# Staff/Principal Identity Engineer at Legora

Legora is hiring a Staff/Principal Identity Engineer in New York, United States. It pays $216k-$292k a year and Level rates it Little AI ●○○○; you can [apply on Level](https://jobsbylevel.com/go/89409336-d0ad-4420-a4a4-3d14b9d5fe46).

AI Level 1, AI centrality 32 out of 100. New York City.

## Details

- Company: [Legora](https://jobsbylevel.com/companies/legora)
- AI level: AI Level 1 (score 32 out of 100)
- Location: New York City
- Salary: $216k-$292k
- Posted: October 11, 2026
- Apply: https://jobsbylevel.com/go/89409336-d0ad-4420-a4a4-3d14b9d5fe46

## Description

About Us Legora is redefining how legal work gets done. Not built for lawyers, built with them. We work alongside the world’s best legal teams, who expect excellence, precision, and speed, and we hold ourselves to the same bar. Our AI-native workspace lets legal professionals move faster, think more clearly, and operate with sharper precision. By analysing thousands of documents in minutes and powering end-to-end workflows, we cut through complexity, teams can focus on what matters: judgment, strategy, and outcomes. 2,100+ customers across 80+ countries trust us, including Cleary Gottlieb, Goodwin, Linklaters, White & Case, Dentons, and Barclays. We’ve scaled to $200M+ in ARR , with teams across Europe, North America and APAC, and continue to expand through acquisitions including Qura, Walter AI, Graceview, Cadastral, and Wexler. We partner with world-class performers: including Aaron Judge and the New York Yankees, Ludvig Åberg (and his caddie), and campaigns featuring Jude Law. Joining Legora means three things. We lean in: ownership over titles, outcomes over intentions. We fight for excellence: high standards, direct, ego-free feedback. We grow together: as a team and with our customers. Mission before ego. Everyone contributes. No one coasts. If you’re driven by impact, pace, and raising the bar. This is the place. The role We are looking for a hands-on Staff/Principal Identity Engineer to own Legora's Okta platform and build the security controls that protect our employees, applications, devices and data. This is an individual contributor role with end-to-end responsibility for Okta architecture, engineering, governance and operations. Expert-level Okta capability is the most important requirement. You will set the technical direction, make architecture decisions, build integrations and automation, and remain accountable for how the platform performs in production. You will also engineer controls across SaaS applications, endpoint and device trust, data protection, non-human identities and AI usage. What you will own Full ownership of Okta: Own the platform roadmap, architecture, configuration, security posture, integrations, change management and operational reliability. Set standards for authentication, authorization, administrative access and recovery. Be the final technical escalation point for complex Okta issues and own their resolution. Authentication and application integrations: Design and troubleshoot SSO, SAML, OIDC, OAuth and SCIM integrations. Own phishing-resistant MFA, risk-based authentication, session controls and device-aware access policies. Build secure application onboarding with configuration validation, named owners, approvals and controlled secret handling. Identity lifecycle and access governance: Build reliable joiner, mover and leaver workflows connecting HR systems, Okta, directories and business applications. Own provisioning, entitlement changes and timely revocation, including downstream access and active sessions. Establish access reviews, least-privilege controls, privileged access standards and accountable application ownership. Identity engineering and automation: Build production software using Python and JavaScript, Okta APIs, Workflows and Terraform or other infrastructure-as-code tools. Put configuration and controls under version control with peer review, testing and safe deployment. Design for retries, partial failures, observability, rollback and recovery. Reduce manual work through reliable automation. Non-human identity and agent authorization: Establish ownership, least privilege, credential lifecycle and revocation for service accounts, API tokens, integrations and AI agents. Build authorization controls for agent and MCP access, with clear permission boundaries, approval requirements and audit trails. What you will bring Typically 8-10+ years of relevant experience in identity engineering, IT infrastructure or corporate security, with demonstrated expert-level Okta

The description is cut here. Read the full offer: https://jobsbylevel.com/jobs/staff-principal-identity-engineer-at-legora-9920ef

Source: https://jobsbylevel.com/jobs/staff-principal-identity-engineer-at-legora-9920ef

## Cite this page

Level. https://jobsbylevel.com/jobs/staff-principal-identity-engineer-at-legora-9920ef.

Get job alerts: https://jobsbylevel.com/newsletter
