6 months ago
Base Salary
$200k - $300k/yr
Responsibilities
- Design and implement security controls across applications, APIs, and cloud infrastructure.
- Build systems and processes to protect confidential legal and customer data.
- Establish and enforce secure development practices, including code reviews, threat modeling, and vulnerability management.
- Implement monitoring, alerting, and incident response processes for detecting and responding to security threats.
- Support security and compliance efforts such as SOC 2, including documentation, controls, and audits.
- Partner with engineering and product teams to embed security into the development lifecycle.
Requirements
- 4+ years of experience in security engineering, infrastructure security, or a related role.
- Strong understanding of application security, cloud security such as AWS or GCP, and common vulnerability classes.
- Experience securing production systems, including authentication, authorization, and data protection.
- Proficiency in at least one programming language, such as Python or Go, and comfort working with engineering teams.
- Experience with security tooling, monitoring systems, and incident response workflows.
- Ability to prioritize risks and implement effective, scalable solutions independently in ambiguous environments.
- Clear communication skills for working with engineers, product teams, and leadership.
Tech Stack
Categories
About Crosby
Crosby operates an AI-enabled law firm that uses attorney-in-the-loop software to review and negotiate commercial contracts such as MSAs, DPAs, and NDAs for high-growth companies. It sells legal services delivered via proprietary tooling to speed deal close and standardize quality across workflows. Notable customers include Ramp, Cursor, and Cognition, and the company is privately held.
