-
Herbert Smith Freehills Kramer

Information Security Analyst

Herbert Smith Freehills Kramer
United States · Full-time · Not Applicable

Key Tasks and Responsibilities

  • Assist the Director of Information Security with overall management of the Information Security Program and maintenance of the firm’s ISO certification. Collect and present required evidence in preparation for and during internal / external audits.
  • Participate in the administration of the security awareness training program. Create training simulations, facilitate topic-specific training presentations, help coordinate tabletop exercises.
  • Provide frontline response for information security incidents. Investigate, resolve, track, and follow-up as needed. Identify and report on incident root cause and potential remediation.
  • Assist with Vendor Risk Management and security questionnaire response. Manage and update question/response knowledgebase.
  • Take ownership of level-one incident triage, threat detection and forensics. Use input from various security tools and SIEM solutions to analyze security events for indicators of compromise.
  • Generate analytical figures, reports and dashboards regarding threat and vulnerability findings as necessary.
  • Provide additional inputs for further investigations based on security events.
  • Respond to security incidents across a wide array of technologies, mitigate and contain impacts, coordinate remediation efforts, summarize and make recommendations for improvements
  • Provide up-to-date reports on security incidents and task progress, and centrally track, in a timely fashion, incoming and existing findings.
  • Assist the Director of Information Security to support security strategy by outlining the requirements and benefits of specific security tools and/or solutions.
  • Interface with groups and individuals to conduct reviews and resolve security issues related to implementation of security products.
  • Efficiently manage multiple simultaneous tasks across new projects and existing systems, including management of on-call duties.
  • This position requires ongoing availability due to the need to efficiently respond to security events and alerts.


Requirements/Background

  • Experience conducting security vulnerability assessments, incident response, and internal/external audits is required.
  • Experience or demonstrated knowledge of working with the ISO/IEC 27001 standard and compliance is required.
  • Information security related certification such as CISA (Certified Information Security Auditor), Certified Ethical Hacker (CEH), Security+ or related is a plus.
  • Associate or Bachelor’s degree in cybersecurity, systems engineering, computer science, computer engineering, information technology, management information systems or equivalent.
  • Appropriate English writing and composition skills related to technical documentation. This includes drafting processes, standards and procedures for management review/revision.
  • Solid analytical/problem-solving skills with capability to identify solutions to unusual and complex problems.
  • Strong command of Microsoft Office applications. Including Word, Excel, PowerPoint, and Outlook.
  • Understanding of cloud technology and networking fundamentals is desirable.
  • Knowledge and experience with security and threat analytic tools. (Qualys Vulnerability Management, Darktrace, SecureWorks Taegis, and others)
  • Understanding of operating system architecture. Microsoft Windows, mobile devices, etc.
  • Must have understanding of information systems security; network architecture; network security; general database concepts; document management; Email Messaging (MS Exchange), Document Management Systems; intrusion detection and forensic tools.
  • 3+ years Security Analyst experience in a law firm, or major corporation is desired
  • Must have passion for Information Security, a desire to continuously learn and stay current on the information security industry.


Salary range: $120,000 - $140,000, dependent upon experience level.

Key Skills

Ranked by relevance

incident response network security cybersecurity powerpoint cloud excel cisa siem ceh
Login to Apply
Posted
May 28, 2025
Type
Full-time
Level
Not Applicable
Location
New York

Industries

Law Practice

Categories

Information Technology

Related Jobs

3 roles aligned with this opportunity

View all jobs
View Job Details
DGH Recruitment
Related

Cyber Security Analyst

2026-05-12

Full-time
Entry
United Kingdom
Law Practice
Information Technology
View Job Details
DGH Recruitment
Related

Cyber Security Analyst

2026-04-24

Full-time
Entry
United Kingdom
Law Practice
Information Technology
View Job Details
Finoa
Related

VP Information Security —

2026-07-11

Full-time
Executive
Lithuania
Technology
Information Technology