Cleary Gottlieb is a pioneer in globalizing the legal profession with 14 offices worldwide, operating as a single, integrated global partnership. The firm employs approximately 1,100 lawyers from over 50 countries. Since 1946, the firm has provided clients with simple, actionable approaches to complex legal and business challenges. The Security Governance, Risk, and Compliance (GRC) Manager, reporting to the Director of Information Security, is crucial for safeguarding the firm's data and meeting client security requirements. This role encompasses Client Security Assessment Management, ISO 27001/27701 Program Management, and Internal GRC Program and Audit Management. As a senior contributor, this role will also create updated Security Awareness training materials. While the role is expected to manage personnel as needed for GRC tasks, it is initially an individual contributor role. The GRC Manager must ensure security GRC policies and procedures are up-to-date and professionally written, collaborating with other IT departments. This role works closely with other GRC-adjacent security roles and requires significant security expertise. The role will be the primary point of contact for client security assessment requests, managing the end-to-end process, including questionnaire completion and evidence curation, utilizing an AI-assisted platform (Vanta). This role interfaces with the Risk Department to delegate questions and determine appropriate responses. As the ISO ISMS/PIMS Coordinator/SME, this role is responsible for preparing ISPF meeting agendas and minutes, working with auditors, performing annual Risk Assessments, gathering performance metrics, and managing continuous improvements. This role is supported by a third-party consulting company. The GRC Manager is also critical in developing the Security Awareness Program, including custom training videos and phishing simulations, and staying current with cybersecurity news. The role will interface with IT Leadership and other departments to answer questions and inform the firm's Information Security strategy. The GRC Manager is a full-time member of the Information Security Department, collaborating with other security roles to enhance core program elements. Cleary Gottlieb is a preeminent law firm known for its collaborative environment, leading the legal industry in cloud and AI technologies, offering unmatched flexibility for hybrid work and a downtown office.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior