GRC Lead
Core
Own Legora's end-to-end assurance program covering certifications, AI governance, and enterprise risk decisions for leadership.
Role type
Senior IC GRC Lead (Security)
Builds
Unified controls library, AI governance program, enterprise risk register, and BCDR program
Domain
Legal Tech / AI Governance / Security Compliance
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
SOC 2 Type II, ISO 27001, ISO/IEC 42001, AI governance frameworks (NIST AI RMF, EU AI Act), enterprise risk management, policy lifecycle management, BCDR planning, code reading/infrastructure-as-code verification
Preferred skills
ISO 42001 Lead Auditor, ISO 27001 Lead Auditor, CISA, CISSP, selling trust to regulated industries, GDPR/CCPA expertise, AI-agent assurance
Technologies
SOC 2, ISO 27001, ISO/IEC 42001, NIST AI RMF, EU AI Act, Infrastructure-as-Code
Responsibilities
Manage SOC 2, ISO 27001, and ISO/IEC 42001 certification cycles and auditor relationships; Operate the AI governance program including system inventory and risk classification; Own the enterprise risk register and policy lifecycle; Lead Business Continuity and Disaster Recovery (BCDR) planning and testing
Seniority
Senior, hands-on IC
