Corporate Security Engineer
legora
Job Score
90 ptsAbout Us
Legora is redefining how legal work gets done. Not built for lawyers, built with them. We work alongside the world’s best legal teams, who expect excellence, precision, and speed, and we hold ourselves to the same bar.
Our AI-native workspace lets legal professionals move faster, think more clearly, and operate with sharper precision. By analysing thousands of documents in minutes and powering end-to-end workflows, we cut through complexity, teams can focus on what matters: judgment, strategy, and outcomes.
1,000+ customers across 50+ countries trust us, including Cleary Gottlieb, Goodwin, Linklaters, White & Case, Dentons, and Barclays. We’ve scaled to $100M+ in ARR, with teams across Europe, North America and APAC, and continue to expand through acquisitions including Qura, Walter AI and Graceview.
We partner with world-class performers: including Aaron Judge and the New York Yankees, Ludvig Åberg (and his caddie), and campaigns featuring Jude Law.
Joining Legora means three things.
We lean in: ownership over titles, outcomes over intentions.
We fight for excellence: high standards, direct, ego-free feedback.
We grow together: as a team and with our customers.
Mission before ego. Everyone contributes. No one coasts.
If you’re driven by impact, pace, and raising the bar. This is the place.
About the team
The IT and AI Enablement function exists to make Legora itself run as well as the product we sell: secure, automated, and compounding over time. Legora builds AI that law firms trust with their most sensitive work, which makes us a target for capable, well-resourced adversaries. Information Security keeps that trust intact, builders-first and AI-first: we ship controls as software and let agents take the first pass, so the human work is the judgment layer. We are not looking for someone to administer consoles and work a compliance checklist. The Corporate Security Engineer owns the security of Legora’s own environment — the identities, devices, SaaS, and AI tools every employee depends on — the operating root of trust the rest of the company connects through.
What you’ll be doing
Own non-human identity — the service accounts, agents, and workloads that scale faster than headcount. Keep them inventoried and owned, scoped tightly, running on short-lived and secretless credentials, with a path to revoke at scale.
Set the authorization model for agents — scoped, revocable, and auditable: least-privilege at each MCP call, no token passthrough, and delegated authority rather than standing access.
Secure how Legora uses AI — govern employee use of LLMs and agents, keep client data on sanctioned paths, and make the safe path the fast one as teams adopt AI.
Advance identity for people — phishing-resistant MFA (passkeys / FIDO2), SSO, SCIM lifecycle, and least-privilege / just-in-time access across Google Workspace, Slack, Notion, and the SaaS estate — and cover the attack classes that defeat MFA alone — session / token theft, adversary-in-the-middle phishing, OAuth consent abuse — with continuous access evaluation to revoke live sessions on risk.
Raise the bar on SaaS security posture (SSPM) — configurations held to clear benchmarks, and risky OAuth grants, over-permissioned or stale admins, shadow SaaS / AI, and config drift surfaced continuously — the technical lens on the portfolio the SaaS Enablement & Governance Lead holds the system of record for.
Own endpoint and device trust — an Apple-first fleet on MDM and EDR, with access gated on device health via zero-trust / conditional access, partnering with IT Systems and Workplace Technology, who run the fleet and network.
Own data-protection controls (DLP) across endpoint, SaaS, browser, and AI-egress, run access reviews, and surface insider-risk signals to Detection & Response for investigation with People and Legal.
Build controls and guardrails as code (Python + Terraform / IaC) so security scales, tracked against agent-identity and MFA coverage, risky OAuth grants closed, and mean time to remediate and revoke.
Who you are
4+ years in corporate, enterprise, or IT security, with full ownership of security decisions and scope end to end.
A builder first — you write production-grade code (Python at least) and treat controls, automations, and detections as software you own, not tickets you close.
AI-first by conviction — you already reach for agents and LLMs (Claude Code and the like) to compress toil, and you have a clear view on where they’re trustworthy and where a human owns the call. Show us something you automated that used to eat your week.
