Arnall Golden Gregory LLP (“AGG”), an Atlanta-based law firm with approximately 190 attorneys, is seeking an experienced Information Governance Specialist. This is a senior individual-contributor role that advances the firm’s information governance, data security, and responsible artificial intelligence programs across the matter lifecycle. The Specialist combines deep records and data governance expertise with practical fluency in emerging technologies—particularly the secure, compliant adoption of AI—to help the firm move forward safely rather than to stand in the way of progress.
The Specialist designs and operates governance processes, evaluates and risk-assesses new tools and vendors, defines access and identity models for firm systems, and partners closely with Knowledge Management, Conflicts, Litigation Support, the Office of the General Counsel, and Information Technology. The role serves as a trusted advisor who translates governance, privacy, and security requirements into workable solutions for attorneys and staff.
Position Reports to: Director of Information Governance
FLSA Status: Non-exempt
Overall Responsibilities
Primary duties include, but are not limited to, the following:
- Participate in the design, deployment, and ongoing operation of information governance policies and procedures across physical and electronic records, email, and litigation support data, ensuring consistent application of the firm’s retention schedules and disposition practices.
- Serve as a subject-matter resource on the responsible adoption of artificial intelligence, advising on appropriate use, data handling, retention, and confidentiality so attorneys and staff can use emerging tools safely and in line with professional and ethical obligations.
- Conduct vendor and third-party risk assessments for new and existing technologies, review security posture, data-protection commitments, and contractual safeguards (including zero-data-retention and confidentiality terms), and recommend conditions for safe approval.
- Execute data classification policies and procedures, and lead data quality, unification, and remediation efforts that improve the accuracy and reliability of client, matter, and administrative information.
- Govern Microsoft 365 and unstructured firm data, establishing controls for storage location, classification, retention, and protection of sensitive and regulated information.
- Design and improve governance-related workflows and automations, such as lateral attorney onboarding, matter intake and transfer, and access requests, to increase accuracy, speed, and auditability.
- Ensure compliance with ethical walls and legal hold processes, partnering with the Office of the General Counsel and Conflicts to identify, apply, and monitor restrictions and preservation obligations.
- Coordinate the collection, review, and release of electronic and physical records for lateral attorney onboarding, matter transfers, and client records transfer requests, applying firm withholding and release rules.
- Advise firm personnel on appropriate data storage locations and information governance questions, providing instruction and training to staff, attorneys, and other users.
- Monitor regulatory developments and emerging best practices in information governance, data privacy, security, and AI governance, and translate them into actionable guidance and program improvements.
- Collaborate with Knowledge Management, AI Team, Conflicts, Litigation Support, and Information Technology to support their initiatives and to embed governance early in new projects and system rollouts.
- Other tasks as assigned.
Required Qualifications
- Bachelor’s degree in a related field
- Demonstrated knowledge of information governance, records management, data security, and privacy principles.
- Working familiarity with AI governance concepts and the responsible, secure use of emerging technologies in a professional-services or regulated environment.
- Strong analytical skills, with the ability to interpret data and improve the management of client and administrative records.
- Ability to translate technical, security, and compliance requirements into clear guidance for non-technical stakeholders.
- Ability to work effectively both independently and as part of cross-functional teams.
Preferred Qualifications
- Minimum of two years of relevant experience in information governance, records management, data governance, or knowledge management, including experience operating at a senior or specialist level.
- Hands-on experience with records management and document management systems, including importing, exporting, and migrating data between systems.
- Experience conducting vendor security or third-party risk assessments, including review of security questionnaires, SOC 2 / ISO 27001 reports, and data-protection terms.
- Familiarity with AI governance frameworks (for example, NIST AI RMF, ISO 42001, or comparable emerging standards) and applicable privacy regulations.
- Experience building workflow automations within the Microsoft ecosystem (including Microsoft 365, SharePoint, and workflow/automation tooling) and with Microsoft data protection and governance capabilities.
Mental / Physical / Environmental Requirements
- Indoor offices with controlled temperatures and limited exposure to noise, dust, and chemicals.
- Mobility within the office, including movement from floor to floor.
- May sit for long periods of time.
- Crouching, kneeling, standing, walking, pushing, pulling, and lifting occasionally.
- Operating a personal computer, telephone, voicemail, and other office equipment on a regular basis.
- Must be able to express and exchange ideas by means of the spoken and written word.
- Must have the ability to convey detailed information in a clear and concise manner through the spoken and written word.
- Must demonstrate strong problem-solving skills.
Hours & General Provisions
Hours: Full-time, M–F, 9:00–5:30 (with 1 hour for lunch).
ADA: The employer will make reasonable accommodations in compliance with the Americans with Disabilities Act of 1990.
This job description will be reviewed periodically as duties and responsibilities change with business necessity. Essential and marginal job functions are subject to modification.