Lead Application Security Engineer
Core
Building the security foundation for an AI-native legal technology product used by law firms, focusing on application security, cloud infrastructure, and AI-specific risks.
Role type
Lead Application Security Engineer (hands-on IC)
Builds
Security program, automation tooling, and hardened systems for an AI-native SaaS platform
Domain
Legal technology / AI security / Cloud infrastructure
Deliverable
production ML models | product features | infrastructure
Required skills
Application security, software engineering (code review/contributing), cloud security (AWS), identity and access management (SAML, OAuth, IAM), AI security (prompt injection, model access), systems thinking, pragmatic risk management
Preferred skills
SaaS security, regulated industry experience, Kubernetes, TypeScript, Python, Go, enterprise security controls
Technologies
AWS, Kubernetes, TypeScript, Python, Go, SAML, OAuth, OIDC, RBAC/ABAC
Responsibilities
Build and scale application security program (design reviews, threat modeling, code review, vulnerability management), secure AI-native workflows, develop internal security tooling and automation, review architecture for security risks, strengthen cloud and deployment security, support compliance efforts
Seniority
Senior, hands-on IC