SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Legora is an AI-native legal workspace trusted by 1,000+ customers including major law firms and enterprises across 50+ countries. The company has scaled to $100M+ ARR and operates globally with teams across Europe, North America, and APAC.
As Corporate Security Engineer, you will own the security of Legora's internal environment—the identities, devices, SaaS applications, and AI tools that every employee depends on. This is a hands-on engineering role focused on building security controls as production-grade software rather than administering compliance checklists.
Key responsibilities include:
- Non-human identity governance: inventory and secure service accounts, agents, and workloads with short-lived, secretless credentials and revocation at scale.
- Agent authorization: design scoped, revocable, auditable authorization models with least-privilege access and delegated authority rather than standing access.
- AI security governance: govern employee LLM and agent use, keep client data on sanctioned paths, and make secure practices the fast path for adoption.
- Identity for employees: implement phishing-resistant MFA (passkeys/FIDO2), SSO, SCIM lifecycle, and just-in-time access across Google Workspace, Slack, Notion, and the SaaS estate. Address attack classes beyond MFA alone including session theft, adversary-in-the-middle phishing, and OAuth consent abuse via continuous access evaluation.
- SaaS security posture (SSPM): maintain configurations to clear benchmarks, surface risky OAuth grants, over-permissioned admins, shadow SaaS/AI, and config drift continuously.
- Endpoint and device trust: own Apple-first MDM/EDR fleet with zero-trust conditional access gating, partnering with IT Systems and Workplace Technology.
- Data protection controls (DLP): implement and own DLP across endpoint, SaaS, browser, and AI-egress; run access reviews and surface insider-risk signals.
- Security automation: build controls, guardrails, and detections as code (Python + Terraform/IaC) tracked against coverage metrics and mean time to remediate.
You bring 4+ years in corporate, enterprise, or IT security with full ownership of security decisions end-to-end. You are a builder first—writing production-grade Python code and treating controls as software you own. You are AI-first by conviction, already using agents and LLMs to compress toil with clear judgment on trustworthiness. You think identity-, SaaS-, and AI-centric about security (the modern attack surface), not network-perimeter or compliance-checklist. You are fluent with modern identity platforms (Okta and/or Microsoft Entra ID), Google Workspace, SSO, SCIM, phishing-resistant MFA, and underlying protocols (SAML, OAuth 2.0, OIDC). You find the threat model motivating: securing an AI company law firms trust with sensitive work means well-resourced adversaries and novel attack surface.
Nice-to-have skills include securing AI systems (prompt-injection detection, agent telemetry, OWASP LLM Top 10), identity threat detection (ITDR) and SaaS-identity tooling, non-human identity and secrets management, agent authorization and MCP, endpoint management at scale (Jamf, Intune, modern EDR), and security automation.