Herbert Smith Freehills Kramer logo
Herbert Smith Freehills KramerPosted 2 weeks ago

Analyst, Privacy & Information Security

On-siteSydney, New South Wales, Australia

Full TimeSenior LevelEnterprise

Job Summary

Support client security and privacy requests, audits, and certification activities while maintaining and expanding the firm's ISO 27001 certification and Information Security Management System. Conduct security and privacy risk assessments for new technologies, processes, and ways of working, and assess compliance with client-specific requirements across business teams. Monitor and manage user behaviour and data leakage alerts, escalate issues as required, and deliver security and privacy training, awareness, and communications activities. Provide practical guidance to stakeholders and help embed security controls into business processes and data handling practices. Build strong relationships with key stakeholders across Risk, IT, HR, and legal teams to monitor emerging regulatory and client requirements.

Required Qualifications

  • Degree qualified or equivalent experience in information security, privacy, risk, compliance, audit, or a related field
  • Approximately 3+ years' experience in information security, privacy, risk, compliance, or audit
  • Working knowledge of ISO 27001, information security management systems, or similar security frameworks and standards
  • Understanding of privacy and data protection requirements, particularly across Australia and Asia
  • Strong ability to assess, communicate, and manage security and privacy risks and controls
  • Excellent written and verbal communication skills
  • Strong stakeholder management, relationship-building, and collaboration skills
  • Highly organised, detail-oriented, and able to manage competing priorities in a global environment
  • Strong understanding of IT and cyber security concepts

Desired Qualifications

  • Experience in professional services
  • Relevant professional certifications, or progress towards them, such as CISA, CISM, CISSP, ISO 27001 Lead Auditor, CIPM, CIPP/E or equivalent
  • Curiosity about new tech
  • Openness to learning
  • Excitement about AI

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce