← Back to results

Security Engineer

Join Legora as a Security Engineer to enhance security across a multi-tenant AI platform in a hands-on role.

Location
Stockholm HQ
Compensation
Not disclosed
Level
senior
Type
full time · On-site

Posted by employer 3 weeks ago

First seen on Joblaze 1 week ago

Last verified on the company career page 1 day ago

Apply at Legora → Save job Scanned from legora.com

Skills & Technologies

Role intensity

70% hands-on coding

AI in the day-to-day

Build with LLMs and agents, and help secure code and workflows produced at agent speed.

Requirements

Experience
5+ years

Not disclosed in this posting: compensation, visa sponsorship.

Joblaze summary

In this role, the Security Engineer at Legora is responsible for overseeing security processes across a multi-tenant AI platform, ensuring that security is integrated into every aspect of design and operations. The position requires expertise in areas such as Application Security, Detection Engineering, or Cloud Security, with a strong emphasis on hands-on coding and tooling development in languages like TypeScript and Python. Ideal candidates will have several years of experience in security engineering and a collaborative mindset, thriving in a fast-paced environment where they can influence engineering practices. Legora's commitment to excellence and teamwork creates a dynamic atmosphere

Joblaze insights

Quick facts

Is the Security Engineer role remote?
No — this is an on-site role in Stockholm HQ.
How much experience is required?
At least 5 years of relevant experience for this Security Engineer role.
Where is the role based?
Legora is hiring for this position in Stockholm HQ.
What's the tech stack?
Joblaze extracted these technologies from the posting: Node.js, Python, TypeScript.
What seniority level is this role?
Legora targets senior candidates for this position.
Is this full-time or contract?
Full-time for this Security Engineer role at Legora.

From the original posting

About Us

Legora is redefining how legal work gets done. Not built for lawyers, built with them. We work alongside the world’s best legal teams, who expect excellence, precision, and speed, and we hold ourselves to the same bar.

Our AI-native workspace lets legal professionals move faster, think more clearly, and operate with sharper precision. By analysing thousands of documents in minutes and powering end-to-end workflows, we cut through complexity, teams can focus on what matters: judgment, strategy, and outcomes.

1,000+ customers across 50+ countries trust us, including Cleary Gottlieb, Goodwin, Linklaters, White & Case, Dentons, and Barclays. We’ve scaled to $100M+ in ARR, with teams across Europe, North America and APAC, and continue to expand through acquisitions including Qura, Walter AI and Graceview.

We partner with world-class performers: including Aaron Judge and the New York Yankees, Ludvig Åberg (and his caddie), and campaigns featuring Jude Law.

Joining Legora means three things.

  • We lean in: ownership over titles, outcomes over intentions.

  • We fight for excellence: high standards, direct, ego-free feedback.

  • We grow together: as a team and with our customers.

Mission before ego. Everyone contributes. No one coasts.

If you’re driven by impact, pace, and raising the bar. This is the place.

The role:

At Legora, security is the foundation of the trust our customers place in us. The world’s leading law firms, as well as some of the biggest corporations use our platform for their most sensitive matters, and we need security to be built into how we design, ship, operate, and scale.

We are looking for exceptional Security Engineers who can build leverage across a large surface area: a multi-tenant AI platform, a multi-cloud estate with Azure as our primary cloud, and an engineering organisation that ships fast. This is a hands-on engineering role. You will own security work end to end, build tooling and guardrails, embed with engineering teams, and make the secure path the default path.

We hire T-shaped security engineers. You should bring real depth in one of Application Security, Detection Engineering & Response, or Cloud & Platform Security, while staying credible across the others. Tell us in your application which area is your specialisation.

This role can be based in Stockholm or New York. It is a 5-day in-office role, we believe building together in person drives better outcomes.

What you will be doing:

  • Own security work end to end: architecture, tooling, roadmap, and outcomes.

  • Work embedded with engineering teams to make secure design, development, and operations the default.

  • Build and ship software: guardrails, detections, libraries, automation, and workflows that live in git, are reviewed, tested, and deployed through CI/CD.

  • Raise the security bar across engineering through design reviews, threat modelling, tooling, and enablement.

  • Fix the class of bug, not just the instance, by turning findings into patterns, defaults, or detections.

  • Secure a multi-tenant AI platform, including identity, authorisation, tenant isolation, data handling, and model-facing attack surfaces.

  • Build with LLMs and agents, and help secure code and workflows produced at agent speed.

  • Respond to incidents and write post-mortems that lead to meaningful technical and organisational improvements.

Your specialisation:

  • Application Security: Threat model features and architectures, review high-risk changes across authentication, authorisation, tenant isolation, and data handling, and secure AI and agentic product features against prompt injection, tool-use abuse, data exfiltration, and related attack paths.

  • Detection Engineering & Response: Own detection-as-code, security data pipelines, abuse and account-compromise detection, and incident response across corporate and product surfaces. Build the agents that run first-pass triage and investigation, plus the guardrails and evals that make their output trustworthy. No tiered queue.

  • Cloud & Platform Security: Harden identity, access, cloud control planes, CI/CD, supply chain, infrastructure-as-code, AKS baselines, tenant isolation primitives, and least-privilege access for engineers, workloads, and AI agents.

Who you are:

  • Several years of engineering experience in your security specialisation, with real depth in vulnerabilities you have found, incidents you have run, systems you have hardened, or tooling you have built.

  • You are an engineer who writes production-quality code; we work primarily in TypeScript/Node.js and Python.

  • You are comfortable operating across application security, detection and response, and cloud/platform security, even if one of those areas is your main depth.

  • You understand identity, authorisation, multi-tenancy, and where security boundaries tend to break.

  • You communicate clearly, translate risk into engineering terms, and influence teams without relying on mandates.

  • You are calm and structured under incident pressure, and honest afterwards.

  • You are excited by a small team with a large surface area, where the right answer is usually to build leverage rather than create queues.

Nice to have:

  • Experience securing LLM-based or agentic products.

  • Experience building a security function at a high-growth SaaS company.

  • Familiarity with multi-tenant SaaS isolation models.

  • Experience in environments with strict confidentiality, data residency, or professional secrecy requirements.

  • Supply chain security depth, such as SLSA, artifact signing, or SBOMs.

If you are close but not a perfect match on the list, apply anyway and tell us what you would own.

Legora is an Equal Opportunity Employer

At Legora, we believe great teams are built on diversity of thought and experience. We’re proud to be an equal opportunity employer and committed to creating an inclusive, high-performance culture where everyone can do their best work. We welcome people of all backgrounds and don’t discriminate based on race, color, religion, national origin, gender, gender identity or expression, sexual orientation, age, disability, veteran status, or any other characteristic protected by law.

Similar positions

Legora
Corporate Security Engineer
Legora · New York City
Legora
Software Engineer
Legora · Stockholm HQ
Legora
GRC Engineer
Legora · New York City
Legora
GRC Lead
Legora · New York City
GitLab
Staff Corporate Security Engineer
GitLab · Remote, Canada; Remote, United States