Herbert Smith Freehills logo

Analyst, Privacy & Information Security

Herbert Smith Freehills
3 hours ago
Full-time
On-site
Sydney, New South Wales, Australia
Analyst

Herbert Smith Freehills Kramer is a world-leading global law firm, where our ambition is to help you achieve your goals.

 

Exceptional client service and the pursuit of excellence are at our core. We invest in and care about our client relationships, which is why so many are longstanding. We enjoy breaking new ground, as we have for over 170 years.

 

As a fully integrated transatlantic and transpacific firm, we are where you need us to be. Our footprint is extensive and committed across the world’s largest markets, key financial centres and major growth hubs.

 

At our best tackling complexity and navigating change, we work alongside you on demanding litigation, exacting regulatory work and complex public and private market transactions. We are recognised as leading in these areas.

 

We are immersed in the sectors and challenges that impact you. We are recognised as standing apart in energy, infrastructure and resources. And we’re focused on areas of growth that affect every business across the world.

 

All of this is achieved by supporting the growth of our people, who help us deliver on our ambition – which is to help you achieve yours.

 

Herbert Smith Freehills Kramer: Your goals. Our ambition

The Opportunity

We are seeking a proactive and detail-oriented Information Security & Privacy Analyst to support the delivery of the firm's security, privacy, risk and compliance programs across Australia and Asia.

This role will report to Information Security and Privacy team and will work closely with stakeholders across Risk, IT, HR and Legal teams. You will help manage security and privacy initiatives, support client and regulatory compliance requirements, contribute to ISO 27001 certification activities, and assist with risk assessments, awareness programs and operational security processes.

This role is ideal for a professional with experience in information security, privacy, risk or compliance who is passionate about protecting data, enabling secure business practices, and staying ahead of emerging technologies and evolving regulatory requirements.

What you’ll do

  • Support client security and privacy requests, audits, and certification activities.

  • Assist in maintaining and expanding the firm's ISO 27001 certification and Information Security Management System (ISMS).

  • Conduct and support security and privacy risk assessments for new technologies, processes, and ways of working.

  • Assess compliance with client-specific security and privacy requirements across business teams.

  • Support the delivery of the firm's global privacy program, including risk reviews, awareness initiatives, and regional implementation.

  • Monitor and manage user behaviour and data leakage alerts, escalating issues as required.

  • Deliver security and privacy training, awareness, and communications activities.

  • Provide practical security and privacy guidance to stakeholders and support operational issue resolution.

  • Help embed security and privacy controls into business processes and data handling practices.

  • Build strong relationships with key stakeholders across Risk, IT, HR, and legal teams.

  • Monitor emerging security, privacy, regulatory, and client requirements to support ongoing compliance and risk management.

What you’ll bring

This role focuses on governance, risk and compliance aspects of information security and privacy. It is not a technical cyber security operations role, although a strong understanding of IT and cyber security concepts is required.

  • Degree qualified or equivalent experience in information security, privacy, risk, compliance, audit, or a related field.

  • Experience in professional services (desirable but not required).

  • Approximately 3+ years' experience in information security, privacy, risk, compliance, or audit (candidates with less experience and strong capability will also be considered).

  • Working knowledge of ISO 27001, information security management systems, or similar security frameworks and standards.

  • Understanding of privacy and data protection requirements, particularly across Australia and Asia.

  • Strong ability to assess, communicate, and manage security and privacy risks and controls.

  • Excellent written and verbal communication skills, with the ability to engage both technical and non-technical stakeholders.

  • Strong stakeholder management, relationship-building, and collaboration skills.

  • Highly organised, detail-oriented, and able to manage competing priorities in a global environment.

  • Relevant professional certifications, or progress towards them, such as CISA, CISM, CISSP, ISO 27001 Lead Auditor, CIPM, CIPP/E or equivalent (desirable but not required).

  • Is curious about new tech and open to learning, even better if you’re excited about AI!

What you can expect from us

  • We’re a world leading international law firm with a global team of over 6,000 professionals across 26 offices. As the market leader in Australia, we are committed to high performance, collaboration, diversity and digital innovation. We are client-centred, commercially driven, and renowned for our solution-focused expertise. We will align your growth with our ambitions.

  • We make your personal and professional growth our business. And as part of the team, our ambition is yours too. Wherever you are in your career: grow and help the firm grow with you.

  • We will provide opportunities to learn on the job as well as a mix of learning opportunities tailored to you. Daily experiences, supportive challenges, team collaboration, mentors, and structured learning opportunities help you to expand your knowledge and reach your goals.

  • We value your wellbeing, both at home and work and we place a strong emphasis on mental health. If you need support, you’ll have it and we’ll empower you to harness your personal strengths, navigate uncertainty, embrace opportunities, and effectively manage things within your control.

  • For more benefits on offer such as our holistic wellbeing fund or home office allowance please click here.

  • Join us to be part of a human, bold and outstanding team at Australia’s market leading law firm.

We are committed to attracting people from all backgrounds and creating a respectful and inclusive culture where everyone thrives. We see this as essential to our success, including our ability to innovate and achieve sustained high performance. This is a key part of our Values—Human, Bold, and Outstanding.

Team

General Counsel and Risk

Working Pattern

Full time

Location

Sydney

Contract type

Permanent Contract

Diversity & Inclusion

We are committed to attracting people from all backgrounds and creating a respectful and inclusive culture where everyone thrives. We see this as essential to our success, including our ability to innovate and achieve sustained high performance. This is a key part of our Values—Human, Bold, and Outstanding.