Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Senior Security GRC Manager (AI Governance): Own and lead the assurance program including certifications, AI governance, and risk management for a legal AI software product. With an accent on compliance frameworks like SOC 2, ISO 27001, and AI regulatory requirements. Focus on designing unified controls, managing risk registers, and collaborating with auditors, regulators, and customer security teams.
Location: On-site in New York City, USA
Company
Legora is a legal AI software company trusted by 1,000+ customers worldwide, delivering AI-native workspaces that accelerate legal workflows with precision and speed.
What you will do
- Own and manage SOC 2 Type II, ISO 27001, and ISO/IEC 42001 certifications and audit processes.
- Lead the AI governance program including risk classification and alignment to NIST AI RMF and EU AI Act compliance.
- Design and maintain a unified controls library mapped across multiple compliance frameworks.
- Manage enterprise risk register and policy lifecycle, collaborating with engineering to automate controls.
- Support business continuity and disaster recovery programs with impact analysis and recovery testing.
- Serve as the primary contact for auditors, regulators, and customer security teams on assurance matters.
Requirements
- Location: Must work onsite in New York City, USA
- 6+ years in GRC, security compliance, or IT audit with experience owning SOC 2 and/or ISO 27001 in B2B SaaS.
- Working knowledge of AI governance frameworks (ISO 42001, NIST AI RMF) and EU AI Act or ability to quickly learn new regulatory domains.
- Experience with continuous assurance models and ability to verify controls including reading code and infrastructure-as-code.
- Strong enterprise risk management experience with leadership engagement.
- Clear, precise writing skills for policies and risk narratives read by legal professionals.
Nice to have
- Certifications such as ISO 42001 Lead Auditor, ISO 27001 Lead Auditor, CISA, or CISSP.
- Experience selling trust to law firms, financial services, or other regulated industries.
- Knowledge of GDPR, CCPA, and cross-border data transfer regulations.
- Exposure to AI-agent assurance or certification of AI products.
- Experience with public-sector assurance frameworks like FedRAMP or IRAP.
Culture & Benefits
- Global collaboration with teams and clients across Europe, APAC, and North America.
- Competitive salary and comprehensive benefits including medical, dental, vision, and 401(k) with company match.
- Meaningful work impacting thousands of legal professionals using AI daily.
- On-site work environment at Union Square office with company-provided lunch daily.
- Generous parental leave, family support programs, and additional perks like commuter benefits and identity protection.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →