Cleary Gottlieb is a pioneer in globalizing the legal profession. We have 14 offices in major financial centers around the world, but we operate as a single, integrated global partnership and not as a U.S. firm with a network of overseas locations. The firm employs approximately 1,100 lawyers from more than 50 countries.
Since 1946 our lawyers and staff have worked across practices, industries, jurisdictions, and continents to provide clients with simple, actionable approaches to their most complex legal and business challenges, whether domestic or international. We support every client relationship with intellectual agility, commercial acumen, and a human touch.
Reporting directly to the Firm's Director of Information Security, the Security Governance, Risk, and Compliance (GRC) Manager is considered an essential position in safeguarding our Firm's data and meeting clients' security requirements. This role spans at least three pillars of our GRC program: Client Security Assessment Management, ISO 27001/27701 Program Management, and Internal GRC Program and Audit Management. As a senior contributor within the Information Security Department, this role will take on additional responsibilities to support the team’s mission such as creating updated Security Awareness training materials.
This role is expected to manage other personnel within and outside the Information Security Department as required to gather and document up to date information about security controls, close gaps and findings, and perform audits; however, initially this role will not have any direct reports and this role is considered an individual contributor manager role at this time. This role must ensure that all security GRC policies and procedures remain up to date and professionally written amidst a period of tremendous change, and to work with other IT departments to do so. This role works closely with other GCR-adjacent security roles including a third party risk specialist, our security operations analyst, and our security engineering team, and is expected to have a significant amount of security related expertise. As needed, this person may draw from the availability of other team members to complete recurring tasks, such as first pass questionnaire completion.
This role will be our Firm’s primary point of contact for ongoing client security assessment requests, which are estimated to be at least 100+ such requests throughout the year, and range from full 150+ question questionnaires to minor vulnerability attestation requests. These assessments include handling the end-to-end process with the client compliance teams, and require a friendly demeanor coupled with deep expertise in our security program to guide these assessments through an initial response, detailed completion of security questionnaires, curation of evidence, and review meetings to step through evidence and findings. Critically, this role must ensure that our AI-assisted questionnaire automation platform (Vanta) answer bank remains up to date and is used to accelerate accurate completion of assessment requests. Note that this role routinely interfaces with our Risk Department (office of the General Counsel) to delegate specific questions and determine the appropriate response in the context of the client relationship.
As the official ISO ISMS/PIMS Coordinator/SME, and a full time member of our Information Security and Privacy Forum (ISPF), this role is responsible for preparing all ISPM bi-monthly meeting agendas and minutes, working with auditors to scheduling internal and external audits, performing annual Risk Assessments, gathering and reporting performance metrics, and managing an extensive queue of continuous improvements that are aligned to risk themes & control domains. This is a strategic program management level responsibility that works closely with the Director of Information Security to ensure that these improvements are prioritized and produce expected results. Note that the entire ISMS/PIMS is supported by a third party consulting company, and this role is not expected to operate along without this important resource.
Alongside the Director of Information Security, this role is also critical in developing our Security Awareness Program, including custom training videos and managing our phishing simulations. This role is expected to maintain currency of emerging cybersecurity news and incorporating any emerging themes into this program as necessary.
This role will regularly interface with the Firm’s Risk Department and IT Leadership, as well as other departments as required, to answer questions effectively. Taking any feedback from our client auditors, this role will be pivotal to inform the firm’s Information Security strategy in a measured manner.
The GRC Manager is a full-time member of the Firm's Information Security Department. They will collaborate with Senior Security Engineers, Security Operations Analysts, and Security Specialists to enhance core program elements, including incident response, assimilation of threat intelligence, vulnerability management, third-party risk management, and continuous compliance processes.
Cleary Gottlieb is a preeminent law firm that prides itself on providing an extremely collaborative and collegial environment that is perfect for your career growth. We are leading the legal industry in the use of cloud and AI technologies and would love for you to join our team. We offer unmatched flexibility for hybrid work as well as providing a lovely office downtown to meet and work alongside your peers in Information Technology.
1. Client Assessment Response Program
2. ISO Program Management (ISO 27001 and ISO 27701)
3. Governance and Compliance Framework
4. Policy Development and Documentation
5. Cybersecurity Awareness Program Management
6. Weekly Compliance Reporting
The estimated base salary range for this position is $205,000 to $225,000 at the time of posting. The actual salary offered will depend on a variety of job-related factors, including skills, education, training, credentials, experience, scope and complexity of role responsibilities, geographic location, and performance. This role is exempt meaning it is not overtime pay eligible.
Cleary provides a comprehensive benefits package, including health care benefits. More information can be found here: Benefits
We are an equal opportunity employer and prohibit discrimination based on any category protected by law. Cleary provides reasonable accommodations to enable otherwise qualified employees to perform the essential functions of their position, provided the accommodation does not pose an undue hardship to the Firm.
Click on the following links to view the California Privacy Policy and Notice at Collection for California Residents.