Senior GRC Lead - AI Governance & Certifications

Legora

New York (NY)

On-site

Confidential

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

In-person office: Union Square (NYC)
Daily lunch provided
Comprehensive medical, dental & vision

Job summary

Legora is seeking a senior GRC/Security professional to own our assurance program end to end, including certifications, AI governance, and risk leadership. You’ll interface with auditors, regulators, and customer security teams, shaping controls that scale across products and acquisitions.

You’ll drive an evidence-driven program aligned with NIST AI RMF, EU AI Act, and various U.S. state laws, ensuring continuous improvement and concrete, auditable controls.

Qualifications

  • 6+ years in GRC, security compliance, or IT audit, including at least one B2B SaaS environment where you owned SOC 2 and/or ISO 27001 end to end.
  • Working knowledge of AI governance frameworks (ISO 42001, NIST AI RMF) and the EU AI Act, or a demonstrated ability to get deep in a new regulatory domain fast.
  • A continuous-assurance operating model: you have run (or built toward) monitored controls and pipeline-collected evidence, and treat compliance platforms as plumbing rather than the program.
  • Ability to read code and infrastructure-as-code well enough to verify a control yourself.
  • Experience running enterprise risk processes that leadership uses to make decisions.
  • Clear, precise writing — you will produce policies and risk narratives read by lawyers.
  • You use AI tools daily in your own work and have specific, grounded views on which GRC workflows AI can run today and which it cannot.

Responsibilities

  • Own our SOC 2 Type II, ISO 27001, and ISO/IEC 42001 certifications: recertification cycles, auditor relationships, and remediation, run off continuously collected evidence — and expand the audit boundary as new products, entities, and acquisitions come into scope.
  • Own the AI-agent assurance roadmap: track the emerging agent-certification standards and get us certified for the agents we ship.
  • Design and maintain a unified controls library mapped across frameworks so one control satisfies many obligations.
  • Be the authoritative source behind the Customer Trust team: your certifications, control descriptions, and evidence feed the trust portal and response library they run.
  • Operate the AI governance program: the AI system and agent inventory, risk classification, and alignment to NIST AI RMF.
  • Track the AI regulatory landscape (EU AI Act provider and deployer obligations, US state AI laws, bar and professional-responsibility guidance for legal AI) and translate it into concrete controls with Legal.
  • Own the enterprise risk register: risk assessments, treatment decisions with system owners, and risk reporting leadership actually uses.
  • Own the policy lifecycle, and turn written policies into enforced checks with the AI GRC Engineer wherever a rule can be automated.
  • Consume the supply-chain-risk program’s vendor assessments for compliance scope; vendor risk itself is owned by the Supply Chain Risk Lead.
  • Own the BCDR program: business impact analysis, recovery objectives with Engineering, and regular tabletop exercises and recovery tests.

Skills

GRC
Security Compliance
IT Audit
B2B SaaS
AI governance familiarity

Tools

SOC 2 Type II
ISO 27001
ISO/IEC 42001

Job description

Legora is seeking a senior GRC/Security professional to own our assurance program end to end, including certifications, AI governance, and risk leadership. You’ll interface with auditors, regulators, and customer security teams, shaping controls that scale across products and acquisitions.

You’ll drive an evidence-driven program aligned with NIST AI RMF, EU AI Act, and various U.S. state laws, ensuring continuous improvement and concrete, auditable controls.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

On-Site NYC AI GRC Lead — Compliance & Assurance
On-Site NYC AI GRC Lead — Compliance & Assurance

Legora • New York (NY)

On-site
USD 160,000 - 210,000
Union Square office
Lunch provided daily
401(K) with company match
+6
Senior GRC & AI Compliance Engineer — On-site NYC
Senior GRC & AI Compliance Engineer — On-site NYC

Legora • New York (NY)

On-site
USD 170,000 - 250,000
Office lunch daily
Union Square office
Medical plans
+3
GRC Engineer - AI-Driven Compliance & Assurance
GRC Engineer - AI-Driven Compliance & Assurance

Legora • New York (NY)

On-site
Confidential
Medical plans
Dental plans
Vision plans
+7
Senior GRC Lead for AI – End-to-End Certifications & Audits
Senior GRC Lead for AI – End-to-End Certifications & Audits

Thinking Machines Lab • San Francisco (CA)

On-site
USD 225,000 - 350,000
Health, dental, and vision benefits
Unlimited PTO
Parental leave
+1
Remote GRC Lead — AI Security & Compliance
Remote GRC Lead — AI Security & Compliance

Applied Methods Ltd • Foster City (CA)

On-site
USD 210,000 - 270,000
Competitive Salary
401(k) with 4% match
Health, Dental, Vision, Life
+5
Senior GRC Lead - AI-Driven Security & Compliance
Senior GRC Lead - AI-Driven Security & Compliance

Gusto • San Francisco (CA)

Hybrid
USD 183,000 - 205,000
Equity (RSUs)
Competitive pay & benefits
Hybrid work schedule (2–3 days in-odd)
Senior GRC & Trust Lead — AI-Driven Compliance
Senior GRC & Trust Lead — AI-Driven Compliance

Meta • Menlo Park (CA), Northern (KY)

Hybrid
USD 250,000 - 350,000
GRC Lead
GRC Lead

Legora • New York (NY)

On-site
Confidential
In-person office: Union Square (NYC)
Daily lunch provided
Comprehensive medical, dental & vision
GRC Product Lifecycle Assurance Lead
GRC Product Lifecycle Assurance Lead

OpenAI • New York (NY)

On-site
USD 180,000 - 240,000
GRC Engineer
GRC Engineer

Legora • New York (NY)

On-site
Confidential
Medical plans
Dental plans
Vision plans
+7