Corporate Security Engineer

Posted Yesterday
Be an Early Applicant
New York City, NY, USA
In-Office
188K-221K Annually
Mid level
Artificial Intelligence • Legal Tech • Software
Collaborative AI for exceptional lawyers
The Role
Own and harden Legora's corporate security posture across identities, non-human and human accounts, SaaS, endpoints, and AI use. Build guardrails-as-code (Python/Terraform), enforce least-privilege and phishing-resistant MFA, govern LLM/agent usage, run DLP and access reviews, and automate remediation for risky OAuth grants and device risk.
Summary Generated by Built In
About Us

Legora is redefining how legal work gets done. Not built for lawyers, built with them. We work alongside the world’s best legal teams, who expect excellence, precision, and speed, and we hold ourselves to the same bar.
Our AI-native workspace lets legal professionals move faster, think more clearly, and operate with sharper precision. By analysing thousands of documents in minutes and powering end-to-end workflows, we cut through complexity, teams can focus on what matters: judgment, strategy, and outcomes.
1,000+ customers across 50+ countries trust us, including Cleary Gottlieb, Goodwin, Linklaters, White & Case, Dentons, and Barclays. We’ve scaled to $100M+ in ARR, with teams across Europe, North America and APAC, and continue to expand through acquisitions including Qura, Walter AI and Graceview.
We partner with world-class performers: including Aaron Judge and the New York Yankees, Ludvig Åberg (and his caddie), and campaigns featuring Jude Law.
Joining Legora means three things.

  • We lean in: ownership over titles, outcomes over intentions.

  • We fight for excellence: high standards, direct, ego-free feedback.

  • We grow together: as a team and with our customers.

Mission before ego. Everyone contributes. No one coasts.

If you’re driven by impact, pace, and raising the bar. This is the place.

About the team

The IT and AI Enablement function exists to make Legora itself run as well as the product we sell: secure, automated, and compounding over time. Legora builds AI that law firms trust with their most sensitive work, which makes us a target for capable, well-resourced adversaries. Information Security keeps that trust intact, builders-first and AI-first: we ship controls as software and let agents take the first pass, so the human work is the judgment layer. We are not looking for someone to administer consoles and work a compliance checklist. The Corporate Security Engineer owns the security of Legora’s own environment — the identities, devices, SaaS, and AI tools every employee depends on — the operating root of trust the rest of the company connects through.

What you’ll be doing
  • Own non-human identity — the service accounts, agents, and workloads that scale faster than headcount. Keep them inventoried and owned, scoped tightly, running on short-lived and secretless credentials, with a path to revoke at scale.

  • Set the authorization model for agents — scoped, revocable, and auditable: least-privilege at each MCP call, no token passthrough, and delegated authority rather than standing access.

  • Secure how Legora uses AI — govern employee use of LLMs and agents, keep client data on sanctioned paths, and make the safe path the fast one as teams adopt AI.

  • Advance identity for people — phishing-resistant MFA (passkeys / FIDO2), SSO, SCIM lifecycle, and least-privilege / just-in-time access across Google Workspace, Slack, Notion, and the SaaS estate — and cover the attack classes that defeat MFA alone — session / token theft, adversary-in-the-middle phishing, OAuth consent abuse — with continuous access evaluation to revoke live sessions on risk.

  • Raise the bar on SaaS security posture (SSPM) — configurations held to clear benchmarks, and risky OAuth grants, over-permissioned or stale admins, shadow SaaS / AI, and config drift surfaced continuously — the technical lens on the portfolio the SaaS Enablement & Governance Lead holds the system of record for.

  • Own endpoint and device trust — an Apple-first fleet on MDM and EDR, with access gated on device health via zero-trust / conditional access, partnering with IT Systems and Workplace Technology, who run the fleet and network.

  • Own data-protection controls (DLP) across endpoint, SaaS, browser, and AI-egress, run access reviews, and surface insider-risk signals to Detection & Response for investigation with People and Legal.

  • Build controls and guardrails as code (Python + Terraform / IaC) so security scales, tracked against agent-identity and MFA coverage, risky OAuth grants closed, and mean time to remediate and revoke.

Who you are
  • 4+ years in corporate, enterprise, or IT security, with full ownership of security decisions and scope end to end.

  • A builder first — you write production-grade code (Python at least) and treat controls, automations, and detections as software you own, not tickets you close.

  • AI-first by conviction — you already reach for agents and LLMs (Claude Code and the like) to compress toil, and you have a clear view on where they’re trustworthy and where a human owns the call. Show us something you automated that used to eat your week.

  • Identity-, SaaS-, and AI-centric in how you think about security — the modern attack surface (identity as the new perimeter, the SaaS estate, endpoints, and the AI tools employees use), not network-perimeter or compliance-checklist.

  • Fluent with modern identity — an enterprise IdP (Okta and/or Microsoft Entra ID) and Google Workspace, SSO and SCIM lifecycle, phishing-resistant MFA, and the protocols underneath (SAML, OAuth 2.0, OIDC).

  • Energised by the threat model — you find it motivating, not daunting, that securing an AI company law firms trust with their most sensitive work means well-resourced adversaries and novel attack surface.

Nice to have
  • Securing AI systems — prompt-injection and exfiltration detection, agent / tool-use telemetry, and the OWASP LLM Top 10.

  • Identity threat detection (ITDR) and SaaS-identity tooling — Okta / Microsoft Entra ID Protection and e.g. Push Security.

  • Non-human identity and secrets — service-account governance, workload identity, and secrets management (e.g. 1Password, HashiCorp Vault).

  • Agent authorization — delegated authority and short-lived, narrowly-scoped tokens (OAuth token exchange / identity chaining), and MCP enterprise-managed authorization.

