SlipstreamJobsFresh Startup & VC-Backed Jobs

Security Engineer

Legora - Stockholm, Sweden - In-office - posted 2026-08-21

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Legora is an AI-native legal workspace trusted by 1,000+ customers including top law firms (Cleary Gottlieb, Goodwin, Linklaters, White & Case) and major corporations. The company has scaled to $100M+ ARR with teams across Europe, North America, and APAC. As a Security Engineer, you will own security end-to-end across a multi-tenant AI platform and multi-cloud infrastructure (Azure primary). This is a hands-on engineering role where you build leverage across a large surface area: designing and shipping security tooling, embedding with engineering teams, and making the secure path the default. You will specialize in one of three areas while maintaining credibility across all: **Application Security**: Threat model features and architectures, review high-risk changes in authentication, authorization, tenant isolation, and data handling. Secure AI and agentic product features against prompt injection, tool-use abuse, and data exfiltration. **Detection Engineering & Response**: Own detection-as-code, security data pipelines, abuse and account-compromise detection, and incident response. Build agents for first-pass triage and investigation with trustworthy guardrails and evals. **Cloud & Platform Security**: Harden identity, access, cloud control planes, CI/CD, supply chain, infrastructure-as-code, AKS baselines, tenant isolation primitives, and least-privilege access for engineers, workloads, and AI agents. Key responsibilities include: owning security architecture and roadmap, working embedded with engineering teams on secure design and operations, building and shipping production-quality guardrails and automation (primarily TypeScript/Node.js and Python), raising the security bar through design reviews and threat modeling, securing multi-tenant AI platforms, responding to incidents, and writing post-mortems that drive meaningful improvements. You should bring several years of engineering experience in your security specialization with real depth in vulnerabilities found, incidents run, systems hardened, or tooling built. You understand identity, authorization, multi-tenancy, and where security boundaries break. You communicate clearly, translate risk into engineering terms, and influence teams without mandates. You are calm and structured under incident pressure. Nice-to-haves include experience securing LLM-based or agentic products, building security functions at high-growth SaaS companies, multi-tenant SaaS isolation models, environments with strict confidentiality or data residency requirements, and supply chain security depth (SLSA, artifact signing, SBOMs).

Similar roles