Security Engineer
Job description
About the role
This role strengthens the protection of sensitive data handled by high-profile legal teams. You will own the design and implementation of security controls that safeguard critical legal workflows and sensitive client information. The position requires a mindset focused on evidence-based analysis and continuous improvement in defensive security practices. You will work closely with cross-functional partners to translate complex security topics into clear, actionable guidance. Success in this role means consistently operating with calm judgment during investigations and high-pressure incidents. The work spans application security, infrastructure security, and governance within a rapidly evolving threat landscape. You will be expected to leverage modern tooling and contribute to a security culture that values rigorous testing and proactive defense. Most importantly, you will ensure that security practices keep pace with company growth and evolving regulatory demands.
Key facts
What you'll do
Examine security events and coordinate incident response to contain threats, guide recovery, and prevent recurrence.
Improve defensive capabilities for cloud infrastructure, third-party integrations, and platform services through optimized threat detection and response mechanisms.
Manage and tune AWS security services, including IAM, Security Hub, GuardDuty, and Config to enforce access control and continuous monitoring.
Create and refine security processes, procedures, and runbooks to keep pace with company growth and evolving risks.
Communicate platform security risks clearly to internal partners, translating technical concepts into language that does not rely on specialized jargon.
Apply programming skills in at least one scripting language, such as Python, and operate comfortably within Linux environments to automate tasks and support security initiatives.
Utilize security tools for vulnerability scanning, host or network detection, or SIEM/SOAR platforms to identify and mitigate potential weaknesses.
Understand the web application security landscape, including the OWASP Top 10, and fundamentals of secure coding to support the development lifecycle.
Ensure authorization to work in the United States is maintained, noting that Everlaw is currently not sponsoring U.S. employment visas for this role.
Requirements
You bring 3+ years of experience from a dedicated security-focused role, demonstrating a consistent track record in security operations.
You have handled security events and incidents from initial triage through full remediation, showing ownership and follow-through.
You apply programming skills in at least one scripting language, such as Python, and work comfortably in Linux environments to support automation and analysis.
You have used security tools for vulnerability scanning, host or network detection, or SIEM/SOAR platforms to detect and respond to threats.
You understand the web application security landscape, including OWASP Top 10, and fundamentals of secure coding to identify and reduce risks.
You are authorized to work in the United States, and Everlaw is currently not sponsoring U.S. employment visas for this role, requiring candidates to already possess the necessary authorization.
You hold at least a Bachelor's degree or equivalent professional experience that demonstrates foundational knowledge relevant to security engineering.
You communicate effectively with both technical and non-technical stakeholders, ensuring that security posture and risks are understood across the organization.
Practical notes
Everlaw is an equal opportunity employer that respects diversity and honors pronoun requests.
Typical interview steps
Security interviews usually include a technical assessment, a threat modeling exercise, and behavioral rounds. Candidates may be asked to review a code sample for vulnerabilities or design a secure system. Practical knowledge and clear risk communication are the core skills. Interviewers often ask how you triage and communicate risk. Showing calm judgment under pressure matters as much as technical depth.
Good to know
Security engineers protect systems and data by designing and improving controls across people, processes, and technology. Common tools in this field include cloud platforms, infrastructure-as-code tools, and security monitoring solutions. Roles in this area often require on-call readiness for incident response and collaboration across engineering and product teams. Security professionals operate within a landscape of constant change, where new threats and new rules emerge every year, making ongoing training and adaptation essential. Most companies invest heavily in training and tooling to ensure their teams can defend against sophisticated adversaries. Written communication of risk is a core skill at senior levels, and the ability to explain complex topics without specialized jargon is highly valued.
Questions to ask
Good questions to ask the employer in the interview: what does success look like in the first six months, how is the team structured, what is the current biggest challenge, and how are decisions made. Asking about growth paths and the review process is also well received. Employers expect questions, and good ones show preparation and an understanding of the role's impact.
Career growth
Security careers grow from analyst or engineer to senior, staff, and leadership roles. Specializations include cloud security, application security, and security operations. Certifications help early; demonstrated impact matters later. Security careers reward specialization and a track record of finding and fixing real issues. The ability to document findings and communicate risk in writing becomes increasingly important as you advance to senior positions. Security engineers often progress by taking on more complex investigations, leading cross-functional initiatives, and mentoring junior colleagues.
About the company
Looking for a remote job? Remote OK® is the #1 Remote Job Platform and has 1,131,503+ remote jobs as a Developer, Designer, Copywriter, Customer Support Rep, Sales Professional, Project Manager and more! Find a career where you can work remotely from anywhere.