Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

GRC Lead

Legora

About Us Legora is redefining how legal work gets done. Not built for lawyers, built with them. We work alongside the world’s best legal teams, who expect excellence, precision, and speed, and we hold ourselves to the same bar. Our AI-native workspace lets legal professionals move faster, think more clearly, and operate with sharper precision. By analysing thousands of documents in minutes and powering end-to-end workflows, we cut through complexity, teams can focus on what matters: judgment, strategy, and outcomes. 1,000+ customers across 50+ countries trust us, including Cleary Gottlieb, Goodwin, Linklaters, White & Case, Dentons, and Barclays. We’ve scaled to $100M+ in ARR , with teams across Europe, North America and APAC, and continue to expand through acquisitions including Qura, Walter AI and Graceview. We partner with world-class performers: including Aaron Judge and the New York Yankees, Ludvig Åberg (and his caddie), and campaigns featuring Jude Law. Joining Legora means three things. We lean in: ownership over titles, outcomes over intentions. We fight for excellence: high standards, direct, ego-free feedback. We grow together: as a team and with our customers. Mission before ego. Everyone contributes. No one coasts. If you’re driven by impact, pace, and raising the bar. This is the place.

ABOUT THE ROLE

You will own Legora’s assurance program end to end: certifications, AI governance, and the risk decisions leadership acts on. It’s a senior IC seat in the Security organization. You make the judgment calls, and you’re the one in the room with auditors, regulators, and customer security teams. Your peer, the AI GRC Engineer, builds the platform underneath — the evidence pipelines and agents that carry the repetitive work. Build controls that outlast any single framework. When a new obligation lands (an EU AI Act deadline, a state AI law, the next agent-assurance standard), it should map onto controls you already run and can evidence. Measure the program in loss-event terms, the same language our supply-chain-risk program uses, so leadership can weigh security against any other investment.

WHAT YOU’LL DO

Certification & assurance portfolio Own our SOC 2 Type II, ISO 27001, and ISO/IEC 42001 certifications: recertification cycles, auditor relationships, and remediation, run off continuously collected evidence — and expand the audit boundary as new products, entities, and acquisitions come into scope. Own the AI-agent assurance roadmap: track the emerging agent-certification standards and get us certified for the agents we ship. Design and maintain a unified controls library mapped across frameworks so one control satisfies many obligations. Be the authoritative source behind the Customer Trust team: your certifications, control descriptions, and evidence feed the trust portal and response library they run. AI governance & regulatory Operate the AI governance program: the AI system and agent inventory, risk classification, and alignment to NIST AI RMF. Track the AI regulatory landscape (EU AI Act provider and deployer obligations, US state AI laws, bar and professional-responsibility guidance for legal AI) and translate it into concrete controls with Legal. Risk, policy & resilience Own the enterprise risk register: risk assessments, treatment decisions with system owners, and risk reporting leadership actually uses. Own the policy lifecycle, and turn written policies into enforced checks with the AI GRC Engineer wherever a rule can be automated. Consume the supply-chain-risk program’s vendor assessments for compliance scope; vendor risk itself is owned by the Supply Chain Risk Lead. Own the BCDR program: business impact analysis, recovery objectives with Engineering, and regular tabletop exercises and recovery tests.

WHAT WE’RE LOOKING FOR

6+ years in GRC, security compliance, or IT audit, including at least one B2B SaaS environment where you owned SOC 2 and/or ISO 27001 end to end. Working knowledge of AI governance frameworks (ISO 42001, NIST AI RMF) and the EU AI Act, or a demonstrated ability to get deep in a new regulatory domain fast. A continuous-assurance operating model: you have run (or built toward) monitored controls and pipeline-collected evidence, and treat compliance platforms as plumbing rather than the program. Ability to read code and infrastructure-as-code well enough to verify a control yourself. Experience running enterprise risk processes that leadership uses to make decisions. Clear, precise writing — you will produce policies and risk narratives read by lawyers. You use AI tools daily in your own work and have specific, grounded views on which GRC workflows AI can run today and which it cannot.

NICE TO HAVE

ISO 42001 Lead Auditor, ISO 27001 Lead Auditor, CISA, or CISSP (or equivalent experience). Experience selling trust to law firms, financial services, or other heavily regulated buyers. Experience with GDPR/CCPA and cross-border data transfer requirements. Exposure to AI-agent assurance or certification of AI products. Exposure to public-sector assurance (e.g., FedRAMP, IRAP).

WHAT'S IN IT FOR YOU

Global collaboration: Partner with teams and clients across Europe, APAC, and North America. Competitive package: Comprehensive salary, benefits, and tools for success. Meaningful work: Your efforts shape how thousands of lawyers use AI daily. In-person environment: Union Square office designed for ambitious builders and company provided lunch daily. Benefits & Perks: We invest in our people with a comprehensive, thoughtfully designed benefits package: Medical, Dental & Vision Multiple medical plan options through Aetna and Kaiser Permanente HSA or Healthcare FSA (based on plan selection) Dental plans via MetLife Vision plans via Vision Care Family Support Generous parental leave Free access to Maven Clinic Dependent Care FSA Free One Medical membership for employees and dependents Additional Perks Pre-tax commuter benefits Life Insurance + STD/LTD 401(K) with generous company match Unlimited PTO Robust voluntary benefits, including identity protection (via Aura), legal coverage via MetLife, pet savings programs, and more Legora is an Equal Opportunity Employer At Legora, we believe great teams are built on diversity of thought and experience. We’re proud to be an equal opportunity employer and committed to creating an inclusive, high-performance culture where everyone can do their best work. We welcome people of all backgrounds and don’t discriminate based on race, color, religion, national origin, gender, gender identity or expression, sexual orientation, age, disability, veteran status, or any other characteristic protected by law. #J-18808-Ljbffr Legora

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the GRC Lead in New York, NY vacancy
  •  ...Owner.com is seeking a GRC Specialist to navigate complex Risk, Compliance, and Vulnerability Management as we grow. You will drive compliance efforts, secure systems, and advise senior leadership in security risks. Requires 3+ years in compliance frameworks and 5+ years... 
    Suggested
    Remote work

    Owner

    New York, NY
    4 days ago
  •  ...A leading consulting firm seeks a Governance, Risk, and Compliance (GRC) leader to advance their programs. This remote role requires 5–7 years of experience in GRC with relevant certifications like CISSP or CISM. The successful candidate will lead policy development, perform... 
    Suggested
    Remote work

    Franklin Fitch

    New York, NY
    2 days ago
  •  ...Job Description Job Description GRC Lead requires: Hands-on experience implementing or managing audit technology platforms, specifically AuditBoard (SOXHUB, OpsAudit, RiskOversight)., Proficiency with data analytics tools such as Power BI, Tableau, or advanced... 
    Suggested

    Globalchannelmanagement

    New York, NY
    14 days ago
  •  ...customer trust, protecting Adobe’s customers, employees, and platforms while enabling innovation at scale. We seek a GRC Strategy & Security Insights Lead to drive a data driven shift in our GRC program. This role is positioned where strategy, action, and communication... 
    Suggested
    Local area
    Shift work

    Adobe

    New York, NY
    4 days ago
  • Adobe is seeking a GRC Strategy & Security Insights Lead to drive a data-driven shift in its GRC program. This pivotal role combines the excellence in strategy and communication necessary to influence and engage executives, while overseeing critical security metrics and... 
    Suggested
    Shift work

    Adobe

    New York, NY
    4 days ago
  • PwC in New York is seeking a Senior Manager for GRC/IRM ServiceNow Technology Implementation Solutions. You will help clients maintain regulatory compliance and manage risks within our Cyber, Data & Tech Risk practice. You will coach and motivate teams, apply systems thinking... 

