Kirkland & Ellis LLP

Cybersecurity GRC Specialist II

Kirkland & Ellis LLP$116K — $144K *
Legal & Accounting
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree or equivalent with five (5) years of experience in IT Security required.
  • Preferred certifications include CISSP, CISA, or CISM along with relevant AI governance certifications.
  • Four (4) or more years in Information Security with hands-on technical experience is strongly preferred.
  • Strong working knowledge of security frameworks like ISO 27001 and NIST is required.
  • Experience in AI governance, security, and risk management is essential.
  • Proven ability to produce clear security documentation and communicate effectively with varied audiences.
  • Experience in leading risk assessments and client-facing security discussions with professionalism.

Responsibilities

  • Lead client and third-party security assessments and document evidence for audits.
  • Create and maintain security policies and guidelines with strong technical writing skills.
  • Manage processes to ensure IT systems meet cybersecurity and compliance requirements.
  • Advise technical and non-technical stakeholders as an Information Security subject matter expert.
  • Oversee vendor security risk management program, including assessments and remediation tracking.
  • Manage the security exception request process and provide risk treatment guidance.
  • Develop and evaluate the Security Awareness program roadmap and training effectiveness.

Benefits

  • Comprehensive healthcare coverage.
  • Paid time off.
  • Retirement plan options.
  • Personal support programs.
  • Tailored learning and development opportunities to help reach personal and professional goals.
Full Job Description
What You'll Do

Are you driven to strengthen security programs, reduce risk, and help organizations meet evolving cybersecurity expectations?

As a Security GRC Specialist II, you'll be a key member of the Governance, Risk, and Compliance (GRC) team, leading and executing core GRC programs while serving as a trusted Information Security subject matter expert. This role blends strategic oversight with hands-on execution-partnering with technical teams, business stakeholders, clients, and vendors to ensure security controls, policies, and risk practices are effective, compliant, and clearly communicated.

What You'll Do
  • Client & Third-Party Assessments: Lead responses to client security assessments, questionnaires, and audits, documenting evidence and performing risk assessments as needed.
  • Policy & Standards Management: Create, maintain, and evolve security policies, standards, guidelines, and supporting documentation through strong technical writing.
  • Risk & Compliance Assurance: Manage and support processes that ensure Information Technology (IT) systems meet cybersecurity, risk, and compliance requirements.
  • Security Consulting & SME Support: Serve as an Information Security subject matter expert, advising technical and non-technical stakeholders across the organization.
  • Vendor Risk Management: Manage the third-party Security Vendor Risk Management program, including assessments, remediation tracking, and lifecycle oversight.
  • Exception & Risk Treatment: Oversee the security exception request process and provide guidance on appropriate risk treatment decisions.
  • Security Awareness Program: Manage the full lifecycle of the Security Awareness program, including roadmap development, training evaluation, and effectiveness measurement.
  • GRC Platform Administration: Support and optimize Governance, Risk, and Compliance (GRC) technology platforms and associated workflows.
  • Controls & Compliance Evaluations: Conduct evaluations of IT programs and components to confirm alignment with published security standards and frameworks.

What You'll Bring

  • Education: Bachelor's degree or equivalent with five (5) years of work experience in IT Security is required.
  • Certifications: Certified Information Systems Security Professional (CISSP), Certified Information Security Auditor (CISA), Certified Information Security Manager (CISM), Advanced in AI Audit (AAIA), Advanced in AI Risk (AAIR), Advanced in AI Security Management (AAISM) or other relevant training and certifications are preferred.
  • Information Security Experience: Four (4) or more years of Information Security experience, with hands-on technical experience strongly preferred.
  • Framework & GRC Knowledge: Strong working knowledge of security frameworks and standards such as ISO 27001, National Institute of Standards and Technology (NIST), System and Organization Controls (SOC), and Standardized Information Gathering (SIG) is required.
  • AI Risk: Experience in Artificial Intelligence (AI) governance, security, and risk management is required.
  • Technical Writing & Communication: Proven ability to produce clear, well-structured security documentation and communicate complex technical topics to varied audiences.
  • Risk & Vendor Management Skills: Experience leading risk assessments, vendor security reviews, and client-facing security discussions with professionalism and tact.
  • GRC Tools & Technologies: Familiarity with GRC platforms, role-based access controls, and a broad range of security technologies and tools.
  • Analytical & Organizational Strength: Strong problem-solving, project management, and time management skills with the ability to work independently or collaboratively.
  • Technical Acumen: Working knowledge of areas such as authentication, encryption, firewalls, SIEM, intrusion detection/prevention, vulnerability management, mobile security, and privileged access management.
  • Collaboration & Professionalism: Client-focused mindset with strong interpersonal skills, attention to detail, and a commitment to maintaining accurate records and documentation.

Compensation

The base salary range below represents the low and high end of the salary range for this position in Chicago. This range may differ based on your geographic location and cost of living considerations. At Kirkland & Ellis, we consider compensation more than just a base salary. We offer an exceptional range of flexible benefits including comprehensive healthcare, paid time off, and retirement. We also offer personal support and tailored learning and development opportunities all designed to help you realize your full potential both in life and at work.

Compensation Range:

Chicago: $116,000 - $144,000

How to Apply

Thank you for your interest in Kirkland & Ellis LLP. To complete an application and submit your resume, please click "Apply Now."

Don't meet every job requirement? That's okay! If you're excited about this role but your experience doesn't perfectly fit every qualification, we encourage you to apply anyway. You may be just the right person for this role or others at Kirkland.

About Kirkland & Ellis LLP

Kirkland & Ellis LLP is an American law firm. Founded in 1909 in Chicago, Illinois, Kirkland & Ellis is the largest law firm in the world by revenue, the seventh-largest by number of attorneys, and is the first law firm in the world to reach US$4 billion in revenue. As of 2021, Kirkland & Ellis ranks third on Am Law's list of profits per equity partner. While Kirkland & Ellis was historically considered a firm focused on litigation, during the 2010s, it expanded private equity and restructuring practices which, together with large-scale commercial litigation, comprise the core legal service areas of the firm. Many attorneys from the firm have served as federal officials or judges, including United States Supreme Court Justice Brett Kavanaugh and former Attorney General William Barr.
Learn more about Kirkland & Ellis LLP
Industry
Founded
1909

Similar Jobs

More Jobs at Kirkland & Ellis LLP

More Legal & Accounting Jobs

  • Amazon
    Accounting Product Manager, eero
    $152K — $206K *
    Amazon
    San Francisco, CA 94112 (San Francisco County)
  • Senior Tax Manager
    $110K — $130K *
    Capstone
    Vail, CO 81657 (Eagle County)
  • Trust and Estate Attorney
    $95K — $115K *
    The Perillo Group
    Saint Louis, MO 63129 (Saint Louis County)
  • Carr, Riggs & Ingram
    Manager, Tax
    $90K — $110K *
    Carr, Riggs & Ingram
    Las Cruces, NM 88001 (Dona Ana County)
  • Investigator
    $80K — $95K *
    Federal Emergency Management Agency
    Washington, DC 20011 (District Of Columbia County)

Find similar Cybersecurity GRC Specialist II jobs: