Lead Application Security Engineer
Listed on 2026-06-02
-
IT/Tech
Cybersecurity, Systems Engineer
About Eve
Eve is redefining legal technology for plaintiff law firms, and we're building the team that will take us there. We help firms handle more cases, recover more for clients, and grow with AI that works across every stage of a case, from intake through resolution. The next generation of great plaintiff firms will be AI‑Native, and Eve is how they get there.
But what makes Eve different isn't just the product. It's how we build it. If you're someone who takes ownership, stays curious, and wants to build AI that's already changing how law is practiced, this is where you belong.
Product‑market fit: Eve is trusted by over 1000+ law firms, and we’re growing fast.
Backed by top investors: We’ve raised over $160M from world‑class partners including Spark Capital, Andreessen Horowitz (A16z), Menlo Ventures, and Lightspeed.
Built by a world‑class team: Engineers, designers, and operators from places like Scale, Meta, Airbnb, Cruise, Square, Rubrik, and Lyft are building Eve from the ground up.
AI‑Native from day one: We’re on the bleeding edge of AI, collaborating directly with teams at OpenAI and Anthropic to build best‑in‑class AI workflows tailored for legal work.
Explosive growth: We are growing 2X revenue Quarter over Quarter.
As a Security Engineer at Eve, you'll help build the security foundation for an AI‑native product used by law firms handling highly sensitive legal and client data. This is a hands‑on engineering role for someone who wants to build, not just audit. You'll work directly with product, engineering, infrastructure, and AI teams to make security a practical advantage across the company.
You’ll own high‑impact security work across application security, cloud infrastructure, identity and access, secure SDLC, vendor risk, AI security, and incident readiness. You'll review designs, write code, build automation, harden systems, and help engineers ship quickly without compromising trust. A key part of the role is staying current with the evolving security landscape, especially AI‑enabled offensive and defensive techniques, and translating that judgment into practical roadmap recommendations that keep Eve ahead of emerging risks.
WhatYou'll Do
- Build and scale Eve's product and application security program across design reviews, threat modeling, code review, vulnerability management, and secure deployment.
- Partner with engineering teams to secure AI‑native workflows, including data handling, prompt‑injection risk, model/tool access, and sensitive legal information flows.
- Track emerging security trends, including red‑team AI‑based offensive tactics and blue‑team AI‑based defensive tactics where applicable, and translate them into pragmatic product and engineering roadmap recommendations.
- Develop practical defenses for AI‑enabled abuse cases such as prompt injection, model/tool misuse, data exfiltration, unsafe agent behavior, and sensitive legal data exposure.
- Develop internal security tooling and automation for areas like dependency scanning, secrets detection, access review, abuse detection, and security workflow triage.
- Review architecture and product changes for security risks, then help implement pragmatic fixes directly in the codebase when needed.
- Strengthen cloud, infrastructure, and deployment security across identity, permissions, network boundaries, CI/CD, monitoring, and incident response.
- Build security practices that help Eve move faster: clear standards, lightweight processes, reusable libraries, and guardrails that fit how engineers actually work.
- Support compliance and customer trust efforts by helping translate Eve's security posture into clear, accurate technical evidence.
- Stay close to the product and customers so security decisions reflect real user workflows, business needs, and the sensitivity of legal work.
- Technical Depth: 5+ years of experience in application security, including significant time spent writing and reviewing code.
- Software Engineering
Skills:
Proficiency in more than one major coding language. You should be comfortable contributing directly to the codebase. - Cloud & Containers: Practical experience securing cloud environments (AWS…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).