--- title: 'GRC Lead at Legora' canonical: 'https://feeny.ai/job/grc-lead-legora-new-york-cmhgr8g4z2h4' type: 'job' last_seen: '2026-09-11' --- # GRC Lead at Legora - **Company:** [Legora](https://feeny.ai/companies/legora) - **Location:** New York, NY - **Compensation:** $151k–$273k - **Employment:** full-time - **Work type:** onsite - **Posted:** 2026-07-23 - **Last confirmed live:** 2026-09-11 - **Apply:** https://jobs.ashbyhq.com/legora/72615933-e6bc-4899-bdf2-26b8f33c5a72 ## Job description ## About Us Legora is redefining how legal work gets done. Not built for lawyers, built with them. We work alongside the world’s best legal teams, who expect excellence, precision, and speed, and we hold ourselves to the same bar. Our AI-native workspace lets legal professionals move faster, think more clearly, and operate with sharper precision. By analysing thousands of documents in minutes and powering end-to-end workflows, we cut through complexity, teams can focus on what matters: judgment, strategy, and outcomes. 1,000+ customers across 50+ countries trust us, including Cleary Gottlieb, Goodwin, Linklaters, White & Case, Dentons, and Barclays. We’ve scaled to $100M+ in ARR, with teams across Europe, North America and APAC, and continue to expand through acquisitions including Qura, Walter AI and Graceview. We partner with world-class performers: including Aaron Judge and the New York Yankees, Ludvig Åberg (and his caddie), and campaigns featuring Jude Law. Joining Legora means three things. - We lean in: ownership over titles, outcomes over intentions. - We fight for excellence: high standards, direct, ego-free feedback. - We grow together: as a team and with our customers. Mission before ego. Everyone contributes. No one coasts. If you’re driven by impact, pace, and raising the bar. This is the place. ## ABOUT THE ROLE You will own Legora’s assurance program end to end: certifications, AI governance, and the risk decisions leadership acts on. It’s a senior IC seat in the Security organization. You make the judgment calls, and you’re the one in the room with auditors, regulators, and customer security teams. Your peer, the AI GRC Engineer, builds the platform underneath — the evidence pipelines and agents that carry the repetitive work. Build controls that outlast any single framework. When a new obligation lands (an EU AI Act deadline, a state AI law, the next agent-assurance standard), it should map onto controls you already run and can evidence. Measure the program in loss-event terms, the same language our supply-chain-risk program uses, so leadership can weigh security against any other investment. ## WHAT YOU’LL DO Certification & assurance portfolio - Own our SOC 2 Type II, ISO 27001, and ISO/IEC 42001 certifications: recertification cycles, auditor relationships, and remediation, run off continuously collected evidence — and expand the audit boundary as new products, entities, and acquisitions come into scope. - Own the AI-agent assurance roadmap: track the emerging agent-certification standards and get us certified for the agents we ship. - Design and maintain a unified controls library mapped across frameworks so one control satisfies many obligations. - Be the authoritative source behind the Customer Trust team: your certifications, control descriptions, and evidence feed the trust portal and response library they run. AI governance & regulatory - Operate the AI governance program: the AI system and agent inventory, risk classification, and alignment to NIST AI RMF. - Track the AI regulatory landscape (EU AI Act provider and deployer obligations, US state AI laws, bar and professional-responsibility guidance for legal AI) and translate it into concrete controls with Legal. Risk, policy & resilience - Own the enterprise risk register: risk assessments, treatment decisions with system owners, and risk reporting leadership actually uses. - Own the policy lifecycle, and turn written policies into enforced checks with the AI GRC Engineer wherever a rule can be automated. - Consume the supply-chain-risk program’s vendor assessments for compliance scope; vendor risk itself is owned by the Supply Chain Risk Lead. - Own the BCDR program: business impact analysis, recovery objectives with Engineering, and regular tabletop exercises and recovery tests. ## WHAT WE’RE LOOKING FOR - 6+ years in GRC, security compliance, or IT audit, including at least one B2B SaaS environment where you owned SOC 2 and/or ISO 27001 end to end. - Working knowledge of AI governance frameworks (ISO 42001, NIST AI RMF) and the EU AI Act, or a demonstrated ability to get deep in a new regulatory domain fast. - A continuous-assurance operating model: you have run (or built toward) monitored controls and pipeline-collected evidence, and treat compliance platforms as plumbing rather than the program. - Ability to read code and infrastructure-as-code well enough to verify a control yourself. - Experience running enterprise risk processes that leadership uses to make decisions. - Clear, precise writing — you will produce policies and risk narratives read by lawyers. - You use AI tools daily in your own work and have specific, grounded views on which GRC workflows AI can run today and which it cannot. ## NICE TO HAVE - ISO 42001 Lead Auditor, ISO 27001 Lead Auditor, CISA, or CISSP (or equivalent experience). - Experience selling trust to law firms, financial services, or other heavily regulated buyers. - Experience with GDPR/CCPA and cross-border data transfer requirements. - Exposure to AI-agent assurance or certification of AI products. - Exposure to public-sector assurance (e.g., FedRAMP, IRAP). ## WHAT'S IN IT FOR YOU - Global collaboration: Partner with teams and clients across Europe, APAC, and North America. - Competitive package: Comprehensive salary, benefits, and tools for success. - Meaningful work: Your efforts shape how thousands of lawyers use AI daily. - In-person environment: Union Square office designed for ambitious builders and company provided lunch daily. - Benefits & Perks: We invest in our people with a comprehensive, thoughtfully designed benefits package: Medical, Dental & Vision - Multiple medical plan options through Aetna and Kaiser Permanente - HSA or Healthcare FSA (based on plan selection) - Dental plans via MetLife - Vision plans via Vision Care Family Support - Generous parental leave - Free access to Maven Clinic - Dependent Care FSA - Free One Medical membership for employees and dependents Additional Perks - Pre-tax commuter benefits - Life Insurance + STD/LTD - 401(K) with generous company match - Unlimited PTO - Robust voluntary benefits, including identity protection (via Aura), legal coverage via MetLife, pet savings programs, and more Legora is an Equal Opportunity Employer At Legora, we believe great teams are built on diversity of thought and experience. We’re proud to be an equal opportunity employer and committed to creating an inclusive, high-performance culture where everyone can do their best work. We welcome people of all backgrounds and don’t discriminate based on race, color, religion, national origin, gender, gender identity or expression, sexual orientation, age, disability, veteran status, or any other characteristic protected by law. ## About Legora ## Company Overview - **One-liner**: Legora builds a collaborative AI workspace that empowers legal professionals to review, draft, research, and advise with greater speed and precision. - **Entity Type**: Private (Series D; total funding $865.6M) - **Headquarters**: Stockholm, Sweden - **Founded**: 2023 - **Founders**: Max Junestrand (Co-founder & CEO) ## Core Business - **Primary industry**: Legal Technology (Legal AI) - **Target customers**: Law firms and in-house legal teams (B2B/Enterprise) - **Mission or purpose statement**: "To empower exceptional lawyers" by building the world's first truly collaborative AI for legal work [legora.com/about]. ## Products & Services - **Legora aOS (Agentic Operating System)**: A single platform that connects information, communication, and execution of legal work. Integrates AI agents, monitoring, and workflow tools. - **Agent**: An end-to-end executor that plans, reviews, and delivers complex legal tasks, allowing lawyers to focus on judgment-intensive decisions. - **Monitors**: Continuously scans global regulation and surfaces relevant changes. - **Lists**: Organises legal work from documents and connects AI outputs to workflows. ## Market Standing - **Valuation/Market Cap**: Not publicly disclosed - **Key Metric**: Annual Revenue of $50.0M (LinkedIn estimate); Total Funding of $865.6M across 5 rounds (Seed, Series A, B, C, D). - **Notable Investors/Partners**: Accel, Bessemer Venture Partners, ICONIQ, General Catalyst, Benchmark, Redpoint, Y Combinator. Recent Series D (April 2026, $600M) included 23 investors. - **Growth Signals**: 352 employees (+528.8% YoY); 1,000+ customers in 30+ markets; acquired Qura and Walter. Active job postings up 1308% year-over-year (169 open roles). ## Competitive Advantages - **Deep legal domain AI**: Purpose-built for legal workflows rather than general-purpose LLMs. - **Security & compliance**: ISO 27001, ISO 42001, SOC 2 Type II, GDPR, HIPAA certified – critical for law firm adoption. - **Agentic approach**: End-to-end execution of complex legal work, reducing non-billable hours by an average of 30%. ## Strategic Focus - **Building the "OS for legal work"** – a single system connecting information, communication, and execution. - Expanding globally with offices in 16 countries (US, UK, Australia, India, Denmark, etc.). - Deepening AI governance (ISO 42001) to maintain trust and regulatory readiness. ## Why Work Here - **Culture**: Values include "lean in," "fight for excellence," "grow together," and "curiosity and clarity." Emphasis on transparency, speed, and real impact over hierarchy [legora.com/careers]. - **Work environment**: Highly collaborative – "collaboration isn’t a process, it’s our foundation" [legora.com/about]. Hybrid/office presence likely given multiple locations; exact policy not specified. - **Engineering focus**: Roles span software engineering, AI, site reliability, and product design. Hiring process includes a case presentation and a final interview with the CEO. - **Perks**: Not explicitly detailed, but employer rating is 4.4/5 (Work-Life: 4.5, Compensation: 5.0, Culture: 4.4, Career: 4.4) from 9 reviews on LinkedIn. ## Sources 1. [Legora Careers Page](https://legora.com/careers) 2. [Legora Official Site](https://legora.com/) 3. [Legora About Page](https://legora.com/about) 4. [Legora LinkedIn Company Page](https://www.linkedin.com/company/wearelegora) ## Other roles at Legora - [Senior Talent Acquisition Partner, Engineering](https://feeny.ai/job/senior-talent-acquisition-partner-engineering-legora-london-7bh068ard4nb) — London, United Kingdom - [Strategic Programs Manager](https://feeny.ai/job/strategic-programs-manager-legora-new-york-59fge02vt3g5) — New York, NY - [Senior Software Engineer](https://feeny.ai/job/senior-software-engineer-legora-london-yge34em2hk2x) — London, United Kingdom - [Director of Partnerships APJ](https://feeny.ai/job/director-of-partnerships-apj-legora-sydney-p7116nchk9ae) — Sydney, Australia - [GTM Compensation, Planning & Performance Analyst](https://feeny.ai/job/gtm-compensation-planning-performance-analyst-legora-new-york-she27raabb6r) — New York, NY - [Senior Accountant](https://feeny.ai/job/senior-accountant-legora-new-york-xy2ya1zjnm02) — New York, NY - [Performance Marketing Manager](https://feeny.ai/job/performance-marketing-manager-legora-new-york-ck78favb5rxr) — New York, NY - [Executive Recruiter](https://feeny.ai/job/executive-recruiter-legora-new-york-bkxd7wnx4790) — New York, NY - [Senior Visual Designer - Product Marketing](https://feeny.ai/job/senior-visual-designer-product-marketing-legora-stockholm-cmnb0xkcmk91) — Stockholm, Sweden - [(Senior OR Staff) Detection & Response Engineer](https://feeny.ai/job/senior-or-staff-detection-response-engineer-legora-new-york-2r8hpxdbzgsm) — New York, NY