Legora logo

Detection and Response Engineer

Legora

On-site
New York City, NY
Full-time
Senior
Staff
5+ yrs
$187k–$329kPosted 1h ago

Real job — pulled straight from Legora’s careers page · Verified September 11, 2026 · No reposts.

Job description

Legora is hiring a Detection and Response Engineer — a full-time, based in New York City, NY role ($187k–$329k). Apply directly on Legora's careers page below.

(Senior OR Staff) Detection & Response Engineer

Department: IT

Location: New York City

Compensation: $187,000 – $328,888 • Offers Equity

Employment Type: FullTime

About Us

Legora is redefining how legal work gets done. Not built for lawyers, built with them. We work alongside the world’s best legal teams, who expect excellence, precision, and speed, and we hold ourselves to the same bar.

Our AI-native workspace lets legal professionals move faster, think more clearly, and operate with sharper precision. By analysing thousands of documents in minutes and powering end-to-end workflows, we cut through complexity, teams can focus on what matters: judgment, strategy, and outcomes.

1,000+ customers across 50+ countries trust us, including Cleary Gottlieb, Goodwin, Linklaters, White & Case, Dentons, and Barclays. We’ve scaled to $100M+ in ARR, with teams across Europe, North America and APAC, and continue to expand through acquisitions including Qura, Walter AI and Graceview.

We partner with world-class performers: including Aaron Judge and the New York Yankees, Ludvig Åberg (and his caddie), and campaigns featuring Jude Law.

Joining Legora means three things.

  • We lean in: ownership over titles, outcomes over intentions.

  • We fight for excellence: high standards, direct, ego-free feedback.

  • We grow together: as a team and with our customers.

Mission before ego. Everyone contributes. No one coasts.

If you’re driven by impact, pace, and raising the bar. This is the place.

About the team

The IT and AI Enablement function helps Legora run securely and reliably as we grow. We are building an AI-native Information Security function. We ship security controls as software, and agents handle first-pass triage and routine investigation. People make the high-impact calls.

This role owns detection and response across Legora's corporate and production environments: endpoints, identity, cloud workloads, SaaS, and the AI systems and agents we operate. Law firms trust Legora with sensitive work, so we expect capable, well-resourced attackers. Your job is to find and stop them.

What you’ll be doing

  • Own detection and response across endpoints, identity, cloud workloads, SaaS, and Legora's AI systems. Hunt, triage, investigate, contain, and drive incidents through resolution, then turn what you learn into better detections and controls.

  • Build detections as production software on telemetry and pipelines provided by AI & Integrations Engineering. Keep them version-controlled, peer-reviewed, tested, and deployed through CI/CD. Measure coverage, precision, and time to detection, then tune where the data shows a gap.

  • Build threat models, telemetry, and response playbooks for our AI systems, agents, and their tool use. Detect misuse of agents operating across the company.

  • Build and supervise agents for triage, enrichment, and investigation. Set guardrails and approval thresholds for containment and other high-impact actions.

  • Map coverage to MITRE ATT&CK and validate it through threat hunting, penetration-test findings, and adversary emulation.

  • Share the on-call rotation and act as incident commander when security is involved. Engineering owns service reliability; Customer Trust and Legal own customer communications. Run post-incident reviews and use the findings to reduce detection and containment time.

  • Investigate insider risk and identity abuse with Corporate Security, People, and Legal. Work with Vulnerability Management on exposure priorities and IT Systems on the underlying estate.

  • Track actors and campaigns targeting AI companies and convert the intelligence into hunts and detections. Own the digital-risk platform and coordinate urgent phishing and impersonation takedowns.

Who you are

  • 5+ years in detection engineering, incident response, or security operations, including work as a senior escalation point. For Staff, we expect roughly 10+ years and experience setting detection and response strategy.

  • Strong software engineering skills in Python and SQL. You build detections, automations, and telemetry pipelines that run reliably in production.

  • You use LLMs and agents in day-to-day security work and know which decisions require a human. Be ready to show us an investigation or workflow you automated.

  • Fluent across endpoint, identity, cloud, and SaaS telemetry. You reason from attacker behaviour and correlate signals across systems.

  • You communicate clearly during incidents and turn incomplete technical evidence into sound decisions. Your post-incident reviews lead to concrete changes.

Nice to have

  • Experience with a modern SIEM or security data lake and at least two relevant query or rule languages, such as SPL, KQL, YARA-L, Sigma, or SQL.

  • Experience securing AI systems, agent tool use, and AI data flows, including prompt injection and exfiltration risks.

  • Experience with response automation, incident management, digital forensics, or malware analysis.

  • Threat intelligence, insider risk, or DLP experience.

What’s In It For You

  • Global collaboration: Partner with teams and clients across Europe, APAC, and North America.

  • Competitive package: Comprehensive salary, benefits, and tools for success.

  • Meaningful work: Your efforts shape how thousands of lawyers use AI daily.

  • In-person environment: Union Square office designed for ambitious builders and company provided lunch daily.

  • Benefits & Perks: We invest in our people with a comprehensive, thoughtfully designed benefits package:
    Medical, Dental & Vision

    • Multiple medical plan options through Aetna and Kaiser Permanente

    • HSA or Healthcare FSA (based on plan selection)

    • Dental plans via MetLife

    • Vision plans via Vision Care

    Family Support

    • Generous parental leave

    • Free access to Maven Clinic

    • Dependent Care FSA

    • Free One Medical membership for employees and dependents

    Additional Perks

    • Pre-tax commuter benefits

    • Life Insurance + STD/LTD

    • 401(K) with generous company match

    • Unlimited PTO

    • Robust voluntary benefits, including identity protection (via Aura), legal coverage via MetLife, pet savings programs, and more

Legora is an Equal Opportunity Employer

At Legora, we believe great teams are built on diversity of thought and experience. We’re proud to be an equal opportunity employer and committed to creating an inclusive, high-performance culture where everyone can do their best work. We welcome people of all backgrounds and don’t discriminate based on race, color, religion, national origin, gender, gender identity or expression, sexual orientation, age, disability, veteran status, or any other characteristic protected by law.

Get Detection and Response Engineer jobs like this

New roles from thousands of companies land hourly, straight from their careers pages. Get the freshest matches by email so you never miss one.

Email me new jobs
InventYou logo

Senior Full-Stack Developer

Stockholm, Stockholm County
✓ From careers page· 45m ago
Bedrock Robotics logo

Validation & Verification Test Engineer Intern

San Francisco, CA
✓ From careers page· 45m ago
Bedrock Robotics logo

Sensor Systems Engineer Intern

San Francisco, CA
✓ From careers page· 45m ago
Bedrock Robotics logo

Sensor Hardware Test Engineer Intern

San Francisco, CA
✓ From careers page· 45m ago

Frequently asked questions

What is the salary for Detection and Response Engineer at Legora?

The estimated salary range for Detection and Response Engineer at Legora is $187,000 - $329,000 USD per year.

What skills are required for Detection and Response Engineer at Legora?

The required skills for Detection and Response Engineer at Legora include: Python, SQL, SIEM, IAM.

What is the seniority level for Detection and Response Engineer at Legora?

Detection and Response Engineer at Legora is a Senior / Staff level position.

How do I apply for Detection and Response Engineer at Legora?

You can view the full description and apply for Detection and Response Engineer at Legora on EchoJobs: https://echojobs.io/job/legora-senior-or-staff-detection-response-engineer-wtk3x.