Corporate Security Engineer
New York City • FullTime
Posted 1mo ago
About the job
Legora is seeking a Corporate Security Engineer to own the security of the company's internal environment, including identities, devices, SaaS, and AI tools. This role is for a builder who treats security controls and automations as software they own. The ideal candidate will have an AI-first mindset, leveraging agents and LLMs to improve efficiency, and a deep understanding of modern attack surfaces like identity, SaaS, and AI tools. You will be responsible for securing Legora's AI-native workspace, ensuring the trust of legal professionals who rely on the platform for sensitive work.
Responsibilities
- Own and manage non-human identities, including service accounts, agents, and workloads, ensuring they are inventoried, scoped tightly, and use short-lived, secretless credentials.
- Define and implement authorization models for agents, ensuring they are scoped, revocable, auditable, and adhere to least-privilege principles.
- Govern employee use of LLMs and agents, ensuring client data remains on sanctioned paths and making secure AI adoption the fastest path.
- Advance identity security for people, implementing phishing-resistant MFA, SSO, SCIM lifecycle, and least-privilege access across various SaaS platforms.
- Enhance SaaS security posture management (SSPM) by establishing clear benchmarks, surfacing risky configurations, and managing the technical aspects of the SaaS portfolio.
- Own endpoint and device trust, implementing zero-trust/conditional access policies for an Apple-first fleet managed by MDM and EDR.
- Implement data protection controls (DLP) across endpoint, SaaS, browser, and AI-egress, and conduct access reviews.
- Build security controls and guardrails as code using Python and Terraform/IaC to ensure security scales effectively.
- Surface insider-risk signals to the Detection & Response team for investigation.
Requirements
- 4+ years of experience in corporate, enterprise, or IT security with full ownership of security decisions.
- Proven ability to write production-grade code, particularly in Python, and treat security controls as owned software.
- An AI-first mindset, with experience using agents and LLMs to automate tasks and a clear understanding of their trustworthiness.
- Expertise in modern security attack surfaces, including identity, SaaS, endpoints, and AI tools.
- Proficiency with enterprise identity providers (Okta and/or Microsoft Entra ID) and Google Workspace, including SSO, SCIM lifecycle, phishing-resistant MFA, SAML, OAuth 2.0, and OIDC.
- Comfort and motivation working with sophisticated threat models and well-resourced adversaries.