Information Governance, Communications, and Policy Specialist at a respected law firm. Responsible for enhancing the firm's Information Security Management System and ensuring compliance with regulations.
Responsibilities
Develop, draft, and maintain internal IT and security policies aligned with ISO27001, GDPR, and other relevant regulatory frameworks.
Collaborate with IT, Risk, and Compliance teams to ensure policies are practical, effective, and accurately reflect operational processes.
Monitor regulatory updates from key bodies, perform gap analysis, and recommend necessary policy improvements to ensure continuous compliance.
Support the end-to-end internal and external audit process for ISO27001, assisting with corrective actions and maintaining all required evidence.
Act as the primary point of contact for responding to client security questionnaires and due diligence requests.
Champion internal security awareness initiatives, including training and communications, to foster a robust security culture.
Ensure all governance documentation is meticulously structured, version-controlled, and audit-ready at all times.
Requirements
A degree in Business, IT, Computing, Law, or a related field.
Progressive experience in a role focused on information governance, compliance, policy management, or IT audit.
A strong understanding of information security frameworks, particularly ISO27001, and the principles of policy and procedure documentation.
Experience within a regulated environment (e.g., financial services, corporate services, iGaming, or law firms) is highly beneficial.
Excellent written and verbal communication skills in English, with the ability to create clear, structured, and polished documentation.
A proactive and detail-oriented mindset with a proven ability to improve processes and documentation frameworks.
Strong collaborative skills with the ability to communicate confidently and effectively with stakeholders at all levels.
Relevant certifications (or progress towards) such as CISA, CISM, CISSP, or CRISC would be considered an asset.
Benefits
Competitive Compensation: You will receive a highly competitive compensation package, which includes a competitive base salary, performance bonuses, and other incentives, all reflective of your experience and contribution.
Work-Life Balance: We value work-life balance and offer flexible working arrangements, recognising that achieving your best in your career requires a healthy balance between work and personal life.
Job title
Information Governance, Communications, Policy Specialist
Senior Associate in Business Operations focused on technology - enabled solutions for PwC's digital market growth. Involves innovation, planning, and contract management in Argentina.
Senior Associate in Climate Risk and Resilience at PwC Canada supporting clients in addressing climate change challenges. Delivering insights through data analytics and climate science expertise.
Junior Risk Manager focusing on quantitative analysis and risk management within private markets investment management. Supporting decision - making and developing proprietary quantitative tools.
Senior Associate role within PwC Risk Consulting assisting clients in internal audit and risk management strategies. Responsible for improving internal controls and mitigating risks across diverse teams.
Managing a segment of a program or function at HII’s Newport News Shipbuilding. Overseeing program performance, technical performance, and new technology development.
Associate on Clearing Policy & Market Structure team providing insights into market structure changes. Supporting regulatory engagement and developing materials for external communication.
Lead IT Governance, VMO, and Innovation teams ensuring alignment between strategy and control. Drive strategic initiatives and influence decisions for TI at Grendene.
Risk Manager managing Garney’s insurance and surety programs. Ensuring financial stability through risk mitigation and insurance coverage for catastrophic losses.
Consultant Data Governance focusing on data integration and governance within asset management. Involved in a strategic transformation program post merger of major asset management players.