AI
Curated AI Jobs
Legora

(Senior OR Staff) Detection & Response Engineer

Legora09 Sep 2026
fulltimeonsite
Apply for this position

Before you apply

Listed location: New York City

Work arrangement: onsite. A remote label does not confirm worldwide eligibility or visa sponsorship.

Read the employer’s description for qualifications, compensation and work eligibility. Confirm the position is still open on the application page.

Job description supplied by Legora; category and skill labels may be inferred. How our listings work · Report a problem

Job Description

About Us

Legora is redefining how legal work gets done. Not built for lawyers, built with them. We work alongside the world’s best legal teams, who expect excellence, precision, and speed, and we hold ourselves to the same bar.

Our AI-native workspace lets legal professionals move faster, think more clearly, and operate with sharper precision. By analysing thousands of documents in minutes and powering end-to-end workflows, we cut through complexity, teams can focus on what matters: judgment, strategy, and outcomes.

2,100+ customers across 80+ countries trust us, including Cleary Gottlieb, Goodwin, Linklaters, White & Case, Dentons, and Barclays. We’ve scaled to $200M+ in ARR, with teams across Europe, North America and APAC, and continue to expand through acquisitions including Qura, Walter AI, Graceview, Cadastral, and Wexler.

We partner with world-class performers: including Aaron Judge and the New York Yankees, Ludvig Åberg (and his caddie), and campaigns featuring Jude Law.

Joining Legora means three things.

  • We lean in: ownership over titles, outcomes over intentions.

  • We fight for excellence: high standards, direct, ego-free feedback.

  • We grow together: as a team and with our customers.

Mission before ego. Everyone contributes. No one coasts.

If you’re driven by impact, pace, and raising the bar. This is the place.

About the team

The IT and AI Enablement function helps Legora run securely and reliably as we grow. We are building an AI-native Information Security function. We ship security controls as software, and agents handle first-pass triage and routine investigation. People make the high-impact calls.

This role owns detection and response across Legora's corporate and production environments: endpoints, identity, cloud workloads, SaaS, and the AI systems and agents we operate. Law firms trust Legora with sensitive work, so we expect capable, well-resourced attackers. Your job is to find and stop them.

What you’ll be doing

  • Own detection and response across endpoints, identity, cloud workloads, SaaS, and Legora's AI systems. Hunt, triage, investigate, contain, and drive incidents through resolution, then turn what you learn into better detections and controls.

  • Build detections as production software on telemetry and pipelines provided by AI & Integrations Engineering. Keep them version-controlled, peer-reviewed, tested, and deployed through CI/CD. Measure coverage, precision, and time to detection, then tune where the data shows a gap.

  • Build threat models, telemetry, and response playbooks for our AI systems, agents, and their tool use. Detect misuse of agents operating across the company.

  • Build and supervise agents for triage, enrichment, and investigation. Set guardrails and approval thresholds for containment and other high-impact actions.

  • Map coverage to MITRE ATT&CK and validate it through threat hunting, penetration-test findings, and adversary emulation.

  • Share the on-call rotation and act as incident commander when security is involved. Engineering owns service reliability; Customer Trust and Legal own customer communications. Run post-incident reviews and use the findings to reduce detection and containment time.

  • Investigate insider risk and identity abuse with Corporate Security, People, and Legal. Work with Vulnerability Management on exposure priorities and IT Systems on the underlying estate.

  • Track actors and campaigns targeting AI companies and convert the intelligence into hunts and detections. Own the digital-risk platform and coordinate urgent phishing and impersonation takedowns.

Who you are

  • 5+ years in detection engineering, incident response, or security operations, including work as a senior escalation point. For Staff, we expect roughly 10+ years and experience setting detection and response strategy.

  • Strong software engineering skills in Python and SQL. You build detections, automations, and telemetry pipelines that run reliably in production.

  • You use LLMs and agents in day-to-day security work and know which decisions require a human. Be ready to show us an investigation or workflow you automated.

  • Fluent across endpoint, identity, cloud, and SaaS telemetry. You reason from attacker behaviour and correlate signals across systems.

  • You communicate clearly during incidents and turn incomplete technical evidence into sound decisions. Your post-incident reviews lead to concrete changes.

Nice to have

  • Experience with a modern SIEM or security data lake and at least two relevant query or rule languages, such as SPL, KQL, YARA-L, Sigma, or SQL.

  • Experience securing AI systems, agent tool use, and AI data flows, including prompt injection and exfiltration risks.

  • Experience with response automation, incident management, digital forensics, or malware analysis.

  • Threat intelligence, insider risk, or DLP experience.

What’s In It For You

  • Global collaboration: Partner with teams and clients across Europe, APAC, and North America.

  • Competitive package: Comprehensive salary, benefits, and tools for success.

  • Meaningful work: Your efforts shape how thousands of lawyers use AI daily.

  • In-person environment: Union Square office designed for ambitious builders and company provided lunch daily.

  • Benefits & Perks: We invest in our people with a comprehensive, thoughtfully designed benefits package:
    Medical, Dental & Vision

    • Multiple medical plan options through Aetna and Kaiser Permanente

    • HSA or Healthcare FSA (based on plan selection)

    • Dental plans via MetLife

    • Vision plans via Vision Care

    Family Support

    • Generous parental leave

    • Free access to Maven Clinic

    • Dependent Care FSA

    • Free One Medical membership for employees and dependents

    Additional Perks

    • Pre-tax commuter benefits

    • Life Insurance + STD/LTD

    • 401(K) with generous company match

    • Unlimited PTO

    • Robust voluntary benefits, including identity protection (via Aura), legal coverage via MetLife, pet savings programs, and more

Legora is an Equal Opportunity Employer

At Legora, we believe great teams are built on diversity of thought and experience. We’re proud to be an equal opportunity employer and committed to creating an inclusive, high-performance culture where everyone can do their best work. We welcome people of all backgrounds and don’t discriminate based on race, color, religion, national origin, gender, gender identity or expression, sexual orientation, age, disability, veteran status, or any other characteristic protected by law.

Frequently asked questions

Is the (Senior OR Staff) Detection & Response Engineer position at Legora remote?

The (Senior OR Staff) Detection & Response Engineer role at Legora does not have a confirmed remote arrangement in our data. Check the employer description for its work location.

What type of employment is the (Senior OR Staff) Detection & Response Engineer role?

Legora is hiring for a full-time (Senior OR Staff) Detection & Response Engineer position.

How do I apply for the (Senior OR Staff) Detection & Response Engineer position at Legora?

You can apply for the (Senior OR Staff) Detection & Response Engineer role directly through Legora's official application link provided on this page.

Interested in this role?

Apply directly on the company's website.

Apply Now
Legora

Legora

Website
Posted09 Sep 2026
Typefulltime
LevelLead
LocationNew York City
Apply NowView All Jobs at Legora

Share this job