Job Description
About Us
Legora is redefining how legal work gets done. Not built for lawyers, built with them. We work alongside the world’s best legal teams, who expect excellence, precision, and speed, and we hold ourselves to the same bar.
Our AI-native workspace lets legal professionals move faster, think more clearly, and operate with sharper precision. By analysing thousands of documents in minutes and powering end-to-end workflows, we cut through complexity, teams can focus on what matters: judgment, strategy, and outcomes.
1,000+ customers across 50+ countries trust us, including Cleary Gottlieb, Goodwin, Linklaters, White & Case, Dentons, and Barclays. We’ve scaled to $100M+ in ARR, with teams across Europe, North America and APAC, and continue to expand through acquisitions including Qura, Walter AI and Graceview.
We partner with world-class performers: including Aaron Judge and the New York Yankees, Ludvig Åberg (and his caddie), and campaigns featuring Jude Law.
Joining Legora means three things.
We lean in: ownership over titles, outcomes over intentions.
We fight for excellence: high standards, direct, ego-free feedback.
We grow together: as a team and with our customers.
Mission before ego. Everyone contributes. No one coasts.
If you’re driven by impact, pace, and raising the bar. This is the place.
The Role
Acquisitions are a core part of how Legora grows, and we hold everything we acquire to the same security bar our customers hold us to. As our deal cadence accelerates, we're adding dedicated security depth to our M&A and integration program: a specialist to own the security work-stream of every transaction, from pre-LOI diligence through Day-1 decisions to full integration onto Legora's security baseline.
Deals are the bursty half of this job. The durable half is the estates they leave behind: every acquired company runs as its own operating environment, its own identity, endpoints, vendors, and SDLC, until it is properly integrated or decommissioned, and you own the security posture of that portfolio for as long as it exists. Integration debt is your backlog, and clearing it is the job.
You'll sit within our Security organization and partner daily with Corporate Development and our Post-Merger Integration team, operating with real authority: you own security decisions within the integration program, with defined milestones and exit criteria for every deal. As integrations complete, the role's center of gravity shifts toward Legora's broader security architecture, the mandate grows out of the backlog you clear.
What You'll Do
Own security due diligence for prospective transactions: assess target security posture, architecture, data handling, compliance exposure, and breach history, and translate findings into deal terms, valuation input, and integration conditions
Define and enforce Day-1 security posture for each transaction, connectivity, identity, and access decisions that protect Legora and its customers while the business integrates
Lead each acquired product and team through a structured, time-boxed integration onto Legora's security baseline: identity and SSO, endpoint, logging and detection, vendor consolidation, and secure SDLC
Own the security chapter of Legora's integration playbook, partnering with our Post-Merger Integration team so security milestones are built into every deal plan from day one
Own the security posture of acquired, not-yet-integrated estates as operating environments: minimum control requirements, risk-based exceptions and interim safeguards, TSA-period security, and monitoring against Legora's enterprise risk profile until each estate is integrated or decommissioned
Manage compliance scope as acquired systems enter our SOC 2 / ISO and customer-audit boundary, and uphold our customer data commitments across every product we bring into the portfolio
Work cross-functionally with Corporate Development, Post-Merger Integration, Engineering, Legal, IT, and Product leadership, and report security integration status and risk posture to executive stakeholders
What You Bring
7+ years in security engineering, security architecture, or technical program management, including direct experience with M&A security diligence and/or post-acquisition integration
Fluency across the domains integration touches: identity and access management, cloud infrastructure (AWS/GCP/Azure), corporate IT, vulnerability management, and compliance frameworks (SOC 2, ISO 27001)
Ability to read a pentest report and a deal schedule with equal comfort, you translate technical risk into business terms for executives and deal teams
A program-management mindset: you run multiple concurrent workstreams to defined milestones and hold teams to exit criteria
Sound judgment on sequencing, you know when to contain, when to bridge, and when to fully integrate, and you can defend those calls
Discretion. You'll operate on pre-announcement transactions and hold material non-public information
Nice to have
Experience building an M&A security function or playbook from scratch at an acquisitive technology company
Background in B2B SaaS serving regulated or highly security-conscious customers (legal, financial services, healthcare)
Exposure to transaction mechanics: reps and warranties, escrow and remediation covenants, TSAs
Paste this over the existing "The Role" through "What You Bring" headers, "What's In It For You" stays as is.
What’s In It For You
Global collaboration: Partner with teams and clients across Europe, APAC, and North America.
Competitive package: Comprehensive salary, benefits, and tools for success.
Meaningful work: Your efforts shape how thousands of lawyers use AI daily.
In-person environment: Union Square office designed for ambitious builders and company provided lunch daily.
Benefits & Perks: We invest in our people with a comprehensive, thoughtfully designed benefits package:
Medical, Dental & VisionMultiple medical plan options through Aetna and Kaiser Permanente
HSA or Healthcare FSA (based on plan selection)
Dental plans via MetLife
Vision plans via Vision Care
Family Support
Generous parental leave
Free access to Maven Clinic
Dependent Care FSA
Free One Medical membership for employees and dependents
Additional Perks
Pre-tax commuter benefits
Life Insurance + STD/LTD
401(K) with generous company match
Unlimited PTO
Robust voluntary benefits, including identity protection (via Aura), legal coverage via MetLife, pet savings programs, and more
Legora is an Equal Opportunity Employer
At Legora, we believe great teams are built on diversity of thought and experience. We’re proud to be an equal opportunity employer and committed to creating an inclusive, high-performance culture where everyone can do their best work. We welcome people of all backgrounds and don’t discriminate based on race, color, religion, national origin, gender, gender identity or expression, sexual orientation, age, disability, veteran status, or any other characteristic protected by law.
Categories
Frequently asked questions
Is the M&A Security Lead position at Legora remote?
The M&A Security Lead role at Legora is an on-site or hybrid position.
What type of employment is the M&A Security Lead role?
Legora is hiring for a full-time M&A Security Lead position.
How do I apply for the M&A Security Lead position at Legora?
You can apply for the M&A Security Lead role directly through Legora's official application link provided on this page.