← Back to results

(Senior OR Staff) Detection & Response Engineer

Own detection and response across Legora's environments, utilizing strong software engineering skills and threat intelligence.

Location
New York City, United States
Compensation
Not disclosed
Level
senior
Type
full time

Posted by employer 3 days ago

First seen on Joblaze 1 day ago

Last verified on the company career page 1 day ago

Apply at Legora → Save job Scanned from legora.com

Skills & Technologies

What you'll build

  • Own detection and response across endpoints, identity, cloud workloads, SaaS, and AI systems
  • Build detections as production software
  • Map coverage to MITRE ATT&CK
  • Investigate insider risk and identity abuse
  • Track actors and campaigns targeting AI companies

Must have

  • 5+ years in detection engineering, incident response, or security operations
  • Strong software engineering skills in Python and SQL
  • Fluent across endpoint, identity, cloud, and SaaS telemetry

Nice to have

  • Experience with a modern SIEM or security data lake
  • Experience securing AI systems
  • Experience with response automation
  • Threat intelligence experience

AI in the day-to-day

You use LLMs and agents in day-to-day security work.

Requirements

Experience
5–10 years

Not disclosed in this posting: compensation, work arrangement, visa sponsorship.

Benefits

401k Match Unlimited PTO Health Insurance Parental Leave

Joblaze summary

The Detection & Response Engineer at Legora is responsible for managing security across various environments, including endpoints and cloud workloads, while actively hunting and resolving incidents. This role requires strong software engineering skills, particularly in Python and SQL, to build effective detection systems and automate workflows. Ideal candidates have over five years of experience in security operations, with a focus on detection engineering and incident response, and are comfortable working with AI systems. Legora emphasizes a collaborative culture, where team members are expected to contribute to high standards and continuous improvement.

Joblaze insights

Quick facts

How much experience is required?
5–10 years of relevant experience for this (Senior OR Staff) Detection & Response Engineer role.
What's the tech stack?
Joblaze extracted these technologies from the posting: MITRE ATT&CK, Python, SIEM, SQL, Sigma, YARA-L.
What seniority level is this role?
Legora targets senior candidates for this position.
Is this full-time or contract?
Full-time for this (Senior OR Staff) Detection & Response Engineer role at Legora.

From the original posting

About Us

Legora is redefining how legal work gets done. Not built for lawyers, built with them. We work alongside the world’s best legal teams, who expect excellence, precision, and speed, and we hold ourselves to the same bar.

Our AI-native workspace lets legal professionals move faster, think more clearly, and operate with sharper precision. By analysing thousands of documents in minutes and powering end-to-end workflows, we cut through complexity, teams can focus on what matters: judgment, strategy, and outcomes.

1,000+ customers across 50+ countries trust us, including Cleary Gottlieb, Goodwin, Linklaters, White & Case, Dentons, and Barclays. We’ve scaled to $100M+ in ARR, with teams across Europe, North America and APAC, and continue to expand through acquisitions including Qura, Walter AI and Graceview.

We partner with world-class performers: including Aaron Judge and the New York Yankees, Ludvig Åberg (and his caddie), and campaigns featuring Jude Law.

Joining Legora means three things.

  • We lean in: ownership over titles, outcomes over intentions.

  • We fight for excellence: high standards, direct, ego-free feedback.

  • We grow together: as a team and with our customers.

Mission before ego. Everyone contributes. No one coasts.

If you’re driven by impact, pace, and raising the bar. This is the place.

About the team

The IT and AI Enablement function helps Legora run securely and reliably as we grow. We are building an AI-native Information Security function. We ship security controls as software, and agents handle first-pass triage and routine investigation. People make the high-impact calls.

This role owns detection and response across Legora's corporate and production environments: endpoints, identity, cloud workloads, SaaS, and the AI systems and agents we operate. Law firms trust Legora with sensitive work, so we expect capable, well-resourced attackers. Your job is to find and stop them.

What you’ll be doing

  • Own detection and response across endpoints, identity, cloud workloads, SaaS, and Legora's AI systems. Hunt, triage, investigate, contain, and drive incidents through resolution, then turn what you learn into better detections and controls.

  • Build detections as production software on telemetry and pipelines provided by AI & Integrations Engineering. Keep them version-controlled, peer-reviewed, tested, and deployed through CI/CD. Measure coverage, precision, and time to detection, then tune where the data shows a gap.

  • Build threat models, telemetry, and response playbooks for our AI systems, agents, and their tool use. Detect misuse of agents operating across the company.

  • Build and supervise agents for triage, enrichment, and investigation. Set guardrails and approval thresholds for containment and other high-impact actions.

  • Map coverage to MITRE ATT&CK and validate it through threat hunting, penetration-test findings, and adversary emulation.

  • Share the on-call rotation and act as incident commander when security is involved. Engineering owns service reliability; Customer Trust and Legal own customer communications. Run post-incident reviews and use the findings to reduce detection and containment time.

  • Investigate insider risk and identity abuse with Corporate Security, People, and Legal. Work with Vulnerability Management on exposure priorities and IT Systems on the underlying estate.

  • Track actors and campaigns targeting AI companies and convert the intelligence into hunts and detections. Own the digital-risk platform and coordinate urgent phishing and impersonation takedowns.

Who you are

  • 5+ years in detection engineering, incident response, or security operations, including work as a senior escalation point. For Staff, we expect roughly 10+ years and experience setting detection and response strategy.

  • Strong software engineering skills in Python and SQL. You build detections, automations, and telemetry pipelines that run reliably in production.

  • You use LLMs and agents in day-to-day security work and know which decisions require a human. Be ready to show us an investigation or workflow you automated.

  • Fluent across endpoint, identity, cloud, and SaaS telemetry. You reason from attacker behaviour and correlate signals across systems.

  • You communicate clearly during incidents and turn incomplete technical evidence into sound decisions. Your post-incident reviews lead to concrete changes.

Nice to have

  • Experience with a modern SIEM or security data lake and at least two relevant query or rule languages, such as SPL, KQL, YARA-L, Sigma, or SQL.

  • Experience securing AI systems, agent tool use, and AI data flows, including prompt injection and exfiltration risks.

  • Experience with response automation, incident management, digital forensics, or malware analysis.

  • Threat intelligence, insider risk, or DLP experience.

What’s In It For You

  • Global collaboration: Partner with teams and clients across Europe, APAC, and North America.

  • Competitive package: Comprehensive salary, benefits, and tools for success.

  • Meaningful work: Your efforts shape how thousands of lawyers use AI daily.

  • In-person environment: Union Square office designed for ambitious builders and company provided lunch daily.

  • Benefits & Perks: We invest in our people with a comprehensive, thoughtfully designed benefits package:
    Medical, Dental & Vision

    • Multiple medical plan options through Aetna and Kaiser Permanente

    • HSA or Healthcare FSA (based on plan selection)

    • Dental plans via MetLife

    • Vision plans via Vision Care

    Family Support

    • Generous parental leave

    • Free access to Maven Clinic

    • Dependent Care FSA

    • Free One Medical membership for employees and dependents

    Additional Perks

    • Pre-tax commuter benefits

    • Life Insurance + STD/LTD

    • 401(K) with generous company match

    • Unlimited PTO

    • Robust voluntary benefits, including identity protection (via Aura), legal coverage via MetLife, pet savings programs, and more

Legora is an Equal Opportunity Employer

At Legora, we believe great teams are built on diversity of thought and experience. We’re proud to be an equal opportunity employer and committed to creating an inclusive, high-performance culture where everyone can do their best work. We welcome people of all backgrounds and don’t discriminate based on race, color, religion, national origin, gender, gender identity or expression, sexual orientation, age, disability, veteran status, or any other characteristic protected by law.

Similar positions

Legora
Technical Platform Expert - NYC
Legora · New York City
Legora
Legal Engineer Associate
Legora · San Francisco
Legora
Senior Platform Engineer
Legora · New York City
Legora
AI Enablement Lead
Legora · London
Legora
Staff Site Reliability Engineer
Legora · New York City