Identity-, SaaS-, and AI-centric in how you think about security — the modern attack surface (identity as the new perimeter, the SaaS estate, endpoints, and the AI tools employees use), not network-perimeter or compliance-checklist.
Fluent with modern identity — an enterprise IdP (Okta and/or Microsoft Entra ID) and Google Workspace, SSO and SCIM lifecycle, phishing-resistant MFA, and the protocols underneath (SAML, OAuth 2.0, OIDC).
Energised by the threat model — you find it motivating, not daunting, that securing an AI company law firms trust with their most sensitive work means well-resourced adversaries and novel attack surface.
Nice to have
Securing AI systems — prompt-injection and exfiltration detection, agent / tool-use telemetry, and the OWASP LLM Top 10.
Identity threat detection (ITDR) and SaaS-identity tooling — Okta / Microsoft Entra ID Protection and e.g. Push Security.
Non-human identity and secrets — service-account governance, workload identity, and secrets management (e.g. 1Password, HashiCorp Vault).
Agent authorization — delegated authority and short-lived, narrowly-scoped tokens (OAuth token exchange / identity chaining), and MCP enterprise-managed authorization.
Endpoint at scale — Jamf (Apple) and Intune (Windows), with modern EDR.
Security automation and guardrails-as-code — deterministic workflows and SOAR (e.g. Tines, Torq).
DLP and insider-risk tooling — modern data-loss prevention and UEBA.
SOC 2 / ISO 27001 control implementation and compliance-as-code alongside engineering — GRC owns the certifications, you build and evidence the technical controls.
Experience with Okta, Microsoft Entra ID, 1Password, CrowdStrike, Jamf, Lumos, and our AI-native ITSM (Serval).
What’s In It For You
Global collaboration: Partner with teams and clients across Europe, APAC, and North America.
Competitive package: Comprehensive salary, benefits, and tools for success.
Meaningful work: Your efforts shape how thousands of lawyers use AI daily.
In-person environment: Union Square office designed for ambitious builders and company provided lunch daily.
Benefits & Perks: We invest in our people with a comprehensive, thoughtfully designed benefits package:
Medical, Dental & VisionMultiple medical plan options through Aetna and Kaiser Permanente
HSA or Healthcare FSA (based on plan selection)
Dental plans via MetLife
Vision plans via Vision Care
Family Support
Generous parental leave
Free access to Maven Clinic
Dependent Care FSA
Free One Medical membership for employees and dependents
Additional Perks
Pre-tax commuter benefits
Life Insurance + STD/LTD
401(K) with generous company match
Unlimited PTO
Robust voluntary benefits, including identity protection (via Aura), legal coverage via MetLife, pet savings programs, and more
Legora is an Equal Opportunity Employer
At Legora, we believe great teams are built on diversity of thought and experience. We’re proud to be an equal opportunity employer and committed to creating an inclusive, high-performance culture where everyone can do their best work. We welcome people of all backgrounds and don’t discriminate based on race, color, religion, national origin, gender, gender identity or expression, sexual orientation, age, disability, veteran status, or any other characteristic protected by law.
About Information Security
The Information Security area is one of the most strategic and in-demand fields in the technology market. With the rise of cyberattacks, data breaches, and regulations like LGPD and GDPR, companies of all sizes invest heavily in professionals who can protect their digital assets.
Key specializations include Network Security, Cloud Security (AWS, Azure, GCP), Offensive Security (Penetration Testing, Red Team), Defensive Security (SOC, Blue Team), AppSec, and Security Governance. Tools like SIEM (Splunk, QRadar), firewalls, EDR, and Vulnerability Management platforms are essential.
Certifications like CISSP, CEH, OSCP, CompTIA Security+, and AWS Security Specialty are important differentiators. Information security professionals are among the highest-paid in the sector, with growing demand especially in fintechs, healthtechs, and large enterprises.
About Product Owner
The Product Owner (PO) is the professional responsible for maximizing the value of the product delivered by the development team. They act as the voice of the customer and stakeholders, managing and prioritizing the product backlog, defining clear user stories, and ensuring the team works on the most valuable items for the business.
Key skills include backlog management, user story writing, prioritization (Mascow, RICE), agile methodologies (Scrum, Kanban), and stakeholder communication. Knowledge of tools like Jira, Trello, Azure DevOps, and Miro is essential.
Product Owners are highly sought-after professionals in the technology market, working collaboratively with Scrum Masters, Product Managers, and engineering teams to drive agility and continuous value delivery.
Discover Other Areas
Understand the scope of work, key skills, and tools used in different career areas.
About Cloud Solutions
The Cloud Solutions area is responsible for designing, implementing, and managing cloud infrastructure and services (AWS, Azure, GCP) for companies. Cloud professionals architect scalable, secure, and cost-optimized solutions, from data center migrations to serverless and multi-cloud architectures.
Key skills include IaC (Terraform, CloudFormation), containers (Docker, Kubernetes), serverless (Lambda, Cloud Functions), managed databases (RDS, DynamoDB, BigQuery), cloud networking (VPC, CDN, load balancer), and security (IAM, WAF, KMS). Knowledge of FinOps, cloud governance, and AWS/Azure/GCP certifications is a differentiator.
Cloud Solutions professionals in technology companies are highly valued, especially those who master multi-cloud architectures, FinOps, and can optimize costs while maintaining performance and security. The field offers opportunities from cloud engineer to cloud solutions architect, head of cloud, and chief cloud architect.
About Web Master
The Web Master is the professional responsible for maintaining, securing, and ensuring the technical performance of websites and web applications. They manage servers, hosting infrastructure, uptime monitoring, and ensure everything runs fast and reliably.
Key skills include server management (Apache, Nginx), hosting (AWS, Google Cloud, Azure), CDN (Cloudflare), SSL, DNS, web security (WAF, firewall), performance (Core Web Vitals, cache, compression), and versioning (Git, CI/CD). Knowledge of Docker, WordPress, cPanel, and monitoring (Sentry, New Relic) is a differentiator.
Web Masters in technology companies are highly valued, especially those who master DevOps, SRE, and can guarantee uptime and performance at scale. The field offers opportunities from junior webmaster to SRE and infrastructure engineer, with a focus on reliability, security, and speed.
About Traffic Manager
The Traffic Manager is the professional responsible for planning, executing, and optimizing paid media campaigns across various digital platforms. With the competitiveness of the digital market, paid traffic professionals are essential for generating qualified leads and maximizing return on advertising investment.
Key skills include campaign management on Google Ads, Meta Ads, LinkedIn Ads, and TikTok Ads, media planning, metrics analysis (ROAS, CPA, CPC, CTR), A/B testing, remarketing, and landing page creation. Tools like Google Analytics, Google Tag Manager, Hotjar, and automation platforms are essential.
Traffic managers in technology companies are highly valued, especially those who master performance marketing, conversion funnel optimization, and scaling strategies. The field offers opportunities from media analyst to head of performance, with a focus on growth, budget efficiency, and return on investment.
About Business Analysis
The Business Analyst (BA) is the professional responsible for identifying problems, opportunities, and solutions in organizational processes, acting as a bridge between business areas and the technology development team. They gather and specify requirements, map value streams, design future processes, and help ensure that software deliveries align with the company's strategic goals.
About Human Resources
The Human Resources area is responsible for all people management in organizations, from attracting and selecting talent to developing, retaining, and ensuring employee well-being. HR professionals are fundamental to building strong organizational cultures and engagement.
Key skills include recruitment and selection, compensation and benefits management, learning and development (L&D), organizational climate, employee engagement, labor law, labor relations, and HR tools (Workday, SAP SuccessFactors, Bamboo HR). Knowledge of people analytics and data-driven HR is a differentiator.
HR professionals in technology companies are highly valued, especially those who master employer branding, people analytics, and talent retention strategies. The field offers opportunities from HR analyst to Chief People Officer, with a focus on culture, engagement, and people growth.
Comments 0