SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Legora is an AI-native legal workspace trusted by 1,000+ customers across 50+ countries, including major law firms like Cleary Gottlieb, Goodwin, and Linklaters. The company has scaled to $100M+ ARR and operates teams across Europe, North America, and APAC.
As a Customer Trust Specialist, you will be the front line for customer security, privacy, and compliance scrutiny. You'll own customer trust requests end-to-end, including security questionnaires (SIG, CAIQ, bespoke), DDQs, and security/AI sections of RFPs, delivering high-quality responses against agreed SLAs in time-sensitive sales and renewal cycles.
Key responsibilities include:
- Answering AI-trust questions from buyers regarding training-data handling, model-provider subprocessors, data residency, EU AI Act compliance, ISO/IEC 42001, and NIST AI RMF posture
- Translating Legora's security, privacy, and AI-governance posture into clear, confident answers for customer CISOs, general counsels, and procurement teams
- Developing deep expertise in Legora's platform, security controls, and AI supply chain to resolve complex trust questions
- Managing the trust portal and evidence repository, keeping SOC 2/ISO reports, penetration-test summaries, DPAs, subprocessor lists, and AI-governance documentation current and self-serve
- Supporting DPAs, security addenda, and non-standard customer security/AI terms in partnership with Legal
- Building response libraries and driving questionnaire automation to improve quality and turnaround time
- Identifying recurring questions and objections, partnering cross-functionally to close gaps
- Coordinating customer-facing security calls, audit responses, and follow-ups
- Shaping Customer Trust processes, workflows, and standards as an early team member
You will work in the San Francisco office 5 days per week, collaborating with Information Security, Privacy, Legal counsel, and Go-to-Market teams. The role requires turning customer scrutiny into signed, renewed, and expanded relationships.
REQUIREMENTS:
- 3–5 years in customer trust, security GRC, security assurance, third-party risk, or closely related customer-facing security or compliance role
- Proven ownership of complex, high-stakes B2B relationships with demanding security, procurement, and legal stakeholders
- Ability to translate technical security and AI-governance controls into clear, customer-ready answers with sound judgment on what to answer, caveat, or escalate
- Pattern recognition and proactive collaboration to drive lasting improvements
- Customer-obsessed, organized, detail-oriented, and able to perform under deadline pressure
- Technical curiosity and comfort learning new software, security concepts, and AI/compliance frameworks quickly
- Commitment to in-office presence 5 days per week
NICE TO HAVE:
- Familiarity with SOC 2, ISO 27001, GDPR, NIST, DPAs, and subprocessor management
- Exposure to AI governance and assurance (EU AI Act, ISO/IEC 42001, NIST AI RMF, model-training, data-retention questions)
- Certifications: CISA, CISM, CISSP, or ISO 27001 Lead Implementer/Lead Auditor
- Experience with trust/GRC tooling (Vanta, Drata, SafeBase, OneTrust, Conveyor, Loopio)
- Working understanding of cloud security, data handling, access, encryption, and data residency
- Background in SaaS, AI, or legal tech