SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Legora is an AI-native legal workspace trusted by 1,000+ customers including major law firms and enterprises across 50+ countries. The company has scaled to $100M+ ARR and operates teams globally.
The Detection & Response Engineer role sits within IT and AI Enablement, which is building an AI-native Information Security function. You will own detection and response across Legora's corporate and production environments: endpoints, identity, cloud workloads, SaaS applications, and the AI systems and agents the company operates.
Key responsibilities include:
- Hunt, triage, investigate, and contain security incidents across all infrastructure layers, then drive them to resolution and convert learnings into better detections and controls.
- Build detections as production software using telemetry and pipelines provided by AI & Integrations Engineering, with version control, peer review, testing, and CI/CD deployment.
- Develop threat models, telemetry, and response playbooks specifically for AI systems, agents, and their tool use; detect misuse of agents operating company-wide.
- Build and supervise AI agents for triage, enrichment, and investigation, setting guardrails and approval thresholds for high-impact containment actions.
- Map detection coverage to MITRE ATT&CK framework and validate through threat hunting, penetration testing, and adversary emulation.
- Share on-call rotation and act as incident commander for security incidents; run post-incident reviews to reduce detection and containment time.
- Investigate insider risk and identity abuse in collaboration with Corporate Security, People, and Legal teams.
- Track actors and campaigns targeting AI companies, converting intelligence into hunts and detections; own the digital-risk platform and coordinate phishing/impersonation takedowns.
Required qualifications:
- 5+ years in detection engineering, incident response, or security operations, with experience as a senior escalation point.
- Strong software engineering skills in Python and SQL; ability to build detections, automations, and telemetry pipelines for production environments.
- Hands-on experience using LLMs and agents in security work, with judgment about when human decision-making is required.
- Fluency across endpoint, identity, cloud, and SaaS telemetry; ability to reason from attacker behavior and correlate signals across systems.
- Clear communication during incidents and ability to turn incomplete technical evidence into sound decisions.
Nice-to-have skills include experience with modern SIEMs or security data lakes, multiple query/rule languages (SPL, KQL, YARA-L, Sigma, SQL), securing AI systems and agent tool use, response automation, incident management, digital forensics, malware analysis, threat intelligence, insider risk, or DLP.
The role is based in Legora's Union Square office in New York City, designed for ambitious builders with company-provided lunch daily. The company offers competitive salary and benefits including medical/dental/vision, parental leave, 401(k) match, unlimited PTO, and global collaboration opportunities.