This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Everlaw is looking for a Security Engineer. Reporting to the Manager, Security Engineering, you will be a member of the technical security operations team at the company. Security is one of the main strategic pillars at Everlaw, and we are looking for someone to help us execute on that strategy and protect our most valuable asset--our customer data. Everlaw's customers entrust us with some of their most sensitive information, and it takes dedication and care to protect it. Some of the world's most high-profile cases are managed using the Everlaw Platform. We set a high bar to do what's right by our users. Tackling litigation with technology presents deep challenges. Data is spread across distributed systems, stored in varied databases, housed at different physical locations. Keeping our users' data safe requires a passion for learning new technologies because we have to be good custodians no matter whether data flows through a Web application, gets stored in a data warehouse, or is used to train the latest machine learning algorithms. We are dedicated to continuously learning and improving our processes to achieve our mission. Security Engineering supports teams across Everlaw in creating and operating a secure platform that meets the security and compliance requirements of our customers and company. We collaborate, build, and use technology to make it easy to do the right thing. We seek to understand people's needs and strive to protect confidentiality, integrity, and availability of information. At Everlaw, our mission is to promote justice by illuminating truth. Our company culture is open and vibrant and we’re committed to the professional growth of our team members, offering an annual learning and development stipend and regular check-ins with managers regarding career goals. If you’re looking for a place that values passion, integrity, thinking big, and a desire to learn, we’d love to hear from you! Think you’re missing some of the skills and are hesitant to apply? We do not believe in the ‘perfect’ candidate and encourage you to apply if you feel you can bring value to our team. This is a full-time, exempt position located onsite (3 days/week in office) in Oakland, California.
Job Responsibility:
Support the team to drive improvements in our vulnerability management, threat detection, and incident response capabilities, contributing your perspective to help the team grow
Triage security events and respond to security incidents, taking action to contain them, guiding recovery of normal operations, and reducing the likelihood of recurring threats
Strengthen threat detection and response systems that safeguard both our cloud infrastructure, third-party integrations, and platform services
Develop and refine security processes, procedures, and runbooks that allow our security posture to scale as the company grows
Manage and tune AWS security services (IAM, Security Hub, GuardDuty, Config) for effective threat detection, access control, and continuous monitoring
Collaborate with Engineering, Engineering Operations, Corporate Security, and GRCT teams to help meet our operational security commitments by probing for vulnerabilities, assessing risk, and advising on how to respond to them
Advise other engineers and partners on building a secure platform by leading threat modeling sessions, conducting security design reviews, and reviewing code and configuration changes for security concerns
Proactively solve security challenges and foster a security mindset with innovative, security-conscious coworkers across Everlaw
Requirements:
At least 1-3 years of experience working in a security-focused role
Experience in handling security events and incidents from initial triage through to remediation
Programming skills in at least one scripting language (like Python) and are comfortable navigating a Linux environment
Experience with security tools like vulnerability scanners (Nessus/Trivy), HIDS/NIDS (Wazuh/Zeek), and SIEM/SOAR platforms (Splunk/ELK/Datadog)
Understand the vulnerability lifecycle and have experience detecting, prioritizing, and remediating vulnerabilities
Written detection rules and response processes for security specific events
Can explain technical concepts without jargon, keeping security relatable so that others can solve problems with your support
Balance strong protections with enabling people to do their work, finding ways to improve security without blocking innovation
Authorized to work in the United States without restrictions
Nice to have:
Previous experience with SaaS environments and distributed systems
Programming skills in at least one compiled language (like Java)
Experience with AWS, Terraform, Ansible, git, and other infrastructure, development, and operations tools
What we offer:
Equity program
401(k) retirement plan with company matching
Health, dental, and vision
Flexible Spending Accounts for health and dependent care expenses
Paid parental leave and approximately 10 days (80 hours) per year of sick leave
Seventeen paid vacation days plus 11 federal holidays
Membership to Modern Health to help employees prioritize mental health and wellness
Annual allocation for Learning & Development opportunities and applicable professional membership dues
Company-sponsored life and disability insurance
Work in Downtown Oakland, just steps from the BART line and dozens of restaurants
You will get a powerful Linux laptop and be able to customize your desk setup
Bond over team lunches and out-of-the-box events
Time off for company-sponsored volunteer events and 4 paid hours per quarter to volunteer at a charitable organization of your choice
Take advantage of learning and career development opportunities