Назад
5 дней назад

Corporate Security Engineer (AI)

188 000 - 221 000$
Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
c1
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/

TL;DR

Corporate Security Engineer (Python/AI): Designing and implementing the security architecture for Legora's internal corporate environment with an accent on non-human identity, SaaS security, and AI governance. Focus on building automated controls as code, securing LLM adoption, and managing a zero-trust endpoint fleet.

Location: On-site in New York City

Salary: $188K – $221K + Equity

Company

Legora is an AI-native workspace for legal professionals, serving over 1,000 customers across 50+ countries with $100M+ in ARR.

What you will do

  • Own non-human identity, service accounts, and agent authorization models to ensure least-privilege access.
  • Govern the secure internal adoption and use of LLMs and AI agents, ensuring client data remains on sanctioned paths.
  • Advance identity management for employees using phishing-resistant MFA, SSO, and SCIM lifecycles.
  • Raise the bar on SaaS security posture (SSPM) by managing configurations, OAuth grants, and shadow AI.
  • Own endpoint and device trust for an Apple-first fleet via MDM and EDR with zero-trust conditional access.
  • Build security controls and guardrails as code using Python and Terraform to ensure scalability.

Requirements

  • 4+ years of experience in corporate, enterprise, or IT security with full end-to-end ownership of security decisions.
  • Ability to write production-grade Python code to treat controls and detections as software.
  • Expertise in modern identity protocols (SAML, OAuth 2.0, OIDC) and enterprise IdPs (Okta, Microsoft Entra ID, Google Workspace).
  • AI-first mindset with a proven track record of using agents and LLMs to automate manual toil.
  • Experience securing a modern attack surface, focusing on identity, SaaS estates, and endpoints.
  • Must be based in New York City for on-site work

Nice to have

  • Knowledge of OWASP LLM Top 10, prompt-injection, and exfiltration detection.
  • Experience with ITDR and SaaS-identity tooling (e.g., Push Security).
  • Proficiency with Jamf, Intune, and modern EDR solutions.
  • Experience with SOAR platforms (Tines, Torq) and DLP/UEBA tooling.
  • Practical experience implementing technical controls for SOC 2 or ISO 27001.

Culture & Benefits

  • Competitive compensation package including salary, equity, and a generous 401(k) match.
  • Comprehensive health insurance (Medical, Dental, Vision) through Aetna, Kaiser Permanente, and MetLife.
  • Family support including generous parental leave, Maven Clinic access, and Dependent Care FSA.
  • Unlimited PTO and pre-tax commuter benefits.
  • High-performance, in-person culture at the Union Square office with daily company-provided lunch.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →