Staff/Principal Identity Engineer

Location TBD·Posted today
aisaasjavascriptpythonterraform
About Us Legora is redefining how legal work gets done. Not built for lawyers, built with them. We work alongside the world’s best legal teams, who expect excellence, precision, and speed, and we hold ourselves to the same bar. Our AI-native workspace lets legal professionals move faster, think more clearly, and operate with sharper precision. By analysing thousands of documents in minutes and powering end-to-end workflows, we cut through complexity, teams can focus on what matters: judgment, strategy, and outcomes. 2,100+ customers across 80+ countries trust us, including Cleary Gottlieb, Goodwin, Linklaters, White & Case, Dentons, and Barclays. We’ve scaled to $200M+ in ARR , with teams across Europe, North America and APAC, and continue to expand through acquisitions including Qura, Walter AI, Graceview, Cadastral, and Wexler. We partner with world-class performers: including Aaron Judge and the New York Yankees, Ludvig Åberg (and his caddie), and campaigns featuring Jude Law. Joining Legora means three things. We lean in: ownership over titles, outcomes over intentions. We fight for excellence: high standards, direct, ego-free feedback. We grow together: as a team and with our customers. Mission before ego. Everyone contributes. No one coasts. If you’re driven by impact, pace, and raising the bar. This is the place. The role We are looking for a hands-on Staff/Principal Identity Engineer to own Legora's Okta platform and build the security controls that protect our employees, applications, devices and data. This is an individual contributor role with end-to-end responsibility for Okta architecture, engineering, governance and operations. Expert-level Okta capability is the most important requirement. You will set the technical direction, make architecture decisions, build integrations and automation, and remain accountable for how the platform performs in production. You will also engineer controls across SaaS applications, endpoint and device trust, data protection, non-human identities and AI usage. What you will own Full ownership of Okta: Own the platform roadmap, architecture, configuration, security posture, integrations, change management and operational reliability. Set standards for authentication, authorization, administrative access and recovery. Be the final technical escalation point for complex Okta issues and own their resolution. Authentication and application integrations: Design and troubleshoot SSO, SAML, OIDC, OAuth and SCIM integrations. Own phishing-resistant MFA, risk-based authentication, session controls and device-aware access policies. Build secure application onboarding with configuration validation, named owners, approvals and controlled secret handling. Identity lifecycle and access governance: Build reliable joiner, mover and leaver workflows connecting HR systems, Okta, directories and business applications. Own provisioning, entitlement changes and timely revocation, including downstream access and active sessions. Establish access reviews, least-privilege controls, privileged access standards and accountable application ownership. Identity engineering and automation: Build production software using Python and JavaScript, Okta APIs, Workflows and Terraform or other infrastructure-as-code tools. Put configuration and controls under version control with peer review, testing and safe deployment. Design for retries, partial failures, observability, rollback and recovery. Reduce manual work through reliable automation. Non-human identity and agent authorization: Establish ownership, least privilege, credential lifecycle and revocation for service accounts, API tokens, integrations and AI agents. Build authorization controls for agent and MCP access, with clear permission boundaries, approval requirements and audit trails. What you will bring Typically 8-10+ years of relevant experience in identity engineering, IT infrastructure or corporate security, with demonstrated expert-level Okta ownership. We assess the depth of your experience and the scope of your ownership rather than a fixed years-of-experience minimum. Expert-level, hands-on Okta experience, including architecture, complex integrations, lifecycle management, authentication policies, governance and production troubleshooting. You have personally owned an enterprise Okta environment and can explain the decisions, tradeoffs and outcomes of your work. Deep understanding of SAML, OIDC, OAuth, SCIM, federation, authentication and authorization. You can diagnose integration failures, unsafe access paths and incomplete deprovisioning across interconnected systems. Demonstrated production engineering with Python and/or JavaScript, APIs and Terraform or equivalent infrastructure as code. You can show how you test, deploy, monitor and recover your automation. Experience delivering broader corporate security controls across SaaS, endpoints, device trust and data protection, with the judgment to prioritize risks and carry remediation through to completion. Independent technical ownership: define the technical roadmap, lead complex work across teams, make sound security decisions and remain accountable for production outcomes. Communicate directly, work constructively through disagreement and raise the technical standard around you. Useful additional experience HR-driven identity modernization, Workday integrations, Active Directory retirement or directory consolidation. Self-service application onboarding. Identity governance and privileged access. Non-human identity, AI-agent or MCP security. Okta certifications are useful, but demonstrated engineering depth and ownership matter most. What’s In It For You Global collaboration: Partner with teams and clients across Europe, APAC, and North America. Competitive package: Comprehensive salary, benefits, and tools for success. Meaningful work: Your efforts shape how thousands of lawyers use AI daily. In-person environment: Union Square office designed for ambitious builders and company provided lunch daily. Benefits & Perks: We invest in our people with a comprehensive, thoughtfully designed benefits package: Medical, Dental & Vision Multiple medical plan options through Aetna and Kaiser Permanente HSA or Healthcare FSA (based on plan selection) Dental plans via MetLife Vision plans via Vision Care Family Support Generous parental leave Free access to Maven Clinic Dependent Care FSA Free One Medical membership for employees and dependents Additional Perks Pre-tax commuter benefits Life Insurance + STD/LTD 401(K) with generous company match Unlimited PTO Robust voluntary benefits, including identity protection (via Aura), legal coverage via MetLife, pet savings programs, and more Legora is an Equal Opportunity Employer At Legora, we believe great teams are built on diversity of thought and experience. We’re proud to be an equal opportunity employer and committed to creating an inclusive, high-performance culture where everyone can do their best work. We welcome people of all backgrounds and don’t discriminate based on race, color, religion, national origin, gender, gender identity or expression, sexual orientation, age, disability, veteran status, or any other characteristic protected by law.