M&A Security Lead

Legora

$130K — $180K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 7+ years in security engineering, security architecture, or technical program management with M&A focus
  • Fluency in identity and access management, cloud infrastructure, corporate IT, vulnerability management, and compliance frameworks
  • Ability to interpret technical risk and communicate it in business terms
  • Strong program management skills with ability to handle concurrent workstreams
  • Sound judgment on integration sequencing with a focus on discretion
  • Experience in building M&A security functions or playbooks (preferable)

Responsibilities

  • Own security due diligence for prospective transactions, assessing target security posture and compliance exposure
  • Define Day-1 security posture and access decisions to protect Legora
  • Lead integration of acquired products onto Legora's security baseline
  • Develop and maintain the security chapter of Legora's integration playbook
  • Manage security posture of acquired estates until full integration
  • Ensure compliance scope as systems transition into audit boundaries
  • Report security integration status to executive stakeholders

Benefits

  • Global collaboration with teams across multiple continents
  • Comprehensive salary and benefits package
  • Opportunity to influence AI use in legal processes
  • In-person work environment in Union Square with daily company lunch
  • Medical, dental, and vision plan options
  • Generous parental leave and dependent care support
  • 401(K) plan with company match and unlimited PTO
  • Various voluntary benefits including legal and identity protection
Full Job Description
The Role

Acquisitions are a core part of how Legora grows, and we hold everything we acquire to the same security bar our customers hold us to. As our deal cadence accelerates, we're adding dedicated security depth to our M&A and integration program: a specialist to own the security work-stream of every transaction, from pre-LOI diligence through Day-1 decisions to full integration onto Legora's security baseline.

Deals are the bursty half of this job. The durable half is the estates they leave behind: every acquired company runs as its own operating environment, its own identity, endpoints, vendors, and SDLC, until it is properly integrated or decommissioned, and you own the security posture of that portfolio for as long as it exists. Integration debt is your backlog, and clearing it is the job.

You'll sit within our Security organization and partner daily with Corporate Development and our Post-Merger Integration team, operating with real authority: you own security decisions within the integration program, with defined milestones and exit criteria for every deal. As integrations complete, the role's center of gravity shifts toward Legora's broader security architecture, the mandate grows out of the backlog you clear.

What You'll Do
  • Own security due diligence for prospective transactions: assess target security posture, architecture, data handling, compliance exposure, and breach history, and translate findings into deal terms, valuation input, and integration conditions
  • Define and enforce Day-1 security posture for each transaction, connectivity, identity, and access decisions that protect Legora and its customers while the business integrates
  • Lead each acquired product and team through a structured, time-boxed integration onto Legora's security baseline: identity and SSO, endpoint, logging and detection, vendor consolidation, and secure SDLC
  • Own the security chapter of Legora's integration playbook, partnering with our Post-Merger Integration team so security milestones are built into every deal plan from day one
  • Own the security posture of acquired, not-yet-integrated estates as operating environments: minimum control requirements, risk-based exceptions and interim safeguards, TSA-period security, and monitoring against Legora's enterprise risk profile until each estate is integrated or decommissioned
  • Manage compliance scope as acquired systems enter our SOC 2 / ISO and customer-audit boundary, and uphold our customer data commitments across every product we bring into the portfolio
  • Work cross-functionally with Corporate Development, Post-Merger Integration, Engineering, Legal, IT, and Product leadership, and report security integration status and risk posture to executive stakeholders

What You Bring
  • 7+ years in security engineering, security architecture, or technical program management, including direct experience with M&A security diligence and/or post-acquisition integration
  • Fluency across the domains integration touches: identity and access management, cloud infrastructure (AWS/GCP/Azure), corporate IT, vulnerability management, and compliance frameworks (SOC 2, ISO 27001)
  • Ability to read a pentest report and a deal schedule with equal comfort, you translate technical risk into business terms for executives and deal teams
  • A program-management mindset: you run multiple concurrent workstreams to defined milestones and hold teams to exit criteria
  • Sound judgment on sequencing, you know when to contain, when to bridge, and when to fully integrate, and you can defend those calls
  • Discretion. You'll operate on pre-announcement transactions and hold material non-public information

Nice to have
  • Experience building an M&A security function or playbook from scratch at an acquisitive technology company
  • Background in B2B SaaS serving regulated or highly security-conscious customers (legal, financial services, healthcare)
  • Exposure to transaction mechanics: reps and warranties, escrow and remediation covenants, TSAs

What's In It For You
  • Global collaboration: Partner with teams and clients across Europe, APAC, and North America.
  • Competitive package: Comprehensive salary, benefits, and tools for success.
  • Meaningful work: Your efforts shape how thousands of lawyers use AI daily.
  • In-person environment: Union Square office designed for ambitious builders and company provided lunch daily.
  • Benefits & Perks: We invest in our people with a comprehensive, thoughtfully designed benefits package:
    Medical, Dental & Vision
    • Multiple medical plan options through Aetna and Kaiser Permanente
    • HSA or Healthcare FSA (based on plan selection)
    • Dental plans via MetLife
    • Vision plans via Vision Care

    Family Support
    • Generous parental leave
    • Free access to Maven Clinic
    • Dependent Care FSA
    • Free One Medical membership for employees and dependents

    Additional Perks
    • Pre-tax commuter benefits
    • Life Insurance + STD/LTD
    • 401(K) with generous company match
    • Unlimited PTO
    • Robust voluntary benefits, including identity protection (via Aura), legal coverage via MetLife, pet savings programs, and more

Similar Jobs

More Jobs at Legora

More Information Technology Jobs

Find similar M&A Security Lead jobs: