Talent.com
Lead Governance, Risk, and Compliance (GRC) Analyst
Lead Governance, Risk, and Compliance (GRC) AnalystMorrison Foerster • San Francisco, CA, United States
No longer accepting applications
Lead Governance, Risk, and Compliance (GRC) Analyst

Lead Governance, Risk, and Compliance (GRC) Analyst

Morrison Foerster • San Francisco, CA, United States
12 days ago
Job type
  • Full-time
Job description

Lead Governance, Risk, and Compliance (GRC) Analyst

This role can be based in San Francisco, Palo Alto, Los Angeles, San Diego, Denver, Austin, Boston, New York or Washington, D.C. (see https : / / www.mofo.com / offices ). This role requires a strong leader with expertise in information security governance and ISO 27001.

Overview

At MoFo, we couldn’t write our own success story without yours. Ready to write your story? Join MoFo as a LEAD GRC ANALYST on our Information Technology team!

About The Role

The Lead Governance, Risk, and Compliance (GRC) Analyst is responsible for managing the firm’s information security governance, risk, and compliance program. This role serves as the operational lead for maintaining ISO 27001 certification, managing client and vendor audits, overseeing policy governance, and ensuring continuous audit readiness across all systems and jurisdictions.

Governance, Risk & Compliance

  • Lead and manage the firm’s Information Security Management System (ISMS) to maintain ISO 27001 certification and ongoing compliance.
  • Develop, implement, and monitor controls aligned with ISO 27001, NIST 800-53, DOJ, and CISA EO 14117 frameworks.
  • Serve as the primary liaison for internal, external, client, and vendor security audits, including documentation, evidence, and remediation tracking.
  • Manage the firm’s compliance calendar and ensure timely completion of assessments, certifications, and audits.
  • Improve compliance processes through automation, standardized evidence tracking, and enhanced reporting.
  • Oversee the governance and maintenance of security and privacy policies to ensure alignment with frameworks and regulatory requirements.
  • Conduct risk assessments and document mitigation strategies.
  • Collaborate with IT, Legal, Privacy, and business units to ensure consistent control implementation and reporting.
  • Track and report key performance metrics to measure compliance posture and program maturity.

Audit & Compliance Leadership

  • Manage all phases of ISO, client, and vendor audit cycles, from scoping to evidence delivery.
  • Engage with auditors, clients, and stakeholders to explain controls, policies, and security practices.
  • Maintain continuous audit readiness and coordinate corrective actions and improvement plans as needed.
  • Policy and Documentation Management

  • Maintain ISMS documentation, control inventories, and audit evidence repositories.
  • Review and update policies, procedures, and standards for clarity and alignment with business and legal requirements.
  • Prepare executive‑level reports summarizing compliance posture and audit outcomes.
  • Program Maturity and Process Improvement

  • Identify opportunities to enhance compliance operations through process and technology improvements.
  • Lead initiatives to automate control monitoring and evidence collection.
  • Stay current on evolving regulatory requirements and advise leadership on necessary updates.
  • Client Service and Confidentiality

  • Serve as the primary client‑facing representative for security and compliance inquiries.
  • Ensure timely and professional communication during client and vendor audit engagements.
  • Uphold firm confidentiality standards and elevate potential data protection or compliance incidents as required.
  • About You

  • Bachelor’s degree or higher in Information Technology, Cybersecurity, Business, or a related field.
  • 7–10 years of experience in information security governance, risk, and compliance roles.
  • Proven success managing ISO 27001 programs, client security audits, and vendor assessments.
  • Deep knowledge of ISO 27001 and NIST 800-53 frameworks; familiarity with DOJ and CISA EO 14117 guidance preferred.
  • Demonstrated ability to operate independently, lead audit activities, and manage complex compliance programs.
  • Strong background in control design, mapping, and governance documentation.
  • Required certifications : CISSP, CISA, or equivalent.
  • Preferred certifications : ISO 27001 Lead Auditor or Lead Implementer, CISM, or CRISC.
  • Core Competencies And Applied Skills

  • Audit Leadership : Proven ability to maintain continuous audit readiness and manage full audit cycles end‑to‑end.
  • Policy and Control Management : Expertise in control design, policy governance, and compliance validation.
  • Independent Execution : Operates with minimal supervision, showing initiative, accountability, and ownership.
  • Analytical Thinking : Strong risk assessment and problem‑solving skills; ability to translate frameworks into actionable controls.
  • Communication : Excellent written and verbal skills with experience engaging clients, auditors, and senior leadership.
  • Organization : Skilled at managing multiple audits, priorities, and deliverables under tight deadlines.
  • Collaboration : Works effectively across IT, Legal, Privacy, and business teams to align compliance objectives.
  • Continuous Improvement : Identifies opportunities to enhance efficiency through process and technology optimization.
  • About MoFo

    At MoFo, we collaborate as one firm, across borders, practice areas, and business functions and value fresh ideas and innovation over conformity and competition.

