Security Engineer
legora
Job Score
80 ptsAbout Us
Legora is redefining how legal work gets done. Not built for lawyers, built with them. We work alongside the world’s best legal teams, who expect excellence, precision, and speed, and we hold ourselves to the same bar.
Our AI-native workspace lets legal professionals move faster, think more clearly, and operate with sharper precision. By analysing thousands of documents in minutes and powering end-to-end workflows, we cut through complexity, teams can focus on what matters: judgment, strategy, and outcomes.
1,000+ customers across 50+ countries trust us, including Cleary Gottlieb, Goodwin, Linklaters, White & Case, Dentons, and Barclays. We’ve scaled to $100M+ in ARR, with teams across Europe, North America and APAC, and continue to expand through acquisitions including Qura, Walter AI and Graceview.
We partner with world-class performers: including Aaron Judge and the New York Yankees, Ludvig Åberg (and his caddie), and campaigns featuring Jude Law.
Joining Legora means three things.
We lean in: ownership over titles, outcomes over intentions.
We fight for excellence: high standards, direct, ego-free feedback.
We grow together: as a team and with our customers.
Mission before ego. Everyone contributes. No one coasts.
If you’re driven by impact, pace, and raising the bar. This is the place.
The role:
At Legora, security is the foundation of the trust our customers place in us. The world’s leading law firms, as well as some of the biggest corporations use our platform for their most sensitive matters, and we need security to be built into how we design, ship, operate, and scale.
We are looking for exceptional Security Engineers who can build leverage across a large surface area: a multi-tenant AI platform, a multi-cloud estate with Azure as our primary cloud, and an engineering organisation that ships fast. This is a hands-on engineering role. You will own security work end to end, build tooling and guardrails, embed with engineering teams, and make the secure path the default path.
We hire T-shaped security engineers. You should bring real depth in one of Application Security, Detection Engineering & Response, or Cloud & Platform Security, while staying credible across the others. Tell us in your application which area is your specialisation.
This role can be based in Stockholm or New York. It is a 5-day in-office role, we believe building together in person drives better outcomes.
What you will be doing:
Own security work end to end: architecture, tooling, roadmap, and outcomes.
Work embedded with engineering teams to make secure design, development, and operations the default.
Build and ship software: guardrails, detections, libraries, automation, and workflows that live in git, are reviewed, tested, and deployed through CI/CD.
Raise the security bar across engineering through design reviews, threat modelling, tooling, and enablement.
Fix the class of bug, not just the instance, by turning findings into patterns, defaults, or detections.
Secure a multi-tenant AI platform, including identity, authorisation, tenant isolation, data handling, and model-facing attack surfaces.
Build with LLMs and agents, and help secure code and workflows produced at agent speed.
Respond to incidents and write post-mortems that lead to meaningful technical and organisational improvements.
Your specialisation:
Application Security: Threat model features and architectures, review high-risk changes across authentication, authorisation, tenant isolation, and data handling, and secure AI and agentic product features against prompt injection, tool-use abuse, data exfiltration, and related attack paths.
Detection Engineering & Response: Own detection-as-code, security data pipelines, abuse and account-compromise detection, and incident response across corporate and product surfaces. Build the agents that run first-pass triage and investigation, plus the guardrails and evals that make their output trustworthy. No tiered queue.
Cloud & Platform Security: Harden identity, access, cloud control planes, CI/CD, supply chain, infrastructure-as-code, AKS baselines, tenant isolation primitives, and least-privilege access for engineers, workloads, and AI agents.
Who you are:
Several years of engineering experience in your security specialisation, with real depth in vulnerabilities you have found, incidents you have run, systems you have hardened, or tooling you have built.
You are an engineer who writes production-quality code; we work primarily in TypeScript/Node.js and Python.
You are comfortable operating across application security, detection and response, and cloud/platform security, even if one of those areas is your main depth.
You understand identity, authorisation, multi-tenancy, and where security boundaries tend to break.
You communicate clearly, translate risk into engineering terms, and influence teams without relying on mandates.
You are calm and structured under incident pressure, and honest afterwards.
You are excited by a small team with a large surface area, where the right answer is usually to build leverage rather than create queues.
Nice to have:
Experience securing LLM-based or agentic products.
Experience building a security function at a high-growth SaaS company.
Familiarity with multi-tenant SaaS isolation models.
Experience in environments with strict confidentiality, data residency, or professional secrecy requirements.
Supply chain security depth, such as SLSA, artifact signing, or SBOMs.
If you are close but not a perfect match on the list, apply anyway and tell us what you would own.
