About this role
Job title: Security & Compliance Engineer
About the Role Legora is seeking a Security & Compliance Engineer to help design, implement, and maintain security controls across our platform, ensuring data stays secure, private, and compliant with ISO 42001, ISO 27001, SOC 2 Type 2, and GDPR. You will support the AI governance framework and uphold zero trust principles across the stack.
What You'll Do
- Design, implement, and manage encryption and access management, including BYOK options
- Configure tiered data storage and data retention policies aligned with regulatory requirements
- Maintain zero trust architecture and Zanzibar‑style authorization for scalable, auditable access
- Integrate SSO and manage user authentication and access for end users and engineers
- Lead regular security audits and semi‑annual penetration testing with an assume breach mindset
- Ensure ongoing compliance with ISO 27001, SOC 2 Type 2, GDPR, and related standards
- Provide real time visibility into data access and governance for customers and internal teams
What We're Looking For
- Experience with ISO 27001, SOC 2 Type 2, and GDPR; strong security program mindset
- Knowledge of zero trust design principles and Zanzibar‑like authorization systems
- Hands-on encryption management, BYOK, and key lifecycle management
- Proficiency with SSO integration, access management, and data governance tooling
- Ability to perform threat modeling, risk assessment, and incident response planning
- Collaboration across security, product, and engineering teams
Nice to Have
- Experience with AI governance frameworks or AI platform governance
- Familiarity with tiered storage options, data localization, and cross-region data handling