Grc Engineer

Legora Legora · Vertical AI · New York, NY · Security

This role builds the platform for Legora's assurance program, focusing on pipelines for evidence collection, policy enforcement in CI/CD, and agents for testing controls and drafting audit responses. It's an engineering role within the security organization, crucial because the company sells AI agents to law firms, making system behavior proof a product requirement. The role involves building technical evidence for AI certifications, translating policies into enforceable rules, and designing agentic workflows for evidence analysis and control testing.

What you'd actually do

  1. Build the pipelines and integrations that aggregate control, asset, and identity data across our stack (cloud, IdP, HRIS, source control, CI/CD) and turn it into automated checks, live dashboards, and audit evidence.
  2. Implement the unified controls library so one control satisfies many frameworks, with evidence collected once and mapped everywhere.
  3. Build the technical evidence base for our AI certifications (ISO/IEC 42001 and emerging AI-agent assurance standards): agent action logging, evaluation evidence, tool-call restrictions, and failure-mode documentation, working with Product and Engineering.
  4. Translate written policies and regulatory requirements into enforceable rules: automated checks in CI/CD and infrastructure deployment, continuous controls monitoring, and drift alerts routed to owners.
  5. Design and run agentic workflows for evidence analysis, control testing, and audit response preparation, with a human in the loop where assurance demands it. Anything manual twice a quarter gets automated.

Skills

Required

  • 5+ years spanning software or automation engineering and security compliance
  • Production-grade scripting (Python or similar) against APIs
  • Hands-on experience building LLM/agent workflows and daily use of AI in your own work
  • GRC domain fluency to work inside SOC 2 / ISO 27001 control language
  • Clear technical writing

Nice to have

  • Experience with compliance platform APIs
  • OSCAL or other machine-readable control/catalog formats
  • Infrastructure-as-code (Terraform or similar)
  • CI/CD pipeline engineering
  • Prior work on AI product assurance: evals, red-teaming evidence, or model/agent documentation

What the JD emphasized

  • AI agents to law firms
  • AI product assurance
  • agent action logging
  • evaluation evidence
  • tool-call restrictions
  • failure-mode documentation
  • agentic workflows

Other signals

  • AI-native workspace
  • AI agents to law firms
  • AI product assurance