Head of Information and Cyber Security

The Law Society

Apply now

Welcome

At the Law Society, we have a rich history stretching back 200 years to 1825. Throughout that time as the independent professional body for solicitors in England and Wales, we have worked hard to promote the value of the profession, protect the justice system and support our members.

Today, our 400 employees and 400 dedicated volunteers serve a community of 200,000 members. This year marks a significant milestone: we celebrated our bicentenary and achieved Gold accreditation from Investors in People, reflecting our commitment to being an employer of choice for those who want to make a difference.

With the launch of our new three-year strategy, we are driving a transformation in technology delivery and management to align with our strategic goals. These newly created roles will be pivotal in shaping that change and fostering a member-centric approach—anticipating needs, enhancing capabilities, and making the Law Society an exceptional place to work.

Our teams work relentlessly on all kinds of projects, both large and seemingly small, but all crucial to our members and achieving our ambitions. The scale and complexity of our work behind the scenes can be surprising – for a small organisation we cover an unexpected breadth of activity.

It really is a privilege to work on so many fascinating issues, and to do so with so many passionate and motivated people across our staff and volunteer communities. Our greatest strength comes from the diversity of experience, expertise and skills of our people – all pulling together towards our collective goals.

We wish you every success with your application and look forward to welcoming the successful candidates to help us achieve our ambitions for the future.

Kate Evans
Executive Director - Technology & Change

About The Law Society

We are the professional body for solicitors in England and Wales.

Founded in 1825, our mission is to promote, protect and support solicitors, the rule of law and access to justice.

We promote the value of the profession and champion the £60 billion contribution the legal sector makes each year to the UK economy.

Our members are at the heart of all we do. We amplify the powerful collective voice of more than 200,000 solicitors with diverse experiences and backgrounds, advocating on the issues that matter to our members most.

Our Governance

We’re governed by our Council, supported by our Board and committees with invaluable contributions from our wider elected and appointed members who help set our strategic direction.

Our Council is supported by the Board and several committees, including:

  • Policy and Regulatory Affairs Committee.
  • Membership and Communications Committee.
  • Finance and Investment Committee.
  • People and Remuneration Committee.
  • National Board for Wales.

Our Board

The Board is responsible for:

  • Overseeing the effective implementation of our strategy and business plan, as set by Council.
  • Dealing with financial matters and risk management on behalf of Council.
  • Recommending approval of the budget to Council.
  • Making sure the Law Society is well governed.

Read more about our governance structure here

The role

Security Operations and Engineering Manager (AQ3726)

Apply now

JOB DESCRIPTION

Directorate: Technology & Data
Department: Information and Cyber Security
Team: Information and Cyber Security
Grade: Senior Specialist / Leader A
Reports to: Head of Information and Cyber Security
Line management responsibilities: Yes
Location: London

Role overview

The Security Operations and Engineering Manager is responsible for the operational effectiveness of The Law Society’s cyber security capability. The role leads security engineering, coordinates cyber incident response, manages the organisation’s security technology platforms and oversees the performance of outsourced security operations services. Working closely with internal Technology teams and third-party security partners, the role continuously improves detection, response and resilience, ensuring security controls remain effective and aligned with business risk.

The role serves as the technical lead for cyber security operations and major incidents, while ensuring external security partners deliver agreed outcomes.

Core duties of the role:

The post holder will:

  • Own and improve the security teams’ operational capability by managing outsourced security services, ensuring security alerts and escalations are fully managed to resolution, validate incident severity and impact and ensure incident response processes are defined and followed.
  • Manage the outsourced SOC service by defining operational requirements and improvements, monitoring SLA and KPI performance and creating monthly operational reporting.
  • Lead the design, implementation and continuous improvement of the security controls for Identity, cloud, endpoint, email and data.
  • Lead technical incident responses by creating and maintaining incident playbooks, managing technical investigation teams (internal and external), engagement of forensic partners and conducting post incident reviews to ensure remediation actions are completed.
  • Own the continuous improvement of detection capabilities by working with internal and external teams to reduce false positives and improve early detection.
  • Lead technical exposure management by reviewing vulnerabilities, reviewing remediation and tracking risk acceptance.
  • Lead and continually develop the operational effectiveness of the security platforms implemented.
  • Ensure technical assurance and security by design is adopted for all new projects and solutions.
  • Produce meaningful security operational reporting to include detection, platform health, Incidents and overall maturity.
  • Manage and develop the security team to provide a great service to its customers.
  • Effectively collaborate with internal teams in relation to cybersecurity audits, including the resolution of outstanding actions.
  • Manage the creation and regular updating of security policies.

