About LawYLawY is on a mission: to help legal professionals reclaim their time with AI they actually trust and that understands them.
At LawY, you're not selling generic AI: you're helping legal professionals reclaim their time and deliver better outcomes for their clients and stakeholders. Built by lawyers, we've spent two years listening, learning, and evolving our AI-native workspace. Now it's available as a standalone subscription, expanding from trusted legal research into drafting, contract intelligence, and matter analysis.
You'll be joining at the most exciting inflection point: we've proven product-market fit, our users genuinely love what we've built, and we're scaling a solution that lawyers actually want to adopt. If you want to build something that genuinely helps people do meaningful work better, this is it.
What you'll do
- As a hands-on Information Security & IT Manager, you'd manage the day-to-day security and IT operations.
- You'd work closely with Law
- Y's Engineering, Product and business teams to maintain a secure, reliable and well-managed technology environment.
- You will also work with CORTO Information Security, which will provide broader governance, standards and oversight.
- This is a broad role suited to someone comfortable working across information security, IT operations, cloud security, compliance and risk management.
- Law
- Y operates in a modern cloud and AI-enabled environment.
- Its production platform is hosted with a major cloud provider and uses AI models and services to process information, while its developers use approved AI-assisted development platforms as part of their daily workflows.
- To make this happen you will:
- Manage day-to-day information security and IT operations for Law
- Y. Maintain security controls across cloud, applications, endpoints, identity and SaaS platforms.
- Monitor and respond to security alerts, incidents and vulnerabilities.
- Coordinate remediation activities with Engineering, Product and third-party providers.
- Manage user access, onboarding, offboarding, devices and endpoint security.
- Administer identity and access management and Microsoft 365, including Entra ID, Exchange Online, SharePoint, Defender for Business and relevant security controls.
- Manage User devices through MDM platforms.
- Support and manage enterprise applications, SaaS platforms, licensing, integrations and technology vendors.
- Maintain Law
- Y's network infrastructure and coordinate troubleshooting or improvements with internal teams and specialist providers.
- Support secure software development, architecture reviews and penetration testing.
- Maintain security documentation, risk registers, procedures and asset inventories.
- Support SOC 2, privacy, audits, customer security reviews and compliance activities.
- Manage security and technology vendors.
- Provide regular reporting on security risks, incidents and remediation progress.
- Escalate material risks and incidents to Law
- Y leadership and CORTO Information Security.
What you'll bring
- You will have experience across information security, IT operations or cloud security within a technology or SaaS environment.
- Experience with cloud security, identity and access management, endpoint security and vulnerability management.
- Strong hands-on experience administering Microsoft 365, Entra ID, MDM and Microsoft security tools.
- Experience managing enterprise applications, SaaS platforms and technology vendors.
- A strong understanding of network architecture, connectivity and network security principles.
- Experience supporting incident response and security monitoring.
- A good understanding of secure software development and application security.
- Experience supporting compliance frameworks such as SOC 2 or ISO 270
-
- Familiarity with AWS, Vercel and modern cloud-based and AI-enabled technology environments.
- Strong communication and stakeholder management skills.
- The ability to work independently in a practical, hands-on role.
- A risk-based approach to solving security and technology challenges.
- Even better if you have
- Experience supporting SaaS businesses that use AI platforms in development or production.
- Experience with SIEM, EDR, vulnerability management, GRC or cloud security tools.
- Experience in legal technology, SaaS or another regulated environment.
- Relevant Microsoft 365, endpoint administration, AWS or networking certifications would be advantageous.
- Relevant certifications such as CISSP, CISM, CCSP, Security+, AWS Security Specialty or ISO 270
-
- Law
- Y is an inclusive, people-first company committed to breaking down institutional barriers that keep people from reaching their potential.
- If you meet some, but not all the requirements above, we encourage you to still submit your application.
- Why join Law
- Y? Your work matters.
- We solve real world problems that improve and support local, everyday law firms.
- So they can do their best work for the people in the communities they serve.
- Make an impact.
- You won't be another ‘cog in the wheel' here.
- We give full trust and autonomy for you to be heard, to work on big & complex projects - and to make a real difference.
- Work with a group of authentic, passionate people who love what they do.
- Genuine startup energy - small team, fast decisions, real trajectory, backed by one of the largest legal software companies in the world.
- Flexible and hybrid working.
- We engage, share, and collaborate on ideas and workflows.
- Career and learning opportunities - we move fast and need smart people to get us where we're going.
- We are a scaling business and looking for people who want to grow with us.
- Have fun with us. Celebrations.
- Socials.
- Sports teams.
- Access to sailing and yacht events.
- We value your well-being with additional time off, gym membership and other perks.
- Fast-paced tech environment, if we don't disrupt ourselves someone else will do it!
- Access to LEAP Home - a program unique to the ATI Group to support you in buying your primary residence.