  • Endpoint at scale — Jamf (Apple) and Intune (Windows), with modern EDR.

  • Security automation and guardrails-as-code — deterministic workflows and SOAR (e.g. Tines, Torq).

  • DLP and insider-risk tooling — modern data-loss prevention and UEBA.

  • SOC 2 / ISO 27001 control implementation and compliance-as-code alongside engineering — GRC owns the certifications, you build and evidence the technical controls.

  • Experience with Okta, Microsoft Entra ID, 1Password, CrowdStrike, Jamf, Lumos, and our AI-native ITSM (Serval).

What’s In It For You
  • Global collaboration: Partner with teams and clients across Europe, APAC, and North America.

  • Competitive package: Comprehensive salary, benefits, and tools for success.

  • Meaningful work: Your efforts shape how thousands of lawyers use AI daily.

  • In-person environment: Union Square office designed for ambitious builders and company provided lunch daily.

  • Benefits & Perks: We invest in our people with a comprehensive, thoughtfully designed benefits package:
    Medical, Dental & Vision

    • Multiple medical plan options through Aetna and Kaiser Permanente

    • HSA or Healthcare FSA (based on plan selection)

    • Dental plans via MetLife

    • Vision plans via Vision Care

    Family Support

    • Generous parental leave

    • Free access to Maven Clinic

    • Dependent Care FSA

    • Free One Medical membership for employees and dependents

    Additional Perks

    • Pre-tax commuter benefits

    • Life Insurance + STD/LTD

    • 401(K) with generous company match

    • Unlimited PTO

    • Robust voluntary benefits, including identity protection (via Aura), legal coverage via MetLife, pet savings programs, and more

Legora is an Equal Opportunity Employer

At Legora, we believe great teams are built on diversity of thought and experience. We’re proud to be an equal opportunity employer and committed to creating an inclusive, high-performance culture where everyone can do their best work. We welcome people of all backgrounds and don’t discriminate based on race, color, religion, national origin, gender, gender identity or expression, sexual orientation, age, disability, veteran status, or any other characteristic protected by law.

Skills Required

  • 4+ years in corporate, enterprise, or IT security with end-to-end ownership of security decisions
  • Production-grade coding experience (Python at least) to build controls and automations
  • Experience with Infrastructure as Code and Terraform for building guardrails-as-code
  • Fluency with modern identity: Okta and/or Microsoft Entra ID, Google Workspace, SSO, SCIM lifecycle, phishing-resistant MFA (passkeys/FIDO2)
  • Practical knowledge of identity/security protocols: SAML, OAuth 2.0, OIDC and token/consent abuse mitigation
  • Experience securing endpoints and device trust (MDM, EDR, zero-trust/conditional access)
  • AI-first mindset: experience using/automating with LLMs and agents and governing their safe use
  • Experience securing AI systems (prompt-injection/exfiltration detection, agent telemetry, OWASP LLM considerations)
  • Identity threat detection (ITDR) and SaaS-identity tooling (Okta/Entra protections, Push Security)
  • Non-human identity and secrets management experience (service accounts, HashiCorp Vault, 1Password)
  • Agent authorization patterns (short-lived tokens, OAuth token exchange, delegated authority)
  • Experience with Jamf (Apple) and Intune (Windows) at scale and modern EDR tooling
  • Familiarity with SOAR/automation platforms and guardrails-as-code (Tines, Torq, deterministic workflows)
  • DLP and insider-risk tooling experience and familiarity with UEBA
  • Experience implementing technical controls for SOC 2 / ISO 27001 (compliance-as-code)
  • Familiarity with vendor tools listed (CrowdStrike, Lumos, Serval) and SaaS security posture management

Legora Compensation & Benefits Highlights

  • Healthcare Strength U.S. role descriptions outline comprehensive medical, dental, and vision coverage with HSA/FSA options, plus access to partners like One Medical and Maven. Similar wording across multiple postings indicates a standardized health offering.
  • Parental & Family Support Generous parental leave, Dependent Care FSA, and family health services (e.g., Maven) extend support to employees and dependents. These benefits are highlighted repeatedly in U.S. job materials.
  • Leave & Time Off Breadth Unlimited PTO is positioned as a core element of the package alongside paid sick days and holidays. Multiple postings present this consistently for U.S. roles.

Legora Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: New York, New York
700 Employees
Year Founded: 2023

What We Do

Our mission is to empower exceptional lawyers. We’re building the world’s first truly collaborative AI for legal professionals: a workspace for boundless collaboration between lawyer ingenuity and machine intelligence. We're serving 1000+ clients across the globe and are backed by Bessemer Venture Partners, ICONIQ, General Catalyst, Benchmark, Redpoint, Y Combinator, and other top investors.

Gallery

Gallery
Gallery
Gallery
Gallery

Legora Offices

OnSite Workspace

Typical time on-site:
HQNew York Headquarters
Chicago, Illinois
Denver, Colorado
Houston, Texas
London, England
San Francisco, California
Stockholm, Stockholms län
Learn more

Similar Jobs

Legora Logo Legora

GTM Solutions, Practice Lead

Artificial Intelligence • Legal Tech • Software
In-Office
New York City, NY, USA
700 Employees
175K-206K Annually

Legora Logo Legora

Director, Engagement - Enterprise, East

Artificial Intelligence • Legal Tech • Software
In-Office
New York City, NY, USA
700 Employees
260K-307K Annually

Legora Logo Legora

Director of GTM Systems & Architecture

Artificial Intelligence • Legal Tech • Software
In-Office
New York City, NY, USA
700 Employees
204K-300K Annually

Legora Logo Legora

Partner Manager, Cloud & AI Partnerships

Artificial Intelligence • Legal Tech • Software
In-Office
New York City, NY, USA
700 Employees
204K-240K Annually

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account