Skills and attributes:

Criteria (knowledge, skills and attributes)

  • Strong experience of managing and leading a team (Assessed by interview)
  • Strong skills in Microsoft Security platforms including Defender, Sentinel, Entra ID, Purview and Intune (Assessed by interview)
  • Strong understanding of mail filtering technologies (Assessed by interview)
  • Experience designing and implementing zero trust controls (Assessed by application form)
  • Strong skills in detection engineering and SIEM tuning (Assessed by application form)
  • Strong skills in cloud and identity security (Assessed by interview)
  • Experience with vulnerability management  (Assessed by application form)
  • Experience in incident response leadership (Assessed by interview)
  • Experience with threat intelligence applications (Assessed by application form)
  • Excellent understanding of security frameworks (NIST CSF, ISO27001 and Cyber Essentials) (Assessed by interview)
  • Strong stakeholder and supplier management experience (Assessed by interview)
  • Coaching and mentoring skills (Assessed by interview)
  • Microsoft Certified Cyber Security Architect Expert (SC-100) (Assessed by application form)
  • Microsoft Certified Security Operations Analyst (SC-200) (Assessed by application form)
  • ISC2 CISSP (Assessed by application form)
  • ISACA CISM (Assessed by application form)
  • SANS institute GIAC certification (Assessed by application form)

Terms of appointment

This is an excellent opportunity to work in an organisation which has recently achieved gold accreditation from Investors in People in recognition of its work over the last few years focusing on being an employer of choice for people who want to make a difference.

You will join an organisation with a reputation for excellence, commitment to EDI, development and wellbeing, and a culture of clarity, trust, and respect. We offer hybrid working, a generous flexible benefits package, a positive working environment and the opportunity to develop your career within a professional organisation.

Annual leave

  • Full-time staff get 25 days of annual leave, in addition to public holidays. This increases to:
    • 27 days after two years’ service
    • 30 days after five years’ service
  • If you’re a part-time employee, the allowance is calculated pro rata based on your contracted hours.

Pension (DC Scheme)

  • Defined contribution (DC) schemes are occupational pension schemes where your own contributions and your employer’s contributions are both invested.
  • Employees can join the pension, including the salary sacrifice pension scheme, at any point in the year.
  • We contribute two times our employees’ contributions up to 3.5% of your notional base pay, and one and a half times any contributions you make between 3.5% and 7%.
    • Notional pay is your salary before salary sacrifice.
    • If you contribute 7% of your notional base pay, our contribution will be 12.25%.
    • If you contribute more than 7%, our contribution will remain at 12.25%.

Flexible allowance

  • You can take an additional 3% of annual basic salary (non-consolidated, non-pensionable) as income, paid monthly, or use it to buy additional benefits.
  • You can only buy additional benefits after you complete your probation.
  • The benefits purchase window opens once a year for you to make your selections.

Life assurance

  • You’re covered for a lump sum life assurance cover of four times your notional base pay if you die while working at the Law Society, up until the age of 75.

Private medical insurance

  • Eligibility for this taxable benefit is dependent on length of service and pay grade.

Health screening

  • All staff are eligible for this tax-free benefit after they’ve completed two years of employment.

Season ticket loan

  • A season ticket loan of up to £8,000 is available after you complete your probation.

Help with professional development

  • Providing certain conditions are met, we offer:
    • study leave of up to 5 days in a 12-month period to support longer-term programmes of study and sitting exams
    • funding of up to £2,000 and assistance with buying essential materials
    • books of up to £200 per year

Maternity leave

  • You can take up to 12 months’ absence while on maternity leave.
  • The payment amounts during this time vary depending on your length of service.

Paternity leave

  • You’re entitled to two weeks’ ordinary paternity leave.
  • You can take additional leave of up to 26 weeks, provided certain conditions are met.

Childcare allowance

  • Employees returning from maternity, paternity or adoption leave are eligible for a supplementary allowance of £200 per month for a period of six months.

Health club membership

  • We offer subsidised health club membership after you complete your probation. This is a company-funded and taxable benefit.

Please note: if you are an internal applicant, Pay Policy will apply.

How to apply

Anderson Quigley is acting as an advisor to The Law Society. An executive search process is being carried out by Anderson Quigley in addition to the public advertisement.

The closing date for applications is 31 August 2026.

Applications should consist of:

  • A full CV.
  • A covering letter  (2 pages of A4) outlining your motivation and details of how you meet the qualification, skills and experience criteria of the person specification.
  • Please include details of two referees in your CV, though please note that we will not approach your referees without your prior consent and only should you be shortlisted.

Should you wish to discuss further details about the role in strict confidence, please get in touch with Grace Tattersall at grace.tattersall@andersonquigley.com or +44 (0)7510 384 761.