Security & Engineering
Security Engineer
About the role
Crimson is the AI case intelligence platform for litigation and arbitration. We help disputes teams at leading law firms understand large case files, test arguments and produce high-quality work grounded in the full matter record.
Crimson is enterprise-grade by design. We are SOC 2 Type II attested, encrypt data in transit and at rest, and maintain rigorous controls across our product, infrastructure and operations. Security is embedded in how we build and operate because leading law firms trust Crimson with highly sensitive case information.
You will work closely with the founders and engineering team to own the continued evolution of our security programme. Combining hands-on delivery with clear judgement about risk, you will ensure our security posture keeps pace with rapid product development, growing enterprise adoption and expansion across the UK and US.
What you'll do
- Own and continuously evolve Crimson's security roadmap across application, cloud, identity, data and corporate systems
- Partner with engineers on threat modelling, architecture reviews and secure design for new AI and document-processing features
- Operate and automate our vulnerability management, security testing, secrets management, access controls, logging and detection capabilities
- Maintain and exercise our incident response programme, including playbooks, simulations, investigations and continuous learning
- Coordinate independent penetration testing and represent Crimson's security posture in customer security reviews
- Maintain the controls and evidence supporting Crimson's SOC 2 Type II attestation and enterprise customer requirements
- Embed practical security guidance and tooling into a fast-moving engineering environment
What we're looking for
- Strong hands-on experience securing a modern cloud-hosted SaaS product
- A solid grounding in application security, cloud security, identity and incident response
- The ability to review code and architecture, automate controls and work directly with product engineers
- Clear communication with both technical teams and security stakeholders at major law firms
- High ownership, sound risk judgement and comfort operating in an early-stage environment
Especially useful
- Experience with security in legal technology, fintech or another high-trust B2B environment
- Experience with AI systems, document pipelines or multi-tenant data platforms
- Familiarity with SOC 2, ISO 27001, GDPR or enterprise security procurement
The opportunity
Crimson is backed by Y Combinator and other leading investors and is already used by litigation teams in the UK and US. You will join a small, multidisciplinary team with direct access to customers, real ownership and the chance to help build a defining company in legal AI.
This is a full-time role based in London or New York. We work together in person at least four days a week and offer a competitive salary plus meaningful equity.
Join the team
Help build the future of litigation
Email your CV or LinkedIn profile and a short note explaining why this role and Crimson are a strong fit.
Apply now