About LawY
LawY is on a mission: to help legal professionals reclaim their time with AI they actually trust and that understands them.
At LawY, you're not selling generic AI: you're helping legal professionals reclaim their time and deliver better outcomes for their clients and stakeholders. Built by lawyers, we've spent two years listening, learning, and evolving our AI-native workspace. Now it’s available as a standalone subscription, expanding from trusted legal research into drafting, contract intelligence, and matter analysis.
You'll be joining at the most exciting inflection point: we've proven product-market fit, our users genuinely love what we've built, and we're scaling a solution that lawyers actually want to adopt. If you want to build something that genuinely helps people do meaningful work better, this is it.
What you’ll do
As a hands-on Information Security & IT Manager, you’d manage the day-to-day security and IT operations. You’d work closely with LawY’s Engineering, Product and business teams to maintain a secure, reliable and well-managed technology environment. You will also work with CORTO Information Security, which will provide broader governance, standards and oversight.
This is a broad role suited to someone comfortable working across information security, IT operations, cloud security, compliance and risk management.
LawY operates in a modern cloud and AI-enabled environment. Its production platform is hosted with a major cloud provider and uses AI models and services to process information, while its developers use approved AI-assisted development platforms as part of their daily workflows.
To make this happen you will:
-
Manage day-to-day information security and IT operations for LawY.
-
Maintain security controls across cloud, applications, endpoints, identity and SaaS platforms.
-
Monitor and respond to security alerts, incidents and vulnerabilities.
-
Coordinate remediation activities with Engineering, Product and third-party providers.
-
Manage user access, onboarding, offboarding, devices and endpoint security.
-
Administer identity and access management and Microsoft 365, including Entra ID, Exchange Online, SharePoint, Defender for Business and relevant security controls.
-
Manage User devices through MDM platforms.
-
Support and manage enterprise applications, SaaS platforms, licensing, integrations and technology vendors.
-
Maintain LawY’s network infrastructure and coordinate troubleshooting or improvements with internal teams and specialist providers.
-
Support secure software development, architecture reviews and penetration testing.
-
Maintain security documentation, risk registers, procedures and asset inventories.
-
Support SOC 2, privacy, audits, customer security reviews and compliance activities.
-
Manage security and technology vendors.
-
Provide regular reporting on security risks, incidents and remediation progress.
-
Escalate material risks and incidents to LawY leadership and CORTO Information Security.
What you’ll bring
You will have experience across information security, IT operations or cloud security within a technology or SaaS environment.
-
Experience with cloud security, identity and access management, endpoint security and vulnerability management.
-
Strong hands-on experience administering Microsoft 365, Entra ID, MDM and Microsoft security tools.
-
Experience managing enterprise applications, SaaS platforms and technology vendors.
-
A strong understanding of network architecture, connectivity and network security principles.
-
Experience supporting incident response and security monitoring.
-
A good understanding of secure software development and application security.
-
Experience supporting compliance frameworks such as SOC 2 or ISO 27001.
-
Familiarity with AWS, Vercel and modern cloud-based and AI-enabled technology environments.
-
Strong communication and stakeholder management skills.
-
The ability to work independently in a practical, hands-on role.
-
A risk-based approach to solving security and technology challenges.
Even better if you have
-
Experience supporting SaaS businesses that use AI platforms in development or production.
-
Experience with SIEM, EDR, vulnerability management, GRC or cloud security tools.
-
Experience in legal technology, SaaS or another regulated environment.
-
Relevant Microsoft 365, endpoint administration, AWS or networking certifications would be advantageous.
-
Relevant certifications such as CISSP, CISM, CCSP, Security+, AWS Security Specialty or ISO 27001.
LawY is an inclusive, people-first company committed to breaking down institutional barriers that keep people from reaching their potential. If you meet some, but not all the requirements above, we encourage you to still submit your application.
Why join LawY?
- Your work matters. We solve real world problems that improve and support local, everyday law firms. So they can do their best work for the people in the communities they serve.
- Make an impact. You won’t be another ‘cog in the wheel’ here. We give full trust and autonomy for you to be heard, to work on big & complex projects – and to make a real difference