Harden the AI tooling and automation surface used by security and engineering (e.g. secure Claude Code workflows, secrets scanning, and MCP integrations).
IT operations and tooling support
- Handle day-to-day IT support across the team, including MCP connector provisioning and permissions troubleshooting for staff integrating internal tools.
- Administer Claude Team connectors and clarify pre-built versus custom connector provisioning for team members.
- Support internal data tooling (e.g. BigQuery, service accounts, Google Sheets integration), including IAM role configuration, OAuth scope grants and external table management.
What we need from you
The ideal candidate will have a mix of technical, compliance and communication skills. You do not need every item below — if you have strong foundations and are keen to learn the rest, we’d like to hear from you.
- Experience in an information security or cyber-security role, as a lead or individual contributor.
- Strong knowledge of fundamental internet technologies, Linux systems, cloud infrastructure and networking — and their real-world use and abuse.
- Experience with SIEM, log and traffic analysis, monitoring, reporting and auditing approaches.
- Hands-on experience managing an ISMS and ISO 27001 compliance (ISO 27001:2022 desirable), including audit preparation and evidence management.
- Confident completing client information security questionnaires and discussing security posture directly with customers and prospects.
- Familiarity with cloud and identity platforms (Google Workspace, Microsoft Entra ID, SSO/SAML) and endpoint/EDR tooling.
- Application security and vulnerability triage, and vendor / third-party risk assessment.
- An interest in, or experience of, AI and agentic security risks (a growing part of the role).
- Solid communication skills, able to work with and influence both technical and non-technical stakeholders.
- Experience in a startup or scale-up environment is beneficial.
- A right to work in the UK (unfortunately, we are not in a position to support visa sponsorship at this stage)
- An ability to work from our London office at least twice a week.
What we offer you:
- 25 days holiday per year (plus public holidays).
- Early Finish Fridays - on the last Friday of every month, we finish around lunchtime!
- Pension with NEST.
- Private Medical Insurance with Bupa, giving you fast access to diagnosis and treatment when you need it.
- Healthshield Health Cash Plan, helping you claim money back on everyday healthcare like dental, optical and physio.
- Personal Learning & Development budget.
- Access to Mental healthcare for you and your immediate family.
- Enhanced parental leave policies so you can spend more time with your family.
- Lots of opportunities for accelerated professional development and career progression.
- Work alongside a supportive and talented team with the opportunity to grow one of the world’s leading LegalTech scale-ups.
- A warm, genuinely collaborative culture and an awesome team; and
- Regular socials.
Power in diversity
We put users at the heart of our design to provide legal transaction experiences that everyone loves. In order to make that a reality, we seek to foster a diverse and inclusive working environment that can empower our people to be creative, effective and innovative, to build a brand we are proud of.
We don’t discriminate against gender, race, religion or belief, disability, age, marital status or sexual orientation. Whatever your background may be, we welcome anyone with talent, drive and emotional intelligence. We're committed to building a diverse team and are constantly looking for ways to improve our processes to help us do that.
Similar jobs
- HA
Senior Cyber Software Engineer Technical Lead
Hackajob Ltd
Charing Cross, Central London🇬🇧Remote2 weeks agoC#C++Java+4Technology - FY
L3 SOC Eng
Fynity
Aylesbury, Buckinghamshire🇬🇧On-site4 weeks ago - PR
Head of Protective Security Services
NewPrevail
London🇬🇧Hybrid6 hours agoBusiness DevelopmentComplianceContinuous Improvement+4 - DR
Cyber Security Architect
NewDGH Recruitment Ltd.
Birmingham🇬🇧Hybrid1 hour agoAzureStakeholder ManagementZero TrustTechnology - SS
Security Engineer
NewSmartedge Solutions Ltd
London🇬🇧Hybrid1 hour agoGenerative AIGitJenkins+3Technology - AP
Network Security Solutions Engineer
NewAmtis Professional Ltd
Oxford, Oxfordshire🇬🇧£47k/yrRemote1 hour agoTechnology