Senior/Staff Engineer, Detection & Response

Legora

New York (NY)

On-site

USD 180,000 - 235,000

Full time

2 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Union Square office
Lunch daily
Competitive benefits
401(k) with match
Unlimited PTO

Job summary

Legora in Manhattan, NYC is seeking a senior security operations professional to own detection and response across endpoints, identity, cloud workloads, and AI systems. You will hunt, triage, investigate, contain, and drive incidents to resolution, then turn findings into improved detections and controls.

The role requires building detections as production software, maintaining CI/CD pipelines, and mapping coverage to MITRE ATT&CK.

Qualifications

  • 5+ years in detection engineering, incident response, or security operations, including senior escalation experience.
  • Strong Python and SQL skills; you build production-grade detections and telemetry pipelines.
  • Experience using LLMs and agents; able to justify human-in-the-loop decisions.
  • Fluent across endpoint, identity, cloud, and SaaS telemetry; correlates signals across systems.
  • Clear incident communication; post-incident reviews lead to concrete changes.

Responsibilities

  • Own detection and response across endpoints, identity, cloud workloads, SaaS, and AI systems; hunt, triage, investigate, contain, and drive incidents to resolution.
  • Build detections as production software; maintain version control, testing, and CI/CD deployment; measure coverage and time to detection.
  • Develop threat models, telemetry, and response playbooks for AI systems and agents; detect misuse of agents.
  • Build and supervise agents for triage, enrichment, and investigation; set guardrails and approval thresholds.
  • Map coverage to MITRE ATT&CK; validate through threat hunting, pentests, and adversary emulation.
  • Share on-call rotation and act as incident commander; coordinate communications and post-incident reviews to reduce time.
  • Investigate insider risk and identity abuse; coordinate with Vulnerability Management and IT Systems.
  • Track campaigns targeting AI companies; manage the digital-risk platform and takedown phishing/impersonation threats.

Skills

Python
SQL
Detection engineering
Incident response
Security operations
LLMs & agents

Tools

SIEM
Security data lake
SPL
KQL
YARA-L
Sigma

Job description

**Please note, this role is 5 days/week on-site in Manhattan, NYC (Union Square)**

About the team

The IT and AI Enablement function helps Legora run securely and reliably as we grow. We are building an AI-native Information Security function. We ship security controls as software, and agents handle first-pass triage and routine investigation. People make the high-impact calls.

This role owns detection and response across Legora's corporate and production environments: endpoints, identity, cloud workloads, SaaS, and the AI systems and agents we operate. Law firms trust Legora with sensitive work, so we expect capable, well-resourced attackers. Your job is to find and stop them.

What you’ll be doing
  • Own detection and response across endpoints, identity, cloud workloads, SaaS, and Legora's AI systems. Hunt, triage, investigate, contain, and drive incidents through resolution, then turn what you learn into better detections and controls.
  • Build detections as production software on telemetry and pipelines provided by AI & Integrations Engineering. Keep them version-controlled, peer-reviewed, tested, and deployed through CI/CD. Measure coverage, precision, and time to detection, then tune where the data shows a gap.
  • Build threat models, telemetry, and response playbooks for our AI systems, agents, and their tool use. Detect misuse of agents operating across the company.
  • Build and supervise agents for triage, enrichment, and investigation. Set guardrails and approval thresholds for containment and other high-impact actions.
  • Map coverage to MITRE ATT&CK and validate it through threat hunting, penetration-test findings, and adversary emulation.
  • Share the on-call rotation and act as incident commander when security is involved. Engineering owns service reliability; Customer Trust and Legal own customer communications. Run post-incident reviews and use the findings to reduce detection and containment time.
  • Investigate insider risk and identity abuse with Corporate Security, People, and Legal. Work with Vulnerability Management on exposure priorities and IT Systems on the underlying estate.
  • Track actors and campaigns targeting AI companies and convert the intelligence into hunts and detections. Own the digital-risk platform and coordinate urgent phishing and impersonation takedowns.
Who you are
  • 5+ years in detection engineering, incident response, or security operations, including work as a senior escalation point. For Staff, we expect roughly 10+ years and experience setting detection and response strategy.
  • Strong software engineering skills in Python and SQL. You build detections, automations, and telemetry pipelines that run reliably in production.
  • You use LLMs and agents in day-to-day security work and know which decisions require a human. Be ready to show us an investigation or workflow you automated.
  • Fluent across endpoint, identity, cloud, and SaaS telemetry. You reason from attacker behaviour and correlate signals across systems.
  • You communicate clearly during incidents and turn incomplete technical evidence into sound decisions. Your post-incident reviews lead to concrete changes.
Nice to have
  • Experience with a modern SIEM or security data lake and at least two relevant query or rule languages, such as SPL, KQL, YARA-L, Sigma, or SQL.
  • Experience securing AI systems, agent tool use, and AI data flows, including prompt injection and exfiltration risks.
  • Experience with response automation, incident management, digital forensics, or malware analysis.
  • Threat intelligence, insider risk, or DLP experience.
What’s In It For You
  • Global collaboration: Partner with teams and clients across Europe, APAC, and North America.
  • Competitive package: Comprehensive salary, benefits, and tools for success.
  • Meaningful work: Your efforts shape how thousands of lawyers use AI daily.
  • In-person environment: Union Square office designed for ambitious builders and company provided lunch daily.
  • Benefits & Perks: We invest in our people with a comprehensive, thoughtfully designed benefits package:
  • Multiple medical plan options through Aetna and Kaiser Permanente
  • HSA or Healthcare FSA (based on plan selection)
  • Family Support
  • Generous parental leave
  • Free access to Maven Clinic
  • Dependent Care FSA
  • Free One Medical membership for employees and dependents
  • Life Insurance + STD/LTD
  • 401(K) with generous company match
  • Unlimited PTO
  • Robust voluntary benefits, including identity protection (via Aura), legal coverage via MetLife, pet savings programs, and more
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

(Senior OR Staff) Detection & Response Engineer
(Senior OR Staff) Detection & Response Engineer

Legora • New York (NY)

On-site
USD 170,000 - 210,000
In-person Union Square office
Comprehensive salary and benefits
401(k) with company match
+3
(Senior OR Staff) Detection & Response Engineer New York City
(Senior OR Staff) Detection & Response Engineer New York City

Legora AB • New York (NY), Northern (KY)

Hybrid
USD 190,000 - 240,000
Global collaboration
Competitive compensation
In-person Union Square office
+3
Corporate Security Engineer
Corporate Security Engineer

Legora • New York (NY)

On-site
Confidential
Medical, Dental & Vision
401K with company match
Unlimited PTO
+1
Senior Forward Deployed Engineer
Senior Forward Deployed Engineer

Legora • New York (NY)

On-site
USD 170,000 - 230,000
Union Square office
Daily lunch provided
Medical, Dental & Vision
GRC Lead
GRC Lead

Legora • New York (NY)

On-site
Confidential
In-person office: Union Square (NYC)
Daily lunch provided
Comprehensive medical, dental & vision
Senior Forward Deployed Engineer New York City
Senior Forward Deployed Engineer New York City

Legora AB • New York (NY), Northern (KY)

Hybrid
USD 160,000 - 240,000
Union Square office
Lunch provided daily
Medical, Dental & Vision
+3
Information Technology Asset Manager
Information Technology Asset Manager

Legora • New York (NY)

On-site
USD 140,000 - 190,000
Global collaboration
Competitive package
Union Square office
+3
Compliance Engineer
Compliance Engineer

Legora • New York (NY)

On-site
USD 170,000 - 250,000
Office lunch daily
Union Square office
Medical plans
+3
Legal Engineer
Legal Engineer

Legora AB • New York (NY)

On-site
USD 150,000 - 210,000
Medical plan
Dental plan
Vision plan
+3
Compliance Lead
Compliance Lead

Legora • New York (NY)

On-site
USD 160,000 - 210,000
Union Square office
Lunch provided daily
401(K) with company match
+6