(Senior OR Staff) Detection & Response Engineer

New York City FullTime

Posted 5d ago

Job Location

New York City

Tech Stack

Remote Work Policy

On-site

Employment Type

FullTime

Categories

Applied AI Engineer

About the job

Legora is seeking a Senior or Staff Detection & Response Engineer to join our AI-native Information Security team. This role is critical in ensuring the security and reliability of Legora's corporate and production environments, including endpoints, identity, cloud workloads, SaaS, and our AI systems. You will be responsible for hunting, triaging, investigating, and resolving security incidents, and translating learnings into improved detections and controls. The ideal candidate will build detections as production software, develop threat models for AI systems, and supervise agents for automated triage and investigation. This position offers a unique opportunity to work at the forefront of AI security within a rapidly growing company trusted by over 1,000 customers worldwide.

Responsibilities

  • Own detection and response across endpoints, identity, cloud workloads, SaaS, and Legora's AI systems.
  • Hunt, triage, investigate, contain, and drive incidents through resolution, then use learnings to improve detections and controls.
  • Build detections as production software on telemetry and pipelines, ensuring version control, peer review, testing, and CI/CD deployment.
  • Measure detection coverage, precision, and time to detection, and tune as needed.
  • Build threat models, telemetry, and response playbooks for AI systems and agents.
  • Detect misuse of AI agents operating across the company.
  • Build and supervise agents for triage, enrichment, and investigation, setting guardrails for high-impact actions.
  • Map coverage to MITRE ATT&CK and validate through threat hunting and adversary emulation.
  • Share on-call rotation and act as incident commander.
  • Run post-incident reviews to reduce detection and containment time.
  • Investigate insider risk and identity abuse.
  • Track actors and campaigns targeting AI companies and convert intelligence into hunts and detections.
  • Own the digital-risk platform and coordinate urgent phishing and impersonation takedowns.

Requirements

  • 5+ years in detection engineering, incident response, or security operations (10+ years for Staff level, including strategy experience).
  • Strong software engineering skills in Python and SQL.
  • Experience building reliable production detections, automations, and telemetry pipelines.
  • Experience using LLMs and agents in security work and understanding human decision points.
  • Fluent across endpoint, identity, cloud, and SaaS telemetry.
  • Ability to reason from attacker behavior and correlate signals across systems.
  • Clear communication during incidents and ability to translate technical evidence into sound decisions.
  • Experience writing post-incident reviews that lead to concrete changes.

Benefits

  • Comprehensive salary
  • Medical, Dental & Vision insurance
  • HSA or Healthcare FSA
  • Generous parental leave
  • Free access to Maven Clinic
  • Dependent Care FSA
  • Free One Medical membership
  • Pre-tax commuter benefits
  • Life Insurance + STD/LTD
  • 401(K) with generous company match
  • Unlimited PTO
  • Company provided lunch daily

About Legora

Get new AI jobs in your inbox

A weekly digest of the newest AI engineering roles.

© 2026 AI Job Board. All rights reserved.