Live opening · Posted 6 days ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
The role
We are seeking a senior risk professional to be an independent advisor within our Risk & Compliance function to lead in advising the firm on Technology, AI and Innovation Risk. This role will lead the assessment, governance, and ongoing management of risks and regulatory requirements arising from the firm’s use of emerging technologies, including artificial intelligence (AI), automation, and digital innovation.
The successful candidate will combine strong regulatory and risk expertise with commercial pragmatism and a deep understanding of technology risk in a professional services or legal environment.
Key responsibilities
Strategic Technology & AI Risk Oversight
Lead the firm’s approach to identifying, assessing, and mitigating risks associated with new and emerging technologies, including AI tools and platforms.
Develop and maintain a Technology and AI Risk Framework, aligned to legal sector regulatory expectations and industry best practice.
Advise senior stakeholders (including CIO, CTO, Innovation teams, and partners) on risk, regulatory and reputational implications of technology adoption.
Collaborate closely with key stakeholders to ensure that AI Risk oversight complements and supports the firm's information security, data privacy and enterprise risk management frameworks.
Ensure alignment with firm-wide risk appetite and governance standards.
Business Partnering with IT & Innovation Teams
Act as a dedicated Risk advisor to IT, cybersecurity, and innovation functions.
Embed risk-by-design principles into technology development, procurement, and implementation processes.
Participate in key technology governance forums, steering committees, and project boards as appropriate.
AI Governance & Responsible Use
Design and implement policies covering responsible AI use, that embed and reflect the firm's compliance policies including:
Confidentiality
Model risk and explainability
Bias and ethical considerations
Client confidentiality, professional conduct obligations and legal privilege risks
AI security threats (e.g. prompt injection, data poisoning, model and data exfiltration), adversarial testing / AI red-teaming, model inventory and validation
Establish approval, review, detection and containment processes for AI tools (including generative AI), covering sanctioned tools and unsanctioned “shadow AI” use in collaboration with IT Risk & Security.
Establish approval and review processes for AI tools (including generative AI).
Working with the General Counsel team, ensure appropriate client disclosures where required, including in relation to Outside Counsel Guidelines and client-specific security and AI-use requirements.
Horizon Scanning
Monitor and interpret global regulatory developments relating to:
AI regulation (e.g. EU AI Act and equivalents)
Legal sector obligations and professional standards
NIS2 / DORA and equivalent operational resilience or cybersecurity regimes where in scope
Client-jurisdiction AI, data and security regimes applicable to firm operations or client requirements
Translate regulatory requirements into actionable internal policies and controls.
Technology Risk Assessment & Controls
Conduct and advise on risk assessments, as appropriate, for new systems, vendors, and technology deployments.
Collaborate with IT on:
Regulatory and client-obligation mapping for third-party and technology risk
Control-adequacy challenge and policy sign-off for information security controls
Regulatory notification, AI-incident handling, client disclosure and privilege considerations in incident response
Ensure risks are documented, tracked, and reported through appropriate governance forums.
Training & Culture
Develop and deliver training on technology and AI risks for lawyers and business services teams.
Promote a culture of responsible innovation and risk awareness.
Reporting & Governance
Provide regular reporting to the Executive Risk Committee and Board-level stakeholders on technology and AI risk exposure.
Maintain risk registers and key risk indicators (KRIs) relating to technology and innovation integrated with the firm’s enterprise and information security risk registers.
Your experience
Essential
Demonstrable experience in risk, ideally within a law firm or professional services environment.
Demonstrated experience in technology risk, AI governance, or digital transformation risk.
A strong understanding of:
Confidentiality obligations
Existing and emerging AI regulatory frameworks
Legal sector obligations and professional standards
Working knowledge of relevant security and AI governance frameworks, including ISO 27001, NIST, ISO 42001 or the NIST AI RMF.
Proven ability to partner with senior technology stakeholders.
Excellent judgment with a commercial and pragmatic approach to risk.
Strong communication skills with experience advising senior leadership.
Desirable
Experience working directly with AI tools, automation programs, or legal tech platforms.
Knowledge of frameworks such as ISO 27001, NIST, or similar.
Experience in third-party/vendor risk management.
Legal or regulatory background (e.g. lawyer, compliance officer) is advantageous.
Employment type
Full-time
Work arrangement
Hybrid
More openings worth a look
Recently tracked roles with full details and direct application links.