Corporate Security Engineer
Legora
| Company | Legora |
| Category | Engineering |
| Location | New York City |
| Remote | On-site (inferred) |
| Employment | Not stated |
| Level | Not stated |
| Salary | USD 188k–221k |
| Posted | 25 Jul 2026 |
| Last verified | 30 Jul 2026 |
| Source | Employer career page (ashby) |
Description
ABOUT US
Legora is redefining how legal work gets done. Not built for lawyers, built with them. We work alongside the world’s best legal teams, who expect excellence, precision, and speed, and we hold ourselves to the same bar.
Our AI-native workspace lets legal professionals move faster, think more clearly, and operate with sharper precision. By analysing thousands of documents in minutes and powering end-to-end workflows, we cut through complexity, teams can focus on what matters: judgment, strategy, and outcomes.
1,000+ customers across 50+ countries trust us, including Cleary Gottlieb, Goodwin, Linklaters, White & Case, Dentons, and Barclays. We’ve scaled to $100M+ in ARR, with teams across Europe, North America and APAC, and continue to expand through acquisitions including Qura, Walter AI and Graceview.
We partner with world-class performers: including Aaron Judge and the New York Yankees, Ludvig Åberg (and his caddie), and campaigns featuring Jude Law.
Joining Legora means three things.
- We lean in: ownership over titles, outcomes over intentions.
- We fight for excellence: high standards, direct, ego-free feedback.
- We grow together: as a team and with our customers.
Mission before ego. Everyone contributes. No one coasts.
If you’re driven by impact, pace, and raising the bar. This is the place.
ABOUT THE TEAM
The IT and AI Enablement function exists to make Legora itself run as well as the product we sell: secure, automated, and compounding over time. Legora builds AI that law firms trust with their most sensitive work, which makes us a target for capable, well-resourced adversaries. Information Security keeps that trust intact, builders-first and AI-first: we ship controls as software and let agents take the first pass, so the human work is the judgment layer. We are not looking for someone to administer consoles and work a compliance checklist. The Corporate Security Engineer owns the security of Legora’s own environment — the identities, devices, SaaS, and AI tools every employee depends on — the operating root of trust the rest of the company connects through.
WHAT YOU’LL BE DOING
- Own non-human identity — the service accounts, agents, and workloads that scale faster than headcount. Keep them inventoried and owned, scoped tightly, running on short-lived and secretless credentials, with a path to revoke at scale.
- Set the authorization model for agents — scoped, revocable, and auditable: least-privilege at each MCP call, no token passthrough, and delegated authority rather than standing access.
- Secure how Legora uses AI — govern employee use of LLMs and agents, keep client data on sanctioned paths, and make the safe path the fast one as teams adopt AI.
- Advance identity for people — phishing-resistant MFA (passkeys / FIDO2), SSO, SCIM lifecycle, and least-privilege / just-in-time access across Google Workspace, Slack, Notion, and the SaaS estate — and cover the attack classes that defeat MFA alone — session / token theft, adversary-in-the-middle phishing, OAuth consent abuse — with continuous access evaluation to revoke live sessions on risk.
- Raise the bar on SaaS security posture (SSPM) — configurations held to clear benchmarks, and risky OAuth grants, over-permissioned or stale admins, shadow SaaS / AI, and config drift surfaced continuously — the technical lens on the portfolio the SaaS Enablement & Governance Lead holds the system of record for.
- Own endpoint and device trust — an Apple-first fleet on MDM and EDR, with access gated on device health via zero-trust / conditional access, partnering with IT Systems and Workplace Technology, who run the fleet and network.
- Own data-protection controls (DLP) across endpoint, SaaS, browser, and AI-egress, run access reviews, and surface insider-risk signals to Detection & Response for investigation with People and Legal.
- Build controls and guardrails as code (Python + Terraform / IaC)
995,367 openings. Erioun finds yours.Scored against your own profile, every hour.Try the radar →