Security Architect & GRC Lead

LawVu is the AI-native operating system for in-house legal - the foundational layer that powers the entire legal function. Our intelligent platform connects legal intake, matters, contracts, spend, and reporting in one connected workspace, enabling legal teams to work smarter, move faster, and deliver measurable business value.

 

Trusted by leading organizations including Discord, Employment Hero, Etsy, and many more, LawVu is helping legal teams transform from reactive service providers into strategic business partners.

 

Founded in New Zealand, LawVu is a fast-growing global software company with customers and employees across North America, Europe, Australia, and New Zealand. Backed by leading venture capital firms, including Insight Partners and Airtree Ventures, we're creating a new category of LegalOS software purpose-built for modern in-house legal teams.


This is a hands-on, strategic role in the Legal, Risk and Compliance team. You’ll partner closely with our product, engineering and go to market teams, and execute high-impact initiatives designed to ensure our product is meeting industry best practice approaches to security. You will be an expert who is deeply connected to our product and risk profile, so you can deliver projects that move the needle for our compliance program.

We're looking for a Security Architect & GRC Lead to own the strategy and direction of information security across the LawVu business and the LawVu Platform. This is a senior role for someone who can set the security architecture, support maturing our governance and compliance program, and move the security agenda forward, including how we securely and safely deploy AI within our products.

 

You'll define the framework, standards, and roadmap; support the Business Support Specialist and run the day-to-day operational and audit work. You'll sit within Legal, Risk & Compliance and partner closely with Engineering, Product, and the commercial teams.

 

What you'll own

Security strategy & architecture

-       Own the information security strategy, standards, and roadmap for the business, partnering closely with the Platform Engineering team to embed security work into the Platform roadmap

-       Provide security architecture oversight and governance, partnering with Engineering and Product to ensure solutions align with LawVu's security requirements and secure-by-design principles. Champion application and product security practices, including secure SDLC, architecture reviews, threat modelling, vulnerability management, and security requirements for new platform capabilities

-       Own security governance: policies, standards, and the risk management framework (risk register, assessments, and treatment).

Security compliance direction

-       Own the continuous maturity of LawVu's security compliance program, including ISO 27001 and SOC 2 (Type II).

-       Define the control framework and audit strategy and own auditor relationships at a strategic level.

AI security & safety

-       Support LawVu's approach to building and deploying AI features securely and responsibly, in partnership with the AI Governance function.

-       Address AI-specific risks - model and LLM integration security, agentic and MCP integrations, prompt injection, data leakage, and AI supply-chain risk.

-       Contribute security architecture and risk perspective to AI impact assessments and product risk determinations.

Third-party, data protection & incident readiness

-       Set the approach for third-party / vendor security risk, incident response, and business continuity / disaster recovery.

-       Partner with privacy and legal on data protection, breach management, and customer data commitments.

Customer trust

-       Act as the senior security voice on strategic customer and prospect engagements.

-       Own the direction of the customer trust program (trust documentation, RFP and due-diligence strategy), with the Business Support Specialist executing day-to-day.


What you'll bring

-       Proven experience leading information security and/or security architecture in a global SaaS environment.

-       Strong track record with ISO 27001 and SOC 2 - ideally having designed a control framework and taken an organisation through certification, not only maintained it.

-       Depth in cloud and application security, multi-tenant SaaS architecture, and secure development practices. Exposure to cloud environments (Azure/ AWS / GCP).

-       Genuine interest and experience in the security and safety of AI tools and products.

-       Experience delivering security outcomes through engineering teams - influencing roadmaps with evidence and risk framing rather than mandate.

-       Ability to translate security and risk into clear, commercial language for executives, auditors, and customers.

-       Experience partnering across Engineering, Product, Legal, and Commercial functions, and managing or mentoring others.

-       Deep experience with threat modelling and security architecture reviews, with a track record of coaching product and engineering teams to think about risk, attack paths, and security trade-offs as part of everyday design and prioritisation decisions.

-       Ability to establish a pragmatic, risk-based approach to product security, ensuring security effort is focused on the areas of greatest customer, business, and platform risk.

 

Nice to have

-       Certifications (desirable): CISSP, CISM, CCSP, ISO 27001 Lead Implementer / Auditor, or equivalent. Privacy credentials (e.g. CIPP) a plus.

-       Legal technology or another regulated / trust-sensitive industry.

-       Familiarity with data protection regimes across multiple jurisdictions (GDPR, UK GDPR, CCPA/CPRA, NZ Privacy Act).

What success looks like

First 90 days: clear picture of current posture and control framework; a prioritised security and GRC roadmap agreed with Head of Legal, Risk and Compliance and wider leadership.

First 6 months: Completion of LawVu’s ISO27001 and SOC2 re-certifications; finalised implementation of the GRC platform.

First 6–12 months: a maturing, well-architected security program; measurable risk reduction; a clear AI security agenda; and support the Business Support Specialist to run BAU effectively.

 

 

Reports to: Head of Legal, Risk & Compliance

 


What sets us apart:

  • Monthly wellness allowance to use on whatever enables you to bring your whole self to work – gym membership, massage, childcare…the list goes on!
  • Health insurance 
  • Extended paid parental leave
  • Extra paid day off on your birthday
  • Share options so you can have a piece of the pie
  • Home office allowance set up for remote employees

 

Why LawVu?

 

At LawVu we support many types of flexible working arrangements that allow you to balance your work, your life and your passions. We offer the opportunity to get onboard a growth company early and the opportunity to participate in LawVu’s success through our incentive scheme. LawVu has rapidly expanding offices and our work environment encourages continuous improvement and future career development. 

 

Our collaborative and inclusive culture is one we’re immensely proud of. We know that a diverse workforce is a strength that enables us to better understand and serve customers and innovate successfully. From the moment you join, you’ll feel welcome and supported to do the best work of your life.

 

Our team is only as strong as the culture it is built upon. Our core values are:

 

  • Inspire and Delight: We go the extra mile to create experiences that inspire and delight our customers.
  • Move Swiftly: We get things done quickly and efficiently.
  • Dig Deeper: No challenge is too big. We embrace challenges, learn from mistakes, and share knowledge.
  • Take Ownership: We take responsibility for our actions and their impact on the business.
  • Back Yourself. Back Others: We support and respect each other, building a high level of trust.
  • Bring Your Woo: We create a safe environment that fosters bringing your whole self to work.

 

We are constantly working towards making LawVu one of the best places to work, for everyone. LawVu is committed to providing equality of opportunity, valuing diversity and promoting a culture of inclusion. We will ensure this by fostering a workplace where people feel safe to be themselves, are able to do the best work of their lives and fulfil their potential. We believe by bringing together our diversity of thoughts and backgrounds, we will develop a world class product for the equally diverse customers we serve.

 

We make hiring decisions based on your experience, skills and passion. If you would like to apply and need reasonable adjustments or would like to note which pronouns you use at any point in the application or interview process, please let us know.

Business Services

New Zealand

Partager sur :

Conditions générales d’utilisationConfidentialitéCookiesPropulsé par Rippling