  • About Us : https : / / www.mofo.com / about
  • Inclusion + Engagement : https : / / www.mofo.com / community / we-at-mofo
  • Commitment to Pro Bono : https : / / careers.mofo.com / careers-pro-bono
  • The MoFo Foundation : https : / / www.mofo.com / culture / mofo-foundation
  • Our Benefits

  • A variety of options for medical, dental, vision, life and disability coverage to meet the needs of you and your family.
  • Industry‑leading parental leave and family benefits including adoption and fertility treatment options and backup child and elder care.
  • Global wellness program, including free access to Talkspace and Calm apps.
  • Annual community service day to make an impact on your community and a birthday holiday just for fun.
  • Education reimbursement annually.
  • Dedicated Talent Development team.
  • Competitive annual profit‑sharing contribution.
  • Compensation

    Where required by law, salary ranges are stated below. Additional compensation may include a discretionary bonus, overtime as applicable, health / welfare benefits, retirement contributions, paid holidays, and PTO. The range displayed is specifically for positions performed in those cities / states and may vary based on factors including but not limited to the following : local market data and ranges; an applicant's skills and prior relevant experience; and certain degrees, licensing, and certifications.

  • New York, San Francisco, Palo Alto : $128k to $178k
  • Los Angeles, San Diego, Boston, Washington, D.C. : $122k to $169k
  • Denver : $114k to $159k
  • The application deadline is May 13, 2026.

    For questions regarding this position, please e-mail jobs@mofo.com

    #J-18808-Ljbffr

    Create a job alert for this search

    Lead Governance Risk Compliance • San Francisco, CA, United States

    Related jobs
    Lead Governance, Risk, and Compliance (GRC) Analyst

    Lead Governance, Risk, and Compliance (GRC) Analyst

    Morrison & Foerster LLP • San Francisco, CA, United States
    Full-time
    Lead Governance, Risk, and Compliance (GRC) Analyst.Position Type : Information Technology.At MoFo, we couldn't write our own success story without yours. This role can be based in San Francisco, Pal...Show more
    Last updated: 9 days ago • Promoted
    Governance, Risk & Compliance Lead

    Governance, Risk & Compliance Lead

    Perplexity • San Francisco, CA, United States
    Full-time
    Perplexity is seeking a highly experienced Governance, Risk & Compliance Analyst to join our world-class team.You will help shape our compliance and risk management program.If you are a self-motiva...Show more
    Last updated: 6 hours ago • Promoted • New!
    Governance, Risk & Compliance Lead

    Governance, Risk & Compliance Lead

    Perplexity AI Inc. • San Francisco, CA, United States
    Full-time
    Perplexity is seeking a highly experienced Governance, Risk & Compliance Analyst to join our world-class team.You will help shape our compliance and risk management program.If you are a self-motiva...Show more
    Last updated: 22 days ago • Promoted
    Lead Specialist, Governance, Risk, & Compliance

    Lead Specialist, Governance, Risk, & Compliance

    KPMG US • San Francisco, CA, United States
    Full-time
    Lead Specialist, Governance, Risk, & Compliance.Apply for the Lead Specialist, Governance, Risk, & Compliance role at KPMG US. KPMG Advisory practice is currently our fastest growing practice.We are...Show more
    Last updated: 30+ days ago • Promoted
    Solution Director, Employee Experience Solutions - Healthcare Growth

    Solution Director, Employee Experience Solutions - Healthcare Growth

    PG Forsta • Emeryville, CA, United States
    Full-time
    PG Forsta is the leading experience measurement, data analytics, and insights provider for complex industries-a status we earned over decades of deep partnership with clients to help them understan...Show more
    Last updated: 30+ days ago • Promoted
    Security GRC Analyst

    Security GRC Analyst

    Nava Software Solutions • San Francisco, CA, United States
    Full-time
    NAVA Software solutions is looking for a Security GRC Analyst.Location : San Francisco , CA - Hybrid.Analyst with 2+ years' experience and with good understanding of security controls and compliance...Show more
    Last updated: 15 days ago • Promoted
    Credit Risk Lead

