Lead Governance, Risk, and Compliance (GRC) Analyst

Morrison & Foerster, LLP
Boston, MA

Overview

At MoFo, we couldn’t write our own success story without yours. Ready to write your story?

Join MoFo as a LEAD GRC ANALYST on our Information Technology team!

This role can be based in San Francisco, Palo Alto, Los Angeles, San Diego, Denver, Austin, Boston, New York or Washington, D.C.

About The Role

The Lead Governance, Risk, and Compliance (GRC) Analyst is responsible for managing the firm’s information security governance, risk, and compliance program. This role serves as the operational lead for maintaining ISO 27001 certification, managing client and vendor audits, overseeing policy governance, and ensuring continuous audit readiness across all systems and jurisdictions. The ideal candidate will be a subject matter expert in information security controls and audit practices, with deep experience in ISO 27001, NIST, and related frameworks. This position requires strong leadership, collaboration, and communication skills, along with the ability to engage effectively with senior leadership, clients, and external auditors.

Governance, Risk & Compliance

  • Lead and manage the firm’s Information Security Management System (ISMS) to maintain ISO 27001 certification and ongoing compliance.
  • Develop, implement, and monitor controls aligned with ISO 27001, NIST 800-53, DOJ, and CISA EO 14117 frameworks.
  • Serve as the primary liaison for internal, external, client, and vendor security audits, including documentation, evidence, and remediation tracking.
  • Manage the firm’s compliance calendar and ensure timely completion of assessments, certifications, and audits.
  • Improve compliance processes through automation, standardized evidence tracking, and enhanced reporting.
  • Oversee the governance and maintenance of security and privacy policies to ensure alignment with frameworks and regulatory requirements.
  • Conduct risk assessments and document mitigation strategies.
  • Collaborate with IT, Legal, Privacy, and business units to ensure consistent control implementation and reporting.
  • Track and report key performance metrics to measure compliance posture and program maturity.


Audit and Compliance Leadership

  • Manage all phases of ISO, client, and vendor audit cycles, from scoping to evidence delivery.
  • Engage with auditors, clients, and stakeholders to explain controls, policies, and security practices.
  • Maintain continuous audit readiness and coordinate corrective actions and improvement plans as needed.


Policy and Documentation Management

  • Maintain ISMS documentation, control inventories, and audit evidence repositories.
  • Review and update policies, procedures, and standards for clarity and alignment with business and legal requirements.
  • Prepare executive-level reports summarizing compliance posture and audit outcomes.


Program Maturity and Process Improvement

  • Identify opportunities to enhance compliance operations through process and technology improvements.
  • Lead initiatives to automate control monitoring and evidence collection.
  • Stay current on evolving regulatory requirements and advise leadership on necessary updates.


Client Service and Confidentiality

  • Serve as the primary client-facing representative for security and compliance inquiries.
  • Ensure timely and professional communication during client and vendor audit engagements.
  • Uphold firm confidentiality standards and escalate potential data protection or compliance incidents as required.


About You

  • Bachelor’s degree or higher in Information Technology, Cybersecurity, Business, or a related field.
  • 7-10 years of experience in information security governance, risk, and compliance roles.
  • Proven success managing ISO 27001 programs, client security audits, and vendor assessments.
  • Deep knowledge of ISO 27001 and NIST 800-53 frameworks; familiarity with DOJ and CISA EO 14117 guidance preferred.
  • Demonstrated ability to operate independently, lead audit activities, and manage complex compliance programs.
  • Strong background in control design, mapping, and governance documentation.
  • Required certifications: CISSP, CISA, or equivalent.
  • Preferred certifications: ISO 27001 Lead Auditor or Lead Implementer, CISM, or CRISC.


Core Competencies And Applied Skills

  • Audit Leadership: Proven ability to maintain continuous audit readiness and manage full audit cycles end-to-end.
  • Policy and Control Management: Expertise in control design, policy governance, and compliance validation.
  • Independent Execution: Operates with minimal supervision, showing initiative, accountability, and ownership.
  • Analytical Thinking: Strong risk assessment and problem-solving skills; ability to translate frameworks into actionable controls.
  • Communication: Excellent written and verbal skills with experience engaging clients, auditors, and senior leadership.
  • Organization: Skilled at managing multiple audits, priorities, and deliverables under tight deadlines.
  • Collaboration: Works effectively across IT, Legal, Privacy, and business teams to align compliance objectives.
  • Continuous Improvement: Identifies opportunities to enhance efficiency through process and technology optimization.


