Senior Analyst-GRC
Summary
Leads GRC initiatives, audits IT/InfoSec/Privacy/AI controls, and maintains ISO certifications while managing risk programs for a global immigration law firm.
Who we are: BAL is a team of brilliant people who change lives through elite immigration work and collaborative innovation. We pursue the exceptional in all that we do, but never at the expense of our values. There’s no denying our work is demanding, both in volume and pace, but we’re up for the challenge. We love the balance of hard work and fun – so, you’ll see us in jeans as we shatter glass ceilings and conventional stereotypes. BAL employees feel valued, rewarded, and respected. We seek opportunities to be of service to others and our communities. We are committed to your growth and development, and want to set you up for success here at BAL and beyond.
Who you are: You are looking for work that has a purpose. You aren’t afraid to roll up your sleeves and get stuff done. You learn quickly. You move fast. You embrace challenge and detail as well as creative thinking. You believe you have something unique to contribute and you aren’t afraid to raise your hand. You understand that powering human achievement is ultimately about impacting a real person. You are looking for a place to grow and an environment where everyone has a spot and is genuinely welcome.
We’re better together: A bright, driven person like you and an industry-leading powerhouse like BAL? It’s a perfect combination! We truly want to see you succeed here and become an integral part of our mission to provide an experience that makes a positive difference in people’s lives. Come be a part of something special, where you can have an impact and be valued just for being you!
In addition to competitive pay, a discretionary annual bonus, and a supportive, team oriented culture, we offer an outstanding benefits package that includes medical, dental, vision, disability, and life insurance, sick time, unlimited vacation, and 401(k) with company match.
PRIMARY RESPONSIBILITIES:
- Leads and performs internal audits using a risk-based methodology; assess IT, InfoSec, Privacy, and AI-related controls and processes; develops and executes audit plans, manages and prioritizes findings based on risk ratings, and tracks corrective action plans to closure.
- Supports the ongoing management and improvement of BAL’s Information Security Management System (ISMS) and Privacy Information Management System (PIMS) to maintain compliance and certification with ISO standards 27001 and 27701.
- Supports privacy program operations including Records of Processing Activities maintenance, Data Protection Impact Assessments (DPIAs), and Data Subject Access Request (DSAR).
- Supports the expansion and ongoing management of BAL’s AI governance framework, including leading risk assessments of AI tools and use cases against applicable regulatory frameworks (e.g., EU AI Act), development and maintenance of AI acceptable use policies, creation and maintenance of an AI system inventory, and the development of AI specific vendor due diligence criteria.
- Supports the Third-Party Risk Management (TPRM) program by performing risk-tiered vendor assessments, security and privacy due diligence reviews, maintaining the vendor risk register, and escalating findings to appropriate stakeholders.
- Serves as the primary operator of BAL’s data loss prevention (DLP) tools, managing alert queues, refining detection policies and works with the SecOps team to review and escalate security operations alerts and vulnerabilities to ensure timely remediation.
- Supports review and response for Security Operations, and Privacy exposure events (incident response).
- Owns and maintains BAL’s Business Continuity and Disaster Recovery (BC/DR) program, including plan documentation, scheduled testing and tabletop exercises, gap identification and remediation tracking, and periodic reporting to firm leadership on program status and maturity.
- Development and management of BAL’s GRC metrics and reporting, including defining Key Performance Indicators (KPIs) and Key Risk Indicators (KRIs) across Information Security, Privacy, and AI governance domains.
- Supports the development and ongoing management of BAL's data governance program, including data classification, data inventory and mapping, records retention policy enforcement, and coordination with practice groups on data lifecycle management.
QUALIFICATIONS:
Skills and Abilities:
- Experience applying risk management methodologies to assess, prioritize, and remediate security, privacy, and compliance risks across complex organizational environments
- Demonstrated knowledge of information security and privacy frameworks including ISO 27001, ISO 27701, NIST CSF, and applicable data protection regulations (GDPR, U.S. state privacy laws)
- Familiarity with AI governance frameworks and emerging regulatory requirements (EU AI Act, NIST AI RMF) with the ability to translate regulatory obligations into operational controls
- Experience conducting and supporting internal audits, including audit planning, control testing, findings documentation, and remediation tracking
- Working knowledge of Third-Party Risk Management (TPRM) methodologies and vendor due diligence processes and best practices
- Familiarity with Data Loss Prevention (DLP) tooling, security operations alert management, and vulnerability triage processes
- Experience developing and maintaining KPIs and KRIs for GRC programs, with the ability to translate metrics into executive level reporting
- Strong interpersonal skills including the ability to achieve goals through genuine influence, collaboration, and cooperation
- Exceptional written and verbal communication skills with demonstrated ability to convey complex security, privacy, and compliance concepts clearly to both technical and non-technical audiences, including firm leadership, attorneys, and clients
- Ability to quickly adapt to new concepts / processes while maintaining performance levels within a dynamic and challenging environment
- Ability to maintain professionalism while interacting with customers and colleagues at all levels and to foster positive business relationships
- Ability to work independently and in a collaborative team environment
- Genuine interest in the evolving GRC and AI governance landscape, with a commitment to continuous learning and professional development
- Comfortable operating with autonomy in ambiguous situations; takes initiative to identify gaps and drive solutions forward
Experience:
- Minimum of 3-5 years’ experience in information security, GRC, compliance, or a related field, with demonstrated exposure to GRC, risk management, audit, and/or privacy programs.
- 2+ years’ direct experience in internal audit, GRC, or a compliance/risk role, with familiarity with audit methodologies, control testing, and findings documentation
- Experience with TPRM programs, AI governance frameworks, or assessing risk of third-party and AI/ML vendors a plus; familiarity with emerging regulatory standards (e.g., NIST AI RMF, EU AI Act) preferred
- Knowledge of ISO standards 27001 and 27701
- CISA, CRISC, CGRC (formerly CAP), or other relevant GRC or audit certification a plus
Minimum Education Level:
- Bachelor’s degree in related field or equivalent experience.
Note: To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed are representative of the knowledge, skill, and/or ability required and are not intended to be an exhaustive list of all duties, responsibilities or qualifications associated with this job.
Berry Appleman & Leiden is an Equal Opportunity Employer. It is the policy of BAL to ensure an equal employment opportunity without discrimination or harassment on the basis of race, color, national origin, religion, gender, gender identity or expression, age, disability, alienage or citizenship status, marital status, creed, genetic predisposition or carrier status, sexual orientation or any other characteristic protected by law. BAL prohibits and will not tolerate any such discrimination or harassment.
BAL does not accept unsolicited resumes from recruiters or employment agencies. BAL is under no obligation to pay any referral compensation or recruiter fee in the absence of a current executed Recruitment Services Agreement. In the event a recruiter or agency submits an unsolicited resume or candidate without an agreement, BAL reserves the right to pursue and hire said candidate(s) without any financial obligation to the recruiter or agency. Any unsolicited resumes, including those submitted to hiring managers, shall be deemed the property of BAL. If your agency would like to be considered as a potential recruiting partner, please forward your contact information to Recruitment@BAL.com.