    PwC

    New York, NY
    2 days ago
  •  ...build together. About The Role Aaru is building out its governance, risk, and compliance function and is hiring its first dedicated GRC Lead to own it. Our customers are large enterprises that use Aaru to pressure-test high-stakes decisions before they make them. They... 
    Work at office
    Relocation
    Visa sponsorship
    Relocation package

    Aaru

    New York, NY
    3 days ago
  • Runway is seeking a seasoned GRC professional to lead governance, risk, and compliance across the US, with remote options. You will shape frameworks that balance security and responsible AI, working closely with product, engineering, and legal teams. Responsibilities include... 
    Remote job

    Runway Financial

    New York, NY
    1 day ago
  • True Zero Technologies seeks an RMF Process Lead to own and govern the organization’s Risk Management Framework processes and guide the transition to a modernized GRC-based solution. You will translate existing RMF workflows into optimized configurations, coordinate with... 

    True Zero Technologies

    New York, NY
    3 days ago
  • Diligent is seeking an experienced GRC Advisor in the United States to work with key accounts, drive adoption and retention, and identify expansion opportunities within our platform. This hybrid role requires strong client-facing skills, deep GRC knowledge, and the ability... 

    Diligent

    New York, NY
    3 days ago
  • Aaru in New York City is expanding its governance, risk, and compliance team and is seeking a dedicated GRC Lead to own the program. You will drive enterprise security reviews, audit readiness, and policy governance with an emphasis on automation and scalable processes... 

    Aaru

    New York, NY
    3 days ago
  • Weaver is seeking an IT Manager to join the Governance, Risk, and Compliance (GRC) team in the New York market. The role focuses on IT SOX compliance, SOC reporting, and IT internal audits for clients, with management of engagement teams and cross-functional collaboration... 

    Weaver

    New York, NY
    4 days ago
  • Riot Platforms seeks an experienced Director of Compliance to own the controls framework, testing program, and GRC platform. You will design and implement auditable controls aligned to ISO 27001, SOC 2, and NIST CSF while driving automation and platform integrations. You... 

    Riot Platforms

    New York, NY
    1 day ago
  • YipitData is seeking a GRC Analyst to lead audits and risk assessments across security, privacy, and vendor risk. You will validate controls, translate requirements into actionable steps for teams, and collaborate with Legal, IT, Engineering, and Finance to improve the... 
    Remote job

    Remote Jobs

    New York, NY
    4 days ago
  • $100k - $180k

    A leading FinTech company in New York is looking for a Senior GRC Analyst to strengthen their Governance, Risk, and Compliance function. The successful candidate will have over 10 years of experience in GRC, expertise in federal security frameworks, and a proactive approach... 

    Quantexa

    New York, NY
    2 days ago
  • Jane Street Group, LLC in New York, NY seeks a Senior Cybersecurity Governance, Risk & Compliance Specialist to lead vendor risk management, regulatory compliance, and strategic security initiatives. You will architect vendor risk frameworks, coordinate across procurement... 

    Janestreet

    New York, NY
    2 days ago
  • $145k - $185k

     ...Product Manager (GPM) is a senior player/coach responsible for leading a team of Product Managers across a suite of Origami products or...  ...execution strategy. The GPM for Governance, Risk, & Compliance (GRC) is responsible for ensuring the products they own deliver meaningful... 
    Full time
    Temporary work
    Work experience placement
    Remote work
    Flexible hours

    Origami Risk LLC.

    New York, NY
    2 days ago
  • $130k - $160k

     ...difference? At Danaher, you can build an incredible career at a leading science and technology company, where we’re committed to hiring...  ...experience in:Experience with governance, risk, and compliance (GRC) platforms and policy management tools, along with security automation... 
    Full time
    Remote work
    Work from home
    Flexible hours

    Danaher Corporation

    New York, NY
    2 days ago
  •  ...RolePresidio has an exciting opportunity for a Security Practice Lead to join our Cybersecurity National Practice. This individual’s primary...  ...are highly desirable.Working knowledge and familiarity with GRC and Offensive Security consulting services (e.g., penetration testing... 
    Full time
    For contractors
    Local area

