Senior Security Engineer
Listed on 2026-07-08
-
IT/Tech
Cybersecurity
Overview
Cleary Gottlieb is a pioneer in globalizing the legal profession. We have 14 offices in major financial centers around the world, but we operate as a single, integrated global partnership and not as a U.S. firm with a network of overseas locations. The firm employs approximately 1,100 lawyers from more than 50 countries.
Since 1946 our lawyers and staff have worked across practices, industries, jurisdictions, and continents to provide clients with simple, actionable approaches to their most complex legal and business challenges, whether domestic or international. We support every client relationship with intellectual agility, commercial acumen, and a human touch.
As a Senior Security Engineer at Cleary Gottlieb, you will play a crucial role in developing and maintaining the firm's cybersecurity infrastructure, as well as guide the safe implantation of cloud and AI systems. This role is an excellent opportunity to stay on the cutting edge by learning about and the latest trends in Agentic Security, Data Security Posture Management, and Cloud.
This role includes hands on design and administration of the Microsoft 365 Security stack (Defender for Endpoint, Identity, Cloud Apps, and O365) as well as Azure, Entra , Sentinel, Purview and much more. The Senior Security Engineer will be essential to our team’s success as they contribute across our hybrid environment and lead assigned technical projects. This individual will analyze, research, and make recommendations on Cleary's existing designs and strategies, as well as the business practices that may bear security risk.
Cleary Gottlieb is a preeminent law firm that prides itself on providing an extremely collaborative and collegial environment that is perfect for your career growth. We are leading the legal industry in the use of cloud and AI technologies and would love for you to join our team. We offer unmatched flexibility for hybrid work as well as providing a lovely office downtown to meet and work alongside your peers in Information Technology.
ResponsibilitiesAI and Agentic Security:
- Lead the Firm’s strategy, design, and implementation of scalable AI security and agentic security controls.
- Work closely with the Firm’s IT and AI acceleration teams to onboard newly developed AI use cases in a security manner, including end to end Dev Sec Ops and CSPM tooling.
Cloud Security:
- Design, implement, and maintain a secure and resilient cloud architecture, encompassing Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS) solutions. This includes Azure, AWS, Office
365, and all manner of SaaS applications. - Design and build continuous audit and alerting capabilities in our cloud environments using native toolsets.
Identity and Access Management:
- Develop and implement robust identity and access management strategies for cloud environments, ensuring proper authentication and authorization controls.
- Monitor and manage user access permissions, following the principle of least privilege.
Data Protection:
- Use leading edge Microsoft 365 Security and Purview technologies to establish and enforce data protection policies to safeguard sensitive information.
- Monitor for data leakage to and from the cloud and on prem.
Incident Response:
- Lead incident response efforts for security incidents, coordinating with internal and external stakeholders.
- Implement logging and monitoring solutions to detect and respond to security events in real-time.
Security Infrastructure Management:
- Design, implement, and manage security infrastructure to safeguard the firm's networks, systems, and applications.
- Conduct regular security assessments and vulnerability scans to identify and address potential risks.
- Incident Response and Investigation
- Lead incident response efforts and conduct thorough investigations in the event of security incidents or breaches.
- Collaborate with legal and IT teams to ensure proper documentation and reporting of security incidents.
Collaboration and Communication
- Work with key stakeholders and internal IT contacts to conduct risk assessments against new technologies being considered for use. Formally document these risk…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).