About Mofo

At MoFo, we collaborate as one firm, across borders, practice areas, and business functions and value fresh ideas and innovation over conformity and competition.

  • About Us:
  • Inclusion + Engagement:
  • Commitment to Pro Bono:
  • The MoFo Foundation:


About Our Benefits

MoFo offers a comprehensive benefits package starting on your first day.

  • A variety of options for medical, dental, vision, life and disability coverage to meet the needs of you and your family.
  • Industry-leading parental leave and family benefits including adoption and fertility treatment options and backup child and elder care.
  • Global wellness program, including free access to Talkspace and Calm apps.
  • Annual community service day to make an impact on your community and a birthday holiday just for fun.
  • Education reimbursement annually.
  • Dedicated Talent Development team.
  • Competitive annual profit-sharing contribution.


Where required by law, salary ranges are stated below. Additional compensation may include a discretionary bonus, overtime as applicable, health/welfare benefits, retirement contributions, paid holidays, and PTO. The range displayed is specifically for positions performed in those cities/states and may vary based on factors including but not limited to the following: local market data and ranges; an applicant's skills and prior relevant experience; and certain degrees, licensing, and certifications. The application deadline is May 13, 2026.

New York, San Francisco, Palo Alto salary range: $128k to $178k

Los Angeles, San Diego, Boston, Washington, D.C. salary range: $122k to $169k

Denver salary range: $114k to $159k

For questions regarding this position, please e-mail [email protected]
Posted 2025-11-15

Recommended Jobs

MuleSoft Developer

UniFirst
Wilmington, MA

This is a hybrid role with 50% on-site requirement in Wilmington, MA . We are seeking a skilled MuleSoft Developer to design, develop, and implement enterprise integration solutions using the Mul…

View Details
Posted 2025-09-16

Fleet Maintenance Customer Service Coordinator

Ryder System
Norton, MA

Fleet Maintenance Customer Service Coordinator Location Norton, MA : ( START ON A CAREER PATH WITH A COMPANY THAT HAS A FUTURE At Ryder, our most important competitive advantage is our people. CUL…

View Details
Posted 2025-11-14

Fire Alarm Lead Technician

TEKsystems
Boston, MA

Job Opening: Fire Alarm Technician Lead *This is a relocation opportunity in Raleigh, NC. We are seeking an experienced Fire Alarm Technician to join our team. This role involves the installation, pro…

View Details
Posted 2025-11-12

Contract Web & UX Strategist (3 months)

829 Studios
Boston, MA

Duration: Up to 3 month contract position. The Web & UX Strategist contractor is a temporary client-facing role on 829’s Web Strategy & UX team that is expected to be up to 40 hours/week.   Our wo…

View Details
Posted 2025-11-13

Accounts Payable Specialist

The Procopio Companies
Middleton, MA

Job Description Job Description Accounts Payable Specialist – The Procopio Companies Since the 1950s, The Procopio Companies (TPC) has grown through four generations of family leadership and a…

View Details
Posted 2025-11-07

Software Development Senior Manager (OCI)

Oracle
Boston, MA

**Job Description** At Oracle Cloud Infrastructure (OCI), we build the future of the cloud for Enterprises as a diverse team of fellow creators and inventors. We act with the speed and attitude of a s…

View Details
Posted 2025-11-13

Accounts Payable Manager

Flagship Pioneering
Cambridge, MA

&##128640; About Lila Lila Sciences is the world’s first scientific superintelligence platform and autonomous lab for life, chemistry, and materials science.  We are pioneering a new age of boundle…

View Details
Posted 2025-09-14

Software Engineer Co-op

Vestmark Internship Program
Wakefield, MA

  We are looking for a motivated  Software Engineer Intern with JAVA/Python and relational database experience with a passion for technology and solving complex problems to join our Engineeri…

View Details
Posted 2025-10-31

Health Informatics Analyst

Prime Therapeutics
Boston, MA

At Prime Therapeutics (Prime), we are a different kind of PBM, with a purpose beyond profits and a unique ability to connect care for those we serve. Looking for a purpose-driven career? Come build th…

View Details
Posted 2025-11-15

Drainage Design - Civil Engineer

Airport Solutions Group, LLC
Burlington, MA

Job Description Job Description Airport Solutions Group, LLC (ASG) is a leader in civil engineering and planning for airports across New England, and our commitment to quality and customer servic…

View Details
Posted 2025-11-07