Lead the security engineering function at Legora, ensuring the safety of sensitive legal data for top law firms and corporations.
Posted by employer 1 day ago
First seen on Joblaze 4 hours ago
Last verified on the company career page 4 hours ago
Skills & Technologies
What you'll build
Must have
Nice to have
Practical constraints
Not disclosed in this posting: compensation, years of experience, visa sponsorship.
Joblaze summary
The Director of Security Engineering at Legora is responsible for establishing and leading the security strategy across the company's product and cloud infrastructure, focusing on proactive risk management and automation. This role requires a strong engineering background, with expertise in application security, detection engineering, and cloud security, to effectively influence technical direction and embed security practices into the software lifecycle. Ideal candidates will have experience scaling security functions in high-growth environments and will be comfortable collaborating with engineering leadership to address systemic security challenges.
Joblaze insights
Quick facts
From the original posting
We lean in: ownership over titles, outcomes over intentions.
The role
At Legora, security is the foundation of the trust our customers place in us. The world's leading law firms and largest corporations use our platform for their most sensitive matters. The risk of breach is very high, and we treat it that way.
We are building an engineering-led security function: secure defaults, paved roads, automation, and measurable risk reduction not advisory gates or ticket queues.
We need a Director of Security Engineering to set the direction for security across our product, platform, and cloud estate; build and lead the team; and tackle systemic problems rather than continually react to individual ones. You will work closely with engineering leadership to anticipate challenges, influence architecture and priorities, and make blockers and consequences clear.
This role can be based in Stockholm or New York. It is a 5-day in-office role we believe building together in person drives better outcomes.
What you will be doing
Security strategy and architecture
Define the security standard across Legora's product, platform, and customer commitments.
Set the roadmap and investment priorities, looking ahead and identifying emerging risks and blockers early.
Partner with the CTO and engineering leadership on architecture and technical direction.
Engineering enablement
Build tools, paved paths, and secure defaults that help teams ship securely without friction.
Embed security into the software lifecycle through reviews, standards, and automation.
Drive areas such as secrets management, workload identity, and Kubernetes hardening through infrastructure as code.
Detection, response and agentic security
Build automated detection and response, supported by specialist penetration testing.
Own incident playbooks, exercises, and investigations.
Threat-model our multi-tenant AI platform and define safe boundaries for coding agents.
Team and enterprise readiness
Hire and develop senior security engineers across Application Security, Detection Engineering & Response, and Cloud & Platform Security.
Give the team the direction and focus to solve underlying problem themes, not just individual findings.
Support enterprise customers through security conversations, questionnaires, and evidence of our practices.
Who you are
You have led and scaled a security engineering function through rapid product and team growth, ideally in an environment facing real threats.
You have an engineering background rather than a purely corporate infosec or compliance background.
You have strong architectural judgement and experience influencing technical direction at scale.
You understand application security, detection engineering, and cloud and platform security, and how they fit together.
You can operate as a peer to the engineering leadership, bringing security onto the agenda and making consequences and urgency clear.
You communicate clearly, translate risk into engineering terms, and influence without relying on mandates.
Nice to have
Experience securing LLM-based or agentic products.
Experience building security at a high-growth SaaS company.
Depth in more than one security specialisation.
Experience with strict data confidentiality, data residency, or professional secrecy requirements.
Experience representing security externally with enterprise customers, through research, or speaking.
If you are close but not a perfect match, apply anyway and tell us what you would own.
Standard company text repeated across Legora's postings is omitted here.
Explore more