Legora AB

(Senior OR Staff) Detection & Response Engineer

Legora AB
Apply
7 hours ago
New York, NY, USASenior / Staff+

Base Salary

$187k - $329k/yr

Responsibilities

  • Own detection and response across endpoints, identity, cloud workloads, SaaS, and Legora’s AI systems, including hunting, triage, investigation, containment, and incident resolution.
  • Build, test, review, version-control, deploy, and tune production detection software using telemetry and data pipelines.
  • Develop threat models, telemetry, and response playbooks for AI systems, agents, and agent tool use.
  • Build and supervise agents for triage, enrichment, and investigation, including guardrails and approval thresholds for high-impact actions.
  • Map detection coverage to MITRE ATT&CK and validate it through threat hunting, penetration-test findings, and adversary emulation.
  • Participate in the on-call rotation, serve as incident commander for security incidents, and lead post-incident reviews.
  • Investigate insider risk and identity abuse with Corporate Security, People, and Legal, and coordinate with Vulnerability Management and IT Systems.
  • Track threat actors and campaigns targeting AI companies, convert intelligence into hunts and detections, and own the digital-risk platform and urgent phishing and impersonation takedowns.

Requirements

  • At least 5 years of experience in detection engineering, incident response, or security operations, including experience as a senior escalation point.
  • Staff-level candidates are expected to have roughly 10 or more years of experience and experience setting detection and response strategy.
  • Strong software engineering skills in Python and SQL, with experience building reliable production detections, automations, and telemetry pipelines.
  • Experience using LLMs and agents in security work and understanding which decisions require human judgment.
  • Fluency across endpoint, identity, cloud, and SaaS telemetry, with the ability to correlate signals based on attacker behavior.
  • Clear incident communication skills and the ability to turn incomplete technical evidence into sound decisions.
  • Preferred experience with a modern SIEM or security data lake and at least two of SPL, KQL, YARA-L, Sigma, or SQL.
  • Preferred experience securing AI systems, agent tool use, and AI data flows, including prompt injection and exfiltration risks.
  • Preferred experience with response automation, incident management, digital forensics, malware analysis, threat intelligence, insider risk, or DLP.

Benefits

  • Global collaboration with teams and clients across Europe, APAC, and North America.
  • Comprehensive salary and benefits package with tools for success.
  • In-person work in the Union Square office with company-provided lunch daily.
  • Medical, dental, and vision plans, including options through Aetna, Kaiser Permanente, MetLife, and Vision Care.
  • HSA or Healthcare FSA, dependent care FSA, parental leave, Maven Clinic access, and One Medical membership for employees and dependents.
  • Pre-tax commuter benefits, life insurance, short-term and long-term disability coverage, and a 401(k) with company match.
  • Unlimited PTO and voluntary benefits including identity protection, legal coverage, and pet savings programs.

Tech Stack

Categories

Legora AB

About Legora AB

501-1,000 employees

Legora builds an AI-powered collaborative workspace for legal professionals, used by law firms and in-house legal teams to draft, review, and manage matters. It sells enterprise SaaS to senior legal decision-makers, focusing on precision and speed for complex workflows. Founded in 2023 and headquartered in Stockholm, this privately held company serves over 200 global clients and is backed by Accel, Bessemer, ICONIQ, General Catalyst, Benchmark, Redpoint, and Y Combinator.

Contact me