Corporate Security Engineer

LegoraNew York, NY
$232,000 - $273,000Onsite

About The Position

The IT and AI Enablement function exists to make Legora itself run as well as the product we sell: secure, automated, and compounding over time. Legora builds AI that law firms trust with their most sensitive work, which makes us a target for capable, well-resourced adversaries. Information Security keeps that trust intact, builders-first and AI-first: we ship controls as software and let agents take the first pass, so the human work is the judgment layer. We are not looking for someone to administer consoles and work a compliance checklist. The Corporate Security Engineer owns the security of Legora’s own environment — the identities, devices, SaaS, and AI tools every employee depends on — the operating root of trust the rest of the company connects through.

Requirements

  • 4+ years in corporate, enterprise, or IT security, with full ownership of security decisions and scope end to end.
  • A builder first — you write production-grade code (Python at least) and treat controls, automations, and detections as software you own, not tickets you close.
  • AI-first by conviction — you already reach for agents and LLMs (Claude Code and the like) to compress toil, and you have a clear view on where they’re trustworthy and where a human owns the call. Show us something you automated that used to eat your week.
  • Identity-, SaaS-, and AI-centric in how you think about security — the modern attack surface (identity as the new perimeter, the SaaS estate, endpoints, and the AI tools employees use), not network-perimeter or compliance-checklist.
  • Fluent with modern identity — an enterprise IdP (Okta and/or Microsoft Entra ID) and Google Workspace, SSO and SCIM lifecycle, phishing-resistant MFA, and the protocols underneath (SAML, OAuth 2.0, OIDC).
  • Energised by the threat model — you find it motivating, not daunting, that securing an AI company law firms trust with their most sensitive work means well-resourced adversaries and novel attack surface.

Nice To Haves

  • Securing AI systems — prompt-injection and exfiltration detection, agent / tool-use telemetry, and the OWASP LLM Top 10.
  • Identity threat detection (ITDR) and SaaS-identity tooling — Okta / Microsoft Entra ID Protection and e.g. Push Security.
  • Non-human identity and secrets — service-account governance, workload identity, and secrets management (e.g. 1Password, HashiCorp Vault).
  • Agent authorization — delegated authority and short-lived, narrowly-scoped tokens (OAuth token exchange / identity chaining), and MCP enterprise-managed authorization.
  • Endpoint at scale — Jamf (Apple) and Intune (Windows), with modern EDR.
  • Security automation and guardrails-as-code — deterministic workflows and SOAR (e.g. Tines, Torq).
  • DLP and insider-risk tooling — modern data-loss prevention and UEBA.
  • SOC 2 / ISO 27001 control implementation and compliance-as-code alongside engineering — GRC owns the certifications, you build and evidence the technical controls.
  • Experience with Okta, Microsoft Entra ID, 1Password, CrowdStrike, Jamf, Lumos, and our AI-native ITSM (Serval).

Responsibilities

  • Own non-human identity — the service accounts, agents, and workloads that scale faster than headcount. Keep them inventoried and owned, scoped tightly, running on short-lived and secretless credentials, with a path to revoke at scale.
  • Set the authorization model for agents — scoped, revocable, and auditable: least-privilege at each MCP call, no token passthrough, and delegated authority rather than standing access.
  • Secure how Legora uses AI — govern employee use of LLMs and agents, keep client data on sanctioned paths, and make the safe path the fast one as teams adopt AI.
  • Advance identity for people — phishing-resistant MFA (passkeys / FIDO2), SSO, SCIM lifecycle, and least-privilege / just-in-time access across Google Workspace, Slack, Notion, and the SaaS estate — and cover the attack classes that defeat MFA alone — session / token theft, adversary-in-the-middle phishing, OAuth consent abuse — with continuous access evaluation to revoke live sessions on risk.
  • Raise the bar on SaaS security posture (SSPM) — configurations held to clear benchmarks, and risky OAuth grants, over-permissioned or stale admins, shadow SaaS / AI, and config drift surfaced continuously — the technical lens on the portfolio the SaaS Enablement & Governance Lead holds the system of record for.
  • Own endpoint and device trust — an Apple-first fleet on MDM and EDR, with access gated on device health via zero-trust / conditional access, partnering with IT Systems and Workplace Technology, who run the fleet and network.
  • Own data-protection controls (DLP) across endpoint, SaaS, browser, and AI-egress, run access reviews, and surface insider-risk signals to Detection & Response for investigation with People and Legal.
  • Build controls and guardrails as code (Python + Terraform / IaC) so security scales, tracked against agent-identity and MFA coverage, risky OAuth grants closed, and mean time to remediate and revoke.

Benefits

  • Medical, Dental & Vision
  • Multiple medical plan options through Aetna and Kaiser Permanente
  • HSA or Healthcare FSA (based on plan selection)
  • Dental plans via MetLife
  • Vision plans via Vision Care
  • Generous parental leave
  • Free access to Maven Clinic
  • Dependent Care FSA
  • Free One Medical membership for employees and dependents
  • Pre-tax commuter benefits
  • Life Insurance + STD/LTD
  • 401(K) with generous company match
  • Unlimited PTO
  • Robust voluntary benefits, including identity protection (via Aura), legal coverage via MetLife, pet savings programs, and more
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service