Security Engineer

Crimson

Greater London

Hybrid

GBP 90,000 - 130,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Competitive salary
Meaningful equity

Job summary

Crimson is hiring a security leader/engineer to own the continued evolution of our security programme. You will work closely with the founders and engineering team to ensure our security posture keeps pace with rapid product development and enterprise adoption.

Based in London or New York, this full-time role requires hands-on security across cloud, application and data, with direct engagement in threat modelling, incident response and customer security reviews. Equity is offered.

Qualifications

  • Strong hands-on experience securing a modern cloud-hosted SaaS product.
  • Grounding in application security, cloud security, identity and incident response.
  • Ability to review code and architecture, automate controls with engineers.
  • Clear communication with technical teams and security stakeholders.

Responsibilities

  • Own and evolve Crimson's security roadmap across app, cloud, data, and identity.
  • Partner with engineers on threat modelling, architecture reviews and secure design.
  • Operate and automate vulnerability management, secrets management, and access controls.
  • Maintain incident response program, run playbooks and investigations.
  • Coordinate penetration tests and represent security posture in customer reviews.
  • Maintain SOC 2 Type II attestation evidence and compliance controls.
  • Embed practical security tooling into a fast-moving engineering culture.

Skills

Cloud security
Application security
Incident response
Threat modelling
Code review
Security automation

Tools

AWS
GCP
Azure
CI/CD security tooling

Job description

Crimson is the AI case intelligence platform for litigation and arbitration. We help disputes teams at leading law firms understand large case files, test arguments and produce high-quality work grounded in the full matter record.

Crimson is enterprise-grade by design. We are SOC 2 Type II attested, encrypt data in transit and at rest, and maintain rigorous controls across our product, infrastructure and operations. Security is embedded in how we build and operate because leading law firms trust Crimson with highly sensitive case information.

You will work closely with the founders and engineering team to own the continued evolution of our security programme. Combining hands-on delivery with clear judgement about risk, you will ensure our security posture keeps pace with rapid product development, growing enterprise adoption and expansion across the UK and US.

What you'll do
  • Own and continuously evolve Crimson's security roadmap across application, cloud, identity, data and corporate systems
  • Partner with engineers on threat modelling, architecture reviews and secure design for new AI and document-processing features
  • Operate and automate our vulnerability management, security testing, secrets management, access controls, logging and detection capabilities
  • Maintain and exercise our incident response programme, including playbooks, simulations, investigations and continuous learning
  • Coordinate independent penetration testing and represent Crimson's security posture in customer security reviews
  • Maintain the controls and evidence supporting Crimson's SOC 2 Type II attestation and enterprise customer requirements
  • Embed practical security guidance and tooling into a fast-moving engineering environment
What we're looking for
  • Strong hands-on experience securing a modern cloud-hosted SaaS product
  • A solid grounding in application security, cloud security, identity and incident response
  • The ability to review code and architecture, automate controls and work directly with product engineers
  • Clear communication with both technical teams and security stakeholders at major law firms
  • High ownership, sound risk judgement and comfort operating in an early-stage environment
Especially useful
  • Experience with security in legal technology, fintech or another high-trust B2B environment
  • Experience with AI systems, document pipelines or multi-tenant data platforms
  • Familiarity with SOC 2, ISO 27001, GDPR or enterprise security procurement
The opportunity

Crimson is backed by Y Combinator and other leading investors and is already used by litigation teams in the UK and US. You will join a small, multidisciplinary team with direct access to customers, real ownership and the chance to help build a defining company in legal AI.

This is a full-time role based in London or New York. We work together in person at least four days a week and offer a competitive salary plus meaningful equity.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Litigation Specialist
Litigation Specialist

Crimson • Greater London

On-site
GBP 70,000 - 110,000
Equity
Competitive salary
Security Engineer, AI SaaS — SOC 2 & Incident Response
Security Engineer, AI SaaS — SOC 2 & Incident Response

Crimson • Greater London

Hybrid
GBP 90,000 - 130,000
Competitive salary
Meaningful equity
Litigation Platform Enablement Lead
Litigation Platform Enablement Lead

Crimson • Greater London

On-site
GBP 70,000 - 110,000
Equity
Competitive salary
Founding Security Engineer
Founding Security Engineer

Pear VC • Greater London

On-site
GBP 65,000 - 85,000
Competitive salary
Equity
Budget for learning
+2
Founding Security Engineer
Founding Security Engineer

Praxis, Inc. • Greater London

On-site
GBP 120,000 - 180,000
Competitive salary & equity
Autonomy & ownership
Learning budget
+2
Founding Security Engineer
Founding Security Engineer

Wexler • Greater London

On-site
GBP 70,000 - 90,000
Competitive salary and significant equity
Budget for learning and professional growth
Bi-annual team retreats
Principal Security Engineer
Principal Security Engineer

RedCloud • Greater London

Hybrid
GBP 120,000 - 160,000
25 Days Annual leave
Pension matched
Healthcare cashplan
+4
CyberSecurity Engineer
CyberSecurity Engineer

Fyxer AI • City Of London

Hybrid
GBP 80,000
Private medical insurance
Meaningful equity
AI Engineer
AI Engineer

Norton Rose Fulbright • City of Westminster

Hybrid
GBP 85,000 - 125,000
Cybersecurity Analyst
Cybersecurity Analyst

Aplaro Ltd • Greater London

On-site
GBP 60,000 - 85,000