> Markdown version of [/jobs/ext/1458135-corporate-security-engineer](https://www.wearedevelopers.com/jobs/ext/1458135-corporate-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Corporate Security Engineer - **Company:** Legora, Inc. - **Location:** New York, NY, United States - **Experience:** Experienced - **Salary:** $188,000.0 - $221,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Software as a Service, Cloud Computing Security, Cyber Security, Python (Programming Language), OAuth, Phishing, Large Language Models, Information Technology, Production Code, Gsuite, Terraform - **Published:** July 27, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=6f0fbb5f1a1f3d0d ## About the Role * 4+ years in corporate, enterprise, or IT security, with full ownership of security decisions and scope end to end. * A builder first - you write production-grade code (Python at least) and treat controls, automations, and detections as software you own, not tickets you close. * AI-first by conviction - you already reach for agents and LLMs (Claude Code and the like) to compress toil, and you have a clear view on where they're trustworthy and where a human owns the call. Show us something you automated that used to eat your week. ## Description * Own non-human identity - the service accounts, agents, and workloads that scale faster than headcount. Keep them inventoried and owned, scoped tightly, running on short-lived and secretless credentials, with a path to revoke at scale. * Set the authorization model for agents - scoped, revocable, and auditable: least-privilege at each MCP call, no token passthrough, and delegated authority rather than standing access. * Secure how Legora uses AI - govern employee use of LLMs and agents, keep client data on sanctioned paths, and make the safe path the fast one as teams adopt AI. * Advance identity for people - phishing-resistant MFA (passkeys / FIDO2), SSO, SCIM lifecycle, and least-privilege / just-in-time access across Google Workspace, Slack, Notion, and the SaaS estate - and cover the attack classes that defeat MFA alone - session / token theft, adversary-in-the-middle phishing, OAuth consent abuse - with continuous access evaluation to revoke live sessions on risk. * Raise the bar on SaaS security posture (SSPM) - configurations held to clear benchmarks, and risky OAuth grants, over-permissioned or stale admins, shadow SaaS / AI, and config drift surfaced continuously - the technical lens on the portfolio the SaaS Enablement & Governance Lead holds the system of record for. * Own endpoint and device trust - an Apple-first fleet on MDM and EDR, with access gated on device health via zero-trust / conditional access, partnering with IT Systems and Workplace Technology, who run the fleet and network. * Own data-protection controls (DLP) across endpoint, SaaS, browser, and AI-egress, run access reviews, and surface insider-risk signals to Detection & Response for investigation with People and Legal. * Build controls and guardrails as code (Python + Terraform / IaC) so security scales, tracked against agent-identity and MFA coverage, risky OAuth grants closed, and mean time to remediate and revoke. ## Related Videos - [Automated Security for the Entire SDLC](https://www.wearedevelopers.com/videos/100323-automated-security-for-the-entire-sdlc) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Beyond the Hype: Building Trustworthy and Reliable LLM Applications with Guardrails](https://www.wearedevelopers.com/videos/1594-beyond-the-hype-building-trustworthy-and-reliable-llm-applications-with-guardrails) - [Skynet wants your Passwords! The Role of AI in Automating Social Engineering](https://www.wearedevelopers.com/videos/770-skynet-wants-your-passwords-the-role-of-ai-in-automating-social-engineering) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) ## Related Articles - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 137 - AI'm not sure about this](https://www.wearedevelopers.com/magazine/485-dev-digest-137-ai-m-not-sure-about-this) - [What Are Large Language Models?](https://www.wearedevelopers.com/magazine/304-what-are-large-language-models) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 132 - Binging WADFlix?](https://www.wearedevelopers.com/magazine/473-dev-digest-132-binging-wadflix)