Talent.com
No longer accepting applications
Lead Governance, Risk, and Compliance (GRC) Analyst

Lead Governance, Risk, and Compliance (GRC) Analyst

Morrison FoersterSan Francisco, California, United States
1 day ago
Job type
  • Full-time
Job description

Lead Governance, Risk, and Compliance (GRC) Analyst

This role can be based in San Francisco, Palo Alto, Los Angeles, San Diego, Denver, Austin, Boston, New York or Washington, D.C. (see

https : / / www.mofo.com / offices ). This role requires a strong leader with expertise in information security governance and ISO 27001.

Overview

At MoFo, we couldn’t write our own success story without yours. Ready to write your story? Join MoFo as a

LEAD GRC ANALYST

on our Information Technology team!

About The Role

The Lead Governance, Risk, and Compliance (GRC) Analyst is responsible for managing the firm’s information security governance, risk, and compliance program. This role serves as the operational lead for maintaining ISO 27001 certification, managing client and vendor audits, overseeing policy governance, and ensuring continuous audit readiness across all systems and jurisdictions.

Governance, Risk & Compliance

Lead and manage the firm’s Information Security Management System (ISMS) to maintain ISO 27001 certification and ongoing compliance.

Develop, implement, and monitor controls aligned with ISO 27001, NIST 800-53, DOJ, and CISA EO 14117 frameworks.

Serve as the primary liaison for internal, external, client, and vendor security audits, including documentation, evidence, and remediation tracking.

Manage the firm’s compliance calendar and ensure timely completion of assessments, certifications, and audits.

Improve compliance processes through automation, standardized evidence tracking, and enhanced reporting.

Oversee the governance and maintenance of security and privacy policies to ensure alignment with frameworks and regulatory requirements.

Conduct risk assessments and document mitigation strategies.

Collaborate with IT, Legal, Privacy, and business units to ensure consistent control implementation and reporting.

Track and report key performance metrics to measure compliance posture and program maturity.

Audit & Compliance Leadership

Manage all phases of ISO, client, and vendor audit cycles, from scoping to evidence delivery.

Engage with auditors, clients, and stakeholders to explain controls, policies, and security practices.

Maintain continuous audit readiness and coordinate corrective actions and improvement plans as needed.

Policy and Documentation Management

Maintain ISMS documentation, control inventories, and audit evidence repositories.

Review and update policies, procedures, and standards for clarity and alignment with business and legal requirements.

Prepare executive‑level reports summarizing compliance posture and audit outcomes.

Program Maturity and Process Improvement

Identify opportunities to enhance compliance operations through process and technology improvements.

Lead initiatives to automate control monitoring and evidence collection.

Stay current on evolving regulatory requirements and advise leadership on necessary updates.

Client Service and Confidentiality

Serve as the primary client‑facing representative for security and compliance inquiries.

Ensure timely and professional communication during client and vendor audit engagements.

Uphold firm confidentiality standards and elevate potential data protection or compliance incidents as required.

About You

Bachelor’s degree or higher in Information Technology, Cybersecurity, Business, or a related field.

7–10 years of experience in information security governance, risk, and compliance roles.

Proven success managing ISO 27001 programs, client security audits, and vendor assessments.

Deep knowledge of ISO 27001 and NIST 800-53 frameworks; familiarity with DOJ and CISA EO 14117 guidance preferred.

Demonstrated ability to operate independently, lead audit activities, and manage complex compliance programs.

Strong background in control design, mapping, and governance documentation.

Required certifications : CISSP, CISA, or equivalent.

Preferred certifications : ISO 27001 Lead Auditor or Lead Implementer, CISM, or CRISC.

Core Competencies And Applied Skills

Audit Leadership : Proven ability to maintain continuous audit readiness and manage full audit cycles end‑to‑end.

Policy and Control Management : Expertise in control design, policy governance, and compliance validation.

Independent Execution : Operates with minimal supervision, showing initiative, accountability, and ownership.

Analytical Thinking : Strong risk assessment and problem‑solving skills; ability to translate frameworks into actionable controls.

Communication : Excellent written and verbal skills with experience engaging clients, auditors, and senior leadership.

Organization : Skilled at managing multiple audits, priorities, and deliverables under tight deadlines.

Collaboration : Works effectively across IT, Legal, Privacy, and business teams to align compliance objectives.

