Compliance Lead
Legora · New York, NY · Yesterday
On-siteInformation Technology$100/hrFull-time
About the role
You will own Legora’s assurance program end to end: certifications, AI governance, and the risk decisions leadership acts on. It’s a senior IC seat in the Security organization. You make the judgment calls, and you’re the one in the room with auditors, regulators, and customer security teams.
Responsibilities
- Certification & assurance portfolio:
- Own our SOC 2 Type II, ISO 27001, and ISO/IEC 42001 certifications: recertification cycles, auditor relationships, and remediation, run off continuously collected evidence — and expand the audit boundary as new products, entities, and acquisitions come into scope.
- Own the AI-agent assurance roadmap: track the emerging agent-certification standards and get us certified for the agents we ship.
- Design and maintain a unified controls library mapped across frameworks so one control satisfies many obligations.
- Be the authoritative source behind the Customer Trust team: your certifications, control descriptions, and evidence feed the trust portal and response library they run.
- AI governance & regulatory:
- Operate the AI governance program: the AI system and agent inventory, risk classification, and alignment to NIST AI RMF.
- Track the AI regulatory landscape (EU AI Act provider and deployer obligations, US state AI laws, bar and professional-responsibility guidance for legal AI) and translate it into concrete controls with Legal.
- Risk, policy & resilience:
- Risk assessment, treatment decisions with system owners, and risk reporting leadership actually uses.
- Turn written policies into enforced checks with the AI GRC Engineer wherever a rule can be automated.
- Consume the supply-chain-risk program’s vendor assessments for compliance scope; vendor risk itself is owned by the Supply Chain Risk Lead.
- Own the BCDR program: business impact analysis, recovery objectives with Engineering, and regular tabletop exercises and recovery tests.
Requirements
- 6+ years in GRC, security compliance, or IT audit, including at least one B2B SaaS environment where you owned SOC 2 and/or ISO 27001 end to end.
- Working knowledge of AI governance frameworks (ISO 42001, NIST AI RMF) and the EU AI Act, or a demonstrated ability to get deep in a new regulatory domain fast.
- A continuous-assurance operating model: you have run (or built toward) monitored controls and pipeline-collected evidence, and treat compliance platforms as plumbing rather than the program.
- Ability to read code and infrastructure-as-code well enough to verify a control yourself.
- Experience running enterprise risk processes that leadership uses to make decisions.
- Clear, precise writing — you will produce policies and risk narratives read by lawyers.
- Use AI tools daily in your own work and have specific, grounded views on which GRC workflows AI can run today and which it cannot.
Nice to have
- ISO 42001 Lead Auditor, ISO 27001 Lead Auditor, CISA, or CISSP (or equivalent experience).
- Experience selling trust to law firms, financial services, or other heavily regulated buyers.
- Experience with GDPR/CCPA and cross-border data transfer requirements.
- Exposure to AI-agent assurance or certification of AI products.
- Exposure to public-sector assurance (e.g., FedRAMP, IRAP).
Benefits
- Global collaboration: Partner with teams and clients across Europe, APAC, and North America.
- Competitive package: Comprehensive salary, benefits, and tools for success.
- Meaningful work: Your efforts shape how thousands of lawyers use AI daily.
- In-person environment: Union Square office designed for ambitious builders and company provided lunch daily.
- Benefits & Perks: We invest in our people with a comprehensive, thoughtfully designed benefits package:
- Medical, Dental & Vision
- Multiple medical plan options through Aetna and Kaiser Permanente
- HSA or Healthcare FSA (based on plan selection)
- Dental plans via MetLife
- Vision plans via Vision Care
- Family Support
- Generous parental leave
- Free access to Maven Clinic
- Dependent Care FSA
- Free One Medical membership for employees and dependents
- Additional Perks
- Pre-tax commuter benefits
- Life Insurance + STD/LTD
- 401(K) with generous company match
- Robust voluntary benefits, including identity protection (via Aura), legal coverage via MetLife, pet savings programs, and more
Pay
Competitive salary
Schedule
Full-time