    Credit Risk Lead

    Cardless, Inc. • San Francisco, CA, United States
    Full-time
    At Cardless, we’re building a credit card and loyalty platform that consumer businesses use to engage their customers.We’ve launched 14 credit cards, including for Alibaba and Qatar Airways.We help...Show more
    Last updated: 30+ days ago • Promoted
    AI & Data Governance Manager, Finance

    AI & Data Governance Manager, Finance

    Electronic Arts • Redwood City, CA, United States
    Full-time
    Electronic Arts creates next-level entertainment experiences that inspire players and fans around the world.Here, everyone is part of the story. Part of a community that connects across the globe.A ...Show more
    Last updated: 2 days ago • Promoted
    Audit Director - Assurance & Advisory - State and Local Government

    Audit Director - Assurance & Advisory - State and Local Government

    International Staffing Consultants • Albany, CA, US
    Full-time
    Audit Director - Assurance & Advisory - State and Local Government.The Director is the liaison between the Partner, the client, and the professional staff. Directors are responsible for managing mul...Show more
    Last updated: 30+ days ago • Promoted
    Governance, Risk, and Compliance Lead

    Governance, Risk, and Compliance Lead

    xAI • San Francisco, CA, United States
    Full-time
    Governance, Risk, and Compliance Lead.Governance, Risk, and Compliance Lead.Get AI-powered advice on this job and more exclusive features. AI’s mission is to create AI systems that can accurately un...Show more
    Last updated: 30+ days ago • Promoted
    Senior GRC Security Lead — ISO / NIST, Risk & Audits

    Senior GRC Security Lead — ISO / NIST, Risk & Audits

    Lambda • San Francisco, CA, United States
    Full-time
    A leading AI infrastructure company is seeking a Cybersecurity Risk Manager to enhance their compliance framework.Responsibilities include managing audits, communicating with stakeholders, and ensu...Show more
    Last updated: 8 days ago • Promoted
    Senior GRC Analyst II

    Senior GRC Analyst II

    Menlo Ventures • San Francisco, CA, United States
    Full-time
    Location : San Francisco, CA; Seattle, WA; New York City, NY.Carta connects founders, investors, and limited partners through world‑class software, purpose‑built for everyone in venture capital, pri...Show more
    Last updated: 14 days ago • Promoted
    Manager, Security Governance Risk and Compliance

    Manager, Security Governance Risk and Compliance

    KPMG • San Francisco, CA, United States
    Full-time
    Known for being a great place to work and build a career, KPMG provides audit, tax and advisory services for organizations in today's most important industries. Our growth is driven by delivering re...Show more
    Last updated: 11 days ago • Promoted
    Lead Analyst, Digital Data Governance & Compliance

    Lead Analyst, Digital Data Governance & Compliance

    Fox Rothschild • San Francisco, CA, United States
    Full-time
    As a member of the Information Services department, the Lead Analyst, Digital Data Governance & Compliance will drive and support our firm-wide electronic governance initiatives.This key role will ...Show more
    Last updated: 18 days ago • Promoted
    Director, Analytical Development

    Director, Analytical Development

    REVOLUTION Medicines • Redwood City, CA, United States
    Full-time
    Revolution Medicines is a clinical-stage precision oncology company focused on developing novel targeted therapies to inhibit frontier targets in RAS-addicted cancers. The company's R&D pipeline com...Show more
    Last updated: 18 days ago • Promoted
    Governance, Risk & Compliance Lead

    Governance, Risk & Compliance Lead

    Pantera Capital • San Francisco, CA, United States
    Full-time
    Perplexity is an AI-powered answer engine founded in December 2022 and growing rapidly as one of the world’s leading AI platforms. Perplexity has raised over $1B in venture investment from some of t...Show more
    Last updated: 23 days ago • Promoted
    Senior TPM : Risk, Compliance & Governance Leader

    Senior TPM : Risk, Compliance & Governance Leader

    WEX, Inc. • San Francisco, CA, United States
    Full-time
    A leading financial services provider is seeking a Senior Technical Program Manager in San Francisco to lead risk and compliance initiatives. This role requires managing multi-faceted programs and e...Show more
    Last updated: 6 hours ago • Promoted • New!
    Founding Security Engineer - Governance, Risk & Compliance (GRC)

    Founding Security Engineer - Governance, Risk & Compliance (GRC)

    Sift Science • San Francisco, CA, United States
    Permanent
    At Sift, we're redefining how modern machines are built, tested, and operated.Our platform provides engineers with real-time observability over high-frequency telemetry, eliminating bottlenecks and...Show more
    Last updated: 30+ days ago • Promoted