Continuous Improvement : Identifies opportunities to enhance efficiency through process and technology optimization.

About MoFo

At MoFo, we collaborate as one firm, across borders, practice areas, and business functions and value fresh ideas and innovation over conformity and competition.

About Us : https : / / www.mofo.com / about

Inclusion + Engagement : https : / / www.mofo.com / community / we-at-mofo

Commitment to Pro Bono : https : / / careers.mofo.com / careers-pro-bono

The MoFo Foundation : https : / / www.mofo.com / culture / mofo-foundation

Our Benefits

A variety of options for medical, dental, vision, life and disability coverage to meet the needs of you and your family.

Industry‑leading parental leave and family benefits including adoption and fertility treatment options and backup child and elder care.

Global wellness program, including free access to Talkspace and Calm apps.

Annual community service day to make an impact on your community and a birthday holiday just for fun.

Education reimbursement annually.

Dedicated Talent Development team.

Competitive annual profit‑sharing contribution.

Compensation

Where required by law, salary ranges are stated below. Additional compensation may include a discretionary bonus, overtime as applicable, health / welfare benefits, retirement contributions, paid holidays, and PTO. The range displayed is specifically for positions performed in those cities / states and may vary based on factors including but not limited to the following : local market data and ranges; an applicant's skills and prior relevant experience; and certain degrees, licensing, and certifications.

New York, San Francisco, Palo Alto : $128k to $178k

Los Angeles, San Diego, Boston, Washington, D.C. : $122k to $169k

Denver : $114k to $159k

The application deadline is May 13, 2026.

For questions regarding this position, please e-mail jobs@mofo.com

#J-18808-Ljbffr

Create a job alert for this search

Lead Governance Risk Compliance • San Francisco, California, United States

Related jobs
  • Promoted
Lead Governance, Risk, and Compliance (GRC) Analyst

Lead Governance, Risk, and Compliance (GRC) Analyst

Morrison & Foerster LLPSan Francisco, CA, United States
Full-time
Lead Governance, Risk, and Compliance (GRC) Analyst.Position Type : Information Technology.At MoFo, we couldn't write our own success story without yours. This role can be based in San Francisco, Pal...Show moreLast updated: 2 days ago
  • Promoted
Governance, Risk, and Compliance Lead

Governance, Risk, and Compliance Lead

xAIPalo Alto, CA, United States
Full-time
AI’s mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. Our team is small, highly motivated, and focused on engineering excelle...Show moreLast updated: 30+ days ago
  • Promoted
Governance, Risk & Compliance Lead

Governance, Risk & Compliance Lead

Pantera CapitalSan Francisco, CA, United States
Full-time
Perplexity is an AI-powered answer engine founded in December 2022 and growing rapidly as one of the world’s leading AI platforms. Perplexity has raised over $1B in venture investment from some of t...Show moreLast updated: 17 days ago
  • Promoted
Governance, Risk & Compliance Lead

Governance, Risk & Compliance Lead

Perplexity AI Inc.San Francisco, CA, United States
Full-time
Perplexity is seeking a highly experienced Governance, Risk & Compliance Analyst to join our world-class team.You will help shape our compliance and risk management program.If you are a self-motiva...Show moreLast updated: 15 days ago
  • Promoted
Head of Governance, Risk and Compliance

Head of Governance, Risk and Compliance

Hippocratic AIPalo Alto, CA, United States
Full-time
Hippocratic AI has developed a safety-focused Large Language Model (LLM) for healthcare.The company believes that a safe LLM can dramatically improve healthcare accessibility and health outcomes in...Show moreLast updated: 5 days ago
  • Promoted
  • New!
Senior AI Risk & Compliance Analyst — Remote-Ready

Senior AI Risk & Compliance Analyst — Remote-Ready

AnthropicSan Francisco, CA, United States
Remote
Full-time
A leading technology organization is looking for a Risk Analyst who will play a critical role within the Compliance Team. This position involves building risk management frameworks while collaborati...Show moreLast updated: 3 hours ago
Compliance Program Lead

Compliance Program Lead

Freelancer.comSan Francisco, CA, US
Full-time
Quick Apply
We are seeking a highly skilled Compliance Program Lead to oversee and enhance our regulatory compliance initiatives.This role is responsible for ensuring adherence to regulatory requirements relat...Show moreLast updated: 30+ days ago
  • Promoted
Remote Senior FP&A Analyst - AI Trainer ($50-$60 / hour)

