Security Architect & GRC Lead @LawVu
Legal
Salary unspecified
Remote Location
Employment Type full-time
Posted 3wks ago

[Hiring] Security Architect & GRC Lead @LawVu

3wks ago - LawVu is hiring a remote Security Architect & GRC Lead. πŸ’Έ Salary: unspecified πŸ“Location: New Zealand

Role Description

This is a hands-on, strategic role in the Legal, Risk and Compliance team. You’ll partner closely with our product, engineering and go to market teams, and execute high-impact initiatives designed to ensure our product is meeting industry best practice approaches to security. You will be an expert who is deeply connected to our product and risk profile, so you can deliver projects that move the needle for our compliance program.

We're looking for a Security Architect & GRC Lead to own the strategy and direction of information security across the LawVu business and the LawVu Platform. This is a senior role for someone who can set the security architecture, support maturing our governance and compliance program, and move the security agenda forward, including how we securely and safely deploy AI within our products.

What you'll own

  • Security strategy & architecture
    • Own the information security strategy, standards, and roadmap for the business, partnering closely with the Platform Engineering team to embed security work into the Platform roadmap.
    • Provide security architecture oversight and governance, partnering with Engineering and Product to ensure solutions align with LawVu's security requirements and secure-by-design principles. Champion application and product security practices, including secure SDLC, architecture reviews, threat modelling, vulnerability management, and security requirements for new platform capabilities.
    • Own security governance: policies, standards, and the risk management framework (risk register, assessments, and treatment).
  • Security compliance direction
    • Own the continuous maturity of LawVu's security compliance program, including ISO 27001 and SOC 2 (Type II).
    • Define the control framework and audit strategy and own auditor relationships at a strategic level.
  • AI security & safety
    • Support LawVu's approach to building and deploying AI features securely and responsibly, in partnership with the AI Governance function.
    • Address AI-specific risks - model and LLM integration security, agentic and MCP integrations, prompt injection, data leakage, and AI supply-chain risk.
    • Contribute security architecture and risk perspective to AI impact assessments and product risk determinations.
  • Third-party, data protection & incident readiness
    • Set the approach for third-party / vendor security risk, incident response, and business continuity / disaster recovery.
    • Partner with privacy and legal on data protection, breach management, and customer data commitments.
  • Customer trust
    • Act as the senior security voice on strategic customer and prospect engagements.
    • Own the direction of the customer trust program (trust documentation, RFP and due-diligence strategy), with the Business Support Specialist executing day-to-day.

Qualifications

  • Proven experience leading information security and/or security architecture in a global SaaS environment.
  • Strong track record with ISO 27001 and SOC 2 - ideally having designed a control framework and taken an organisation through certification, not only maintained it.
  • Depth in cloud and application security, multi-tenant SaaS architecture, and secure development practices.
  • Exposure to cloud environments (Azure/ AWS / GCP).
  • Genuine interest and experience in the security and safety of AI tools and products.
  • Experience delivering security outcomes through engineering teams - influencing roadmaps with evidence and risk framing rather than mandate.
  • Ability to translate security and risk into clear, commercial language for executives, auditors, and customers.
  • Experience partnering across Engineering, Product, Legal, and Commercial functions, and managing or mentoring others.
  • Deep experience with threat modelling and security architecture reviews, with a track record of coaching product and engineering teams to think about risk, attack paths, and security trade-offs as part of everyday design and prioritisation decisions.
  • Ability to establish a pragmatic, risk-based approach to product security, ensuring security effort is focused on the areas of greatest customer, business, and platform risk.

Requirements

  • Certifications (desirable): CISSP, CISM, CCSP, ISO 27001 Lead Implementer / Auditor, or equivalent. Privacy credentials (e.g. CIPP) a plus.
  • Legal technology or another regulated / trust-sensitive industry.
  • Familiarity with data protection regimes across multiple jurisdictions (GDPR, UK GDPR, CCPA/CPRA, NZ Privacy Act).

Benefits

  • Monthly wellness allowance to use on whatever enables you to bring your whole self to work – gym membership, massage, childcare…the list goes on!
  • Health insurance
  • Extended paid parental leave
  • Extra paid day off on your birthday
  • Share options so you can have a piece of the pie
  • Home office allowance set up for remote employees
Before You Apply
️
remote Be aware of the location restriction for this remote position: New Zealand
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Security Architect & GRC Lead @LawVu
Legal
Salary unspecified
Remote Location
Employment Type full-time
Posted 3wks ago
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
️
remote Be aware of the location restriction for this remote position: New Zealand
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
Γ—
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews

⚑ 127,256+ remote jobs, refreshed hourly

πŸ”” Real-time alerts: Apply first, direct to employer

πŸ›‘οΈ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later