Legora is an Equal Opportunity Employer
At Legora, we believe great teams are built on diversity of thought and experience. We’re proud to be an equal opportunity employer and committed to creating an inclusive, high-performance culture where everyone can do their best work. We welcome people of all backgrounds and don’t discriminate based on race, color, religion, national origin, gender, gender identity or expression, sexual orientation, age, disability, veteran status, or any other characteristic protected by law.
About Information Security
The Information Security area is one of the most strategic and in-demand fields in the technology market. With the rise of cyberattacks, data breaches, and regulations like LGPD and GDPR, companies of all sizes invest heavily in professionals who can protect their digital assets.
Key specializations include Network Security, Cloud Security (AWS, Azure, GCP), Offensive Security (Penetration Testing, Red Team), Defensive Security (SOC, Blue Team), AppSec, and Security Governance. Tools like SIEM (Splunk, QRadar), firewalls, EDR, and Vulnerability Management platforms are essential.
Certifications like CISSP, CEH, OSCP, CompTIA Security+, and AWS Security Specialty are important differentiators. Information security professionals are among the highest-paid in the sector, with growing demand especially in fintechs, healthtechs, and large enterprises.
Discover Other Areas
Understand the scope of work, key skills, and tools used in different career areas.
About Design
The Design field, especially UX/UI and Product Design, has experienced significant growth in recent years. With accelerated business digitization, the demand for professionals who can create intuitive and pleasant digital experiences has never been higher.
Key skills include Figma, Sketch, Adobe XD, user research, design thinking, prototyping, and system design. Product designers are increasingly valued for their direct impact on business results.
Remote work has opened doors for Brazilian designers to work for global companies, with competitive salaries in dollars and euros.
About SEO Analyst
The SEO Analyst is the professional responsible for optimizing websites for search engines, increasing organic visibility and qualified traffic. With the growing importance of digital marketing, SEO professionals are fundamental to any online presence strategy.
Key skills include on-page and off-page SEO, technical SEO, keyword research, SEO audits, link building, optimized content creation, and metrics analysis. Tools like Google Search Console, Google Analytics, Ahrefs, Semrush, Moz, and Screaming Frog are essential for daily work.
SEO analysts in technology companies are highly valued, especially those who master technical SEO, Core Web Vitals, and data-driven content strategies. The field offers opportunities from junior analyst to head of SEO, with a focus on organic growth, domain authority, and return on investment.
About Ecommerce Analyst
The Ecommerce Analyst is the professional responsible for analyzing online sales data, buyer behavior, and virtual store performance to guide strategic decisions. They combine data analysis with ecommerce knowledge to optimize conversion, average order value, and return on investment.
Key skills include Google Analytics (GA4), Hotjar, conversion funnel analysis, cohort analysis, customer segmentation, pricing analysis, and ecommerce metrics (CAC, CLV, AOV, conversion rate). Knowledge of SQL, Power BI, Google Tag Manager, and platforms like Shopify and VTEX is a differentiator.
Ecommerce Analysts in technology companies are highly valued, especially those who can turn buyer behavior data into actionable insights to increase revenue and reduce cart abandonment. The field offers opportunities from junior analyst to ecommerce analytics manager.
About Tech Recruiter
The Tech Recruiter is a professional specialized in recruiting technology talent, from developers to AI engineers and DevOps professionals. They combine technical knowledge with recruitment skills to evaluate and attract highly qualified candidates.
Key skills include technical screening, analysis of technical profiles (GitHub, portfolios, blogs), knowledge of software stacks and architectures, networking in tech communities and events. Proficiency with tools like LinkedIn Recruiter, Gem, Ashby, and technical assessment platforms is a differentiator.
Tech Recruiters are scarce and highly paid professionals, especially those who can map and access passive talent in competitive markets like AI, data engineering, and cloud computing.
About Web Master
The Web Master is the professional responsible for maintaining, securing, and ensuring the technical performance of websites and web applications. They manage servers, hosting infrastructure, uptime monitoring, and ensure everything runs fast and reliably.
Key skills include server management (Apache, Nginx), hosting (AWS, Google Cloud, Azure), CDN (Cloudflare), SSL, DNS, web security (WAF, firewall), performance (Core Web Vitals, cache, compression), and versioning (Git, CI/CD). Knowledge of Docker, WordPress, cPanel, and monitoring (Sentry, New Relic) is a differentiator.
Web Masters in technology companies are highly valued, especially those who master DevOps, SRE, and can guarantee uptime and performance at scale. The field offers opportunities from junior webmaster to SRE and infrastructure engineer, with a focus on reliability, security, and speed.
Comments 0