Remote Senior FP&A Analyst - AI Trainer ($50-$60 / hour)

Data AnnotationSan Rafael, California
Remote
Full-time +1
We are looking for a finance professional to join our team to train AI models.You will measure the progress of these AI chatbots, evaluate their logic, and solve problems to improve the quality of ...Show moreLast updated: 10 days ago
  • Promoted
Senior GRC Analyst II

Senior GRC Analyst II

Menlo VenturesSan Francisco, CA, United States
Full-time
Location : San Francisco, CA; Seattle, WA; New York City, NY.Carta connects founders, investors, and limited partners through world‑class software, purpose‑built for everyone in venture capital, pri...Show moreLast updated: 5 days ago
  • Promoted
Senior Manager, Risk and Compliance

Senior Manager, Risk and Compliance

San Francisco Federal Credit UnionSan Francisco, CA, United States
Full-time
With an “A” health rating and solid year-over-year growth, San Francisco Federal Credit Union’s (SFFedCU) membership is now over 43,000 with assets surpassing $1. San Francisco and San Mateo County....Show moreLast updated: 1 day ago
  • Promoted
Remote Investment Analyst – AI Trainer ($50-$60 / hour)

Remote Investment Analyst – AI Trainer ($50-$60 / hour)

Data AnnotationSan Rafael, California
Remote
Full-time +1
We are looking for a finance professional to join our team to train AI models.You will measure the progress of these AI chatbots, evaluate their logic, and solve problems to improve the quality of ...Show moreLast updated: 30+ days ago
  • Promoted
Director of Innovative Programs (4801) Job 81039 - The Fung Institute

Director of Innovative Programs (4801) Job 81039 - The Fung Institute

InsideHigherEdBerkeley, California, United States
Full-time
Director of Innovative Programs (4801) Job 81039 - The Fung Institute.At the University of California, Berkeley, we are dedicated to fostering a community where everyone feels welcome and can thriv...Show moreLast updated: 30+ days ago
  • Promoted
Senior GRC Security Lead — ISO / NIST, Risk & Audits

Senior GRC Security Lead — ISO / NIST, Risk & Audits

LambdaSan Francisco, CA, United States
Full-time
A leading AI infrastructure company is seeking a Cybersecurity Risk Manager to enhance their compliance framework.Responsibilities include managing audits, communicating with stakeholders, and ensu...Show moreLast updated: 1 day ago
  • Promoted
Senior Risk Analyst

Senior Risk Analyst

Monzo BankSan Francisco, CA, United States
Full-time
Risk Analyst to support strategic initiatives across the Risk organization.You will develop deep expertise on processes and drive continuous process improvement initiatives, with a focus on program...Show moreLast updated: 2 days ago
  • Promoted
Policy Director (0566C), California Policy Lab - 81495

Policy Director (0566C), California Policy Lab - 81495

InsideHigherEdBerkeley, California, United States
Full-time
Policy Director (0566C), California Policy Lab - 81495.At the University of California, Berkeley, we are dedicated to fostering a community where everyone feels welcome and can thrive.Our culture o...Show moreLast updated: 30+ days ago
  • Promoted
Lead Principal - Governance Risk and Compliance

Lead Principal - Governance Risk and Compliance

Cloud Software Group, Inc.San Ramon, CA, United States
Full-time
We are seeking a highly skilled and experienced.Governance, Risk and Compliance team.The GRC specialist will play a critical role in managing and enhancing our Governance, Risk, and Compliance (GRC...Show moreLast updated: 12 days ago
  • Promoted
Remote Finance Director - AI Trainer ($50-$60 / hour)

Remote Finance Director - AI Trainer ($50-$60 / hour)

Data AnnotationNovato, California
Remote
Full-time +1
We are looking for a finance professional to join our team to train AI models.You will measure the progress of these AI chatbots, evaluate their logic, and solve problems to improve the quality of ...Show moreLast updated: 30+ days ago
  • Promoted
Governance, Risk & Compliance Analyst III - SOC 2

Governance, Risk & Compliance Analyst III - SOC 2

Sensiba LLPPleasanton, CA, United States
Full-time
At Sensiba, we're more than just a Top 75 Accounting Firm - we're a purpose-driven organization committed to making a meaningful impact for our clients, our people, and our communities.Recognized a...Show moreLast updated: 11 days ago