    Presidio

    New York, NY
    2 days ago
  • Carta is seeking a Lead Product Marketing Manager focused on Carta Law in New York. You’ll own governance, risk, and market presence, shaping product positioning and driving launches with cross-functional teams. You’ll craft compelling collateral, coordinate with Creative... 

    cartage.co

    New York, NY
    4 days ago
  • $147.1k - $213.3k

    Job TitleAssistant Vice President - Cybersecurity Platforms Lead and Risk ManagementDivision: Corp IT, CybersecurityLocation: New York,...  ...members of the Cybersecurity Leadership team, including the Head of GRC, Head of Cyber Resilience, Global Tech Functions & Zone CISOs,... 
    Permanent employment
    Full time
    Work experience placement
    Summer work
    Work at office
    Work from home
    Flexible hours
    3 days per week

    L'Oreal

    New York, NY
    2 days ago
  •  ...Health Insurance firm, is looking for a SAAS Systems Implementation Lead- Legal & Compliance Applications, to be responsible for the...  ...Operations Serve as primary system administrator for: LogicGate (GRC / risk management) Icertis Contract Lifecycle Management DocuSign... 
    Contract work
    3 days per week

    RAZOR

    New York, NY
    1 day ago
  •  ...Space LLC is seeking a Strategic Program Manager to drive strategic security initiatives across the organization. You will partner with GRC, Security Operations, Engineering, Internal Audit, Legal, People, Product, Sales, and business teams to design programs and manage... 

    United States Digital Space LLC

    New York, NY
    22 hours ago
  • Job Description Job Description JOB SUMMARY:  To provide efficient management of location to ensure excellent QSC (Quality, Service & Cleanliness) & overseeing all areas of operation in the absence of Restaurant Manager. RESPONSIBILITIES: # Ensure daily operations...
    Full time
    Local area

    Team Leads GK

    New York, NY
    5 days ago
  • Audit Board (GRC) Implementation Specialist Audit Board (GRC) Implementation Specialist Direct message the job poster from Minisoft Technologies...  ...You’ll Do Platform Administration & Integrations Enablement: Lead the configuration and ongoing maintenance of the AuditBoard... 
    Contract work
    For contractors
    Remote work

    Minisoft Technologies

    New York, NY
    2 days ago
  • The Salvation Army in New York City seeks a Security Guard/Group Leader to help oversee the safety of the afterschool program site, monitor entrances and supervision during activities, and support meal service tasks. Requirements include a high school diploma, ability ...

    The Salvation Army

    New York, NY
    3 days ago
  • $182.75k - $215k

     ...problems we solve today unlock the opportunities of tomorrow. As a Lead Product Marketing Manager focused on our Carta Law segment, you'...  ...: Apply a deep focus on governance, risk, and compliance (GRC) to product positioning, while serving as a key product subject matter... 
    Full time

    Carta

    New York, NY
    3 days ago
  • $17 - $27.75 per hour

     ...deliver an exceptional customer experience * Serves as a Brand Ambassador embodying of Coach values and increasing brand awareness * Leads implementation of Company initiatives and support full operation of the business * Maintain a growth mindset for business and... 
    Minimum wage
    Shift work

    Tapestry

    New York, NY
    3 days ago
  •  ...European River Ships for the 2025 season. The role involves delivering exceptional housekeeping service according to GCCL standards, leading and training staff, and ensuring high hygiene standards. The ideal candidate will have a hotel school diploma or equivalent, a... 

    Grand Circle Cruise Line

    New York, NY
    22 hours ago
  • $142.6k - $261.5k

     ...rapid growth across the SAP and Governance, Risk and Compliance (GRC) space, we’re looking for people who understand the challenges...  ...and GRC. As a Risk Technology Manager, you can expect to utilize leading practice business tools and methodologies to serve diverse and sophisticated... 
    Temporary work
    Work experience placement
    Summer holiday
    Flexible hours
    Shift work

    EY (Ernst & Young)

    New York, NY
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to GRC Lead. Be the first to apply!