About the teamThe IT and AI Enablement function helps Legora run securely and reliably as we grow. We are building an AI-native Information Security function. We ship security controls as software, and agents handle first-pass triage and routine investigation. People make the high-impact calls.
This role owns detection and response across Legora's corporate and production environments: endpoints, identity, cloud workloads, SaaS, and the AI systems and agents we operate. Law firms trust Legora with sensitive work, so we expect capable, well-resourced attackers. Your job is to find and stop them.
What you'll be doing- Own detection and response across endpoints, identity, cloud workloads, SaaS, and Legora's AI systems. Hunt, triage, investigate, contain, and drive incidents through resolution, then turn what you learn into better detections and controls.
- Build detections as production software on telemetry and pipelines provided by AI & Integrations Engineering. Keep them version-controlled, peer-reviewed, tested, and deployed through CI/CD. Measure coverage, precision, and time to detection, then tune where the data shows a gap.
- Build threat models, telemetry, and response playbooks for our AI systems, agents, and their tool use. Detect misuse of agents operating across the company.
- Build and supervise agents for triage, enrichment, and investigation. Set guardrails and approval thresholds for containment and other high-impact actions.
- Map coverage to MITRE ATT&CK and validate it through threat hunting, penetration-test findings, and adversary emulation.
- Share the on-call rotation and act as incident commander when security is involved. Engineering owns service reliability; Customer Trust and Legal own customer communications. Run post-incident reviews and use the findings to reduce detection and containment time.
- Investigate insider risk and identity abuse with Corporate Security, People, and Legal. Work with Vulnerability Management on exposure priorities and IT Systems on the underlying estate.
- Track actors and campaigns targeting AI companies and convert the intelligence into hunts and detections. Own the digital-risk platform and coordinate urgent phishing and impersonation takedowns.
Who you are- 5+ years in detection engineering, incident response, or security operations, including work as a senior escalation point. For Staff, we expect roughly 10+ years and experience setting detection and response strategy.
- Strong software engineering skills in Python and SQL. You build detections, automations, and telemetry pipelines that run reliably in production.
- You use LLMs and agents in day-to-day security work and know which decisions require a human. Be ready to show us an investigation or workflow you automated.
- Fluent across endpoint, identity, cloud, and SaaS telemetry. You reason from attacker behaviour and correlate signals across systems.
- You communicate clearly during incidents and turn incomplete technical evidence into sound decisions. Your post-incident reviews lead to concrete changes.
Nice to have- Experience with a modern SIEM or security data lake and at least two relevant query or rule languages, such as SPL, KQL, YARA-L, Sigma, or SQL.
- Experience securing AI systems, agent tool use, and AI data flows, including prompt injection and exfiltration risks.
- Experience with response automation, incident management, digital forensics, or malware analysis.
- Threat intelligence, insider risk, or DLP experience.
What's In It For You- Global collaboration: Partner with teams and clients across Europe, APAC, and North America.
- Competitive package: Comprehensive salary, benefits, and tools for success.
- Meaningful work: Your efforts shape how thousands of lawyers use AI daily.
- In-person environment: Union Square office designed for ambitious builders and company provided lunch daily.
- Benefits & Perks: We invest in our people with a comprehensive, thoughtfully designed benefits package:
Medical, Dental & Vision
- Multiple medical plan options through Aetna and Kaiser Permanente
- HSA or Healthcare FSA (based on plan selection)
- Dental plans via MetLife
- Vision plans via Vision Care
Family Support
- Generous parental leave
- Free access to Maven Clinic
- Dependent Care FSA
- Free One Medical membership for employees and dependents
Additional Perks
- Pre-tax commuter benefits
- Life Insurance + STD/LTD
- 401(K) with generous company match
- Unlimited PTO
- Robust voluntary benefits, including identity protection (via Aura), legal coverage via MetLife, pet savings programs, and more