Cybersecurity GRC Specialist II

Kirkland & Ellis

Chicago (IL)

On-site

USD 116,000 - 144,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Kirkland & Ellis in Chicago is seeking a Security GRC Specialist II to strengthen security programs, manage risk, and guide compliance efforts across client and vendor interactions. You will partner with technical teams, business stakeholders, clients, and vendors to ensure effective controls and clear risk communication.

This role blends strategic oversight with hands-on execution—from policy development to vendor risk and security awareness initiatives—within a dynamic legal environment.

Qualifications

  • Bachelor's degree with five years of IT security experience.
  • Certifications such as CISSP, CISA, CISM or advanced AI security certifications preferred.
  • 4+ years of hands-on information security experience.
  • Strong knowledge of ISO 27001, NIST, SOC and SIG frameworks.
  • AI risk governance, security and risk management experience required.
  • Technical writing and clear documentation skills.
  • Experience leading risk assessments and vendor security reviews.
  • Familiarity with GRC platforms and access controls.
  • Analytical, organized, able to work independently or in teams.
  • Working knowledge of auth, encryption, firewalls, SIEM, vulnerability mgmt.

Responsibilities

  • Lead client and third-party security assessments and audits.
  • Create, maintain and evolve security policies and standards.
  • Manage IT security risk and compliance programs across the org.
  • Advise stakeholders as a Security SME across technical and non-technical audiences.
  • Oversee third-party Security Vendor Risk Management program.
  • Manage security exception requests and risk treatment guidance.
  • Oversee Security Awareness program roadmap and training effectiveness.
  • Support GRC platforms and related workflows.
  • Evaluate IT programs for alignment with published standards.

Skills

Client & Third-Party Assessments
Policy & Standards Management
Risk & Compliance Assurance
Security Consulting & SME Support
Vendor Risk Management
Exception & Risk Treatment
Security Awareness Program
GRC Platform Administration
Controls & Compliance Evaluations

Education

Bachelor's degree or equivalent in IT Security
Certifications: CISSP, CISA, CISM, AAIA/AAIR/AAISM or equivalents

Tools

GRC platforms

Job description

About Kirkland & Ellis

At Kirkland & Ellis, we don’t just meet the standard for legal excellence — we set it. Our culture is built on teamwork, ingenuity and an unwavering commitment to continuous growth. We tackle the most sophisticated legal challenges with bold ideas and innovative solutions, powered by the exceptional experience and ambition of our 7,000+ people, including 4,000+ attorneys, across 24 offices worldwide. Our dedicated professionals share our lawyers’ commitment to excellence and show up each day to do meaningful work that helps drive global business, investment and innovation forward.

About Kirkland & Ellis

At Kirkland & Ellis, we don’t just meet the standard for legal excellence — we set it. Our culture is built on teamwork, ingenuity and an unwavering commitment to continuous growth. We tackle the most sophisticated legal challenges with bold ideas and innovative solutions, powered by the exceptional experience and ambition of our 7,000+ people, including 4,000+ attorneys, across 24 offices worldwide. Our dedicated professionals share our lawyers’ commitment to excellence and show up each day to do meaningful work that helps drive global business, investment and innovation forward.

What You’ll Do

Are you driven to strengthen security programs, reduce risk, and help organizations meet evolving cybersecurity expectations?

As a Security GRC Specialist II, you’ll be a key member of the Governance, Risk, and Compliance (GRC) team, leading and executing core GRC programs while serving as a trusted Information Security subject matter expert. This role blends strategic oversight with hands-on execution—partnering with technical teams, business stakeholders, clients, and vendors to ensure security controls, policies, and risk practices are effective, compliant, and clearly communicated.

  • Client & Third-Party Assessments: Lead responses to client security assessments, questionnaires, and audits, documenting evidence and performing risk assessments as needed.
  • Policy & Standards Management: Create, maintain, and evolve security policies, standards, guidelines, and supporting documentation through strong technical writing.
  • Risk & Compliance Assurance: Manage and support processes that ensure Information Technology (IT) systems meet cybersecurity, risk, and compliance requirements.
  • Security Consulting & SME Support: Serve as an Information Security subject matter expert, advising technical and non-technical stakeholders across the organization.
  • Vendor Risk Management: Manage the third-party Security Vendor Risk Management program, including assessments, remediation tracking, and lifecycle oversight.
  • Exception & Risk Treatment: Oversee the security exception request process and provide guidance on appropriate risk treatment decisions.
  • Security Awareness Program: Manage the full lifecycle of the Security Awareness program, including roadmap development, training evaluation, and effectiveness measurement.
  • GRC Platform Administration: Support and optimize Governance, Risk, and Compliance (GRC) technology platforms and associated workflows.
  • Controls & Compliance Evaluations: Conduct evaluations of IT programs and components to confirm alignment with published security standards and frameworks.
What You’ll Bring
  • Education: Bachelor's degree or equivalent with five (5) years of work experience in IT Security is required.
  • Certifications: Certified Information Systems Security Professional (CISSP), Certified Information Security Auditor (CISA), Certified Information Security Manager (CISM), Advanced in AI Audit (AAIA), Advanced in AI Risk (AAIR), Advanced in AI Security Management (AAISM) or other relevant training and certifications are preferred.
  • Information Security Experience: Four (4) or more years of Information Security experience, with hands‑on technical experience strongly preferred.
  • Framework & GRC Knowledge: Strong working knowledge of security frameworks and standards such as ISO 27001, National Institute of Standards and Technology (NIST), System and Organization Controls (SOC), and Standardized Information Gathering (SIG) is required.
  • AI Risk: Experience in Artificial Intelligence (AI) governance, security, and risk management is required.
  • Technical Writing & Communication: Proven ability to produce clear, well-structured security documentation and communicate complex technical topics to varied audiences.
  • Risk & Vendor Management Skills: Experience leading risk assessments, vendor security reviews, and client-facing security discussions with professionalism and tact.
  • GRC Tools & Technologies: Familiarity with GRC platforms, role-based access controls, and a broad range of security technologies and tools.
  • Analytical & Organizational Strength: Strong problem-solving, project management, and time management skills with the ability to work independently or collaboratively.
  • Technical Acumen: Working knowledge of areas such as authentication, encryption, firewalls, SIEM, intrusion detection/prevention, vulnerability management, mobile security, and privileged access management.
  • Collaboration & Professionalism: Client-focused mindset with strong interpersonal skills, attention to detail, and a commitment to maintaining accurate records and documentation.
Compensation

The base salary range below represents the low and high end of the salary range for this position in Chicago. This range may differ based on your geographic location and cost of living considerations. At Kirkland & Ellis, we consider compensation more than just a base salary. We offer an exceptional range of flexible benefits including comprehensive healthcare, paid time off, and retirement. We also offer personal support and tailored learning and development opportunities all designed to help you realize your full potential both in life and at work.

Compensation Range

Chicago: $116,000 - $144,000

Don't meet every job requirement? That's okay! If you're excited about this role but your experience doesn't perfectly fit every qualification, we encourage you to apply anyway. You may be just the right person for this role or others at Kirkland.

Equal Employment Opportunity

All employment decisions, including the recruiting, hiring, placement, training availability, promotion, compensation, evaluation, disciplinary actions, and termination of employment (if necessary) are made without regard to the employee’s race, color, creed, religion, sex, pregnancy or childbirth, personal appearance, family responsibilities, sexual orientation or preference, gender identity, political affiliation, source of income, place of residence, national or ethnic origin, ancestry, age, marital status, military veteran status, unfavorable discharge from military service, physical or mental disability, or on any other basis prohibited by applicable law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity GRC Specialist II
Cybersecurity GRC Specialist II

Kirkland & Ellis • Austin (TX)

On-site
USD 116,000 - 144,000
Healthcare
Paid time off
Retirement benefits
Cybersecurity Engineer II
Cybersecurity Engineer II

Kirkland & Ellis • Austin (TX)

On-site
USD 133,000 - 166,000
Hybrid Cybersecurity Assessment & Test Analyst II
Hybrid Cybersecurity Assessment & Test Analyst II

Kirkland & Ellis • Chicago (IL)

Hybrid
USD 116,000 - 144,000
Comprehensive healthcare
Paid time off
Retirement benefits
Cybersecurity Assessment and Test Analyst II
Cybersecurity Assessment and Test Analyst II

Kirkland & Ellis • Chicago (IL)

Hybrid
USD 116,000 - 144,000
Comprehensive healthcare
Paid time off
Retirement benefits
SIEM Engineer II
SIEM Engineer II

Kirkland & Ellis • Austin (TX)

On-site
USD 120,000 - 150,000
SIEM Engineer II
SIEM Engineer II

Kirkland & Ellis • Chicago (IL)

On-site
USD 133,000 - 166,000
Comprehensive healthcare
Paid time off
Retirement plan
+1
Senior Physical Security Engineer
Senior Physical Security Engineer

Kirkland & Ellis • Chicago (IL)

On-site
USD 100,000 - 138,000
Senior Enterprise Infrastructure Architect
Senior Enterprise Infrastructure Architect

Kirkland & Ellis • Houston (TX)

Hybrid
USD 176,000 - 220,000
Firmwide Service Desk Analyst II (10am-6pm CT)
Firmwide Service Desk Analyst II (10am-6pm CT)

Kirkland & Ellis • Chicago (IL)

On-site
USD 73,000 - 79,000
Comprehensive healthcare
Paid time off
Retirement benefits
+1
Server Engineer II
Server Engineer II

Kirkland & Ellis • Chicago (IL)

On-site
USD 116,000 - 144,000
Comprehensive healthcare
Paid time off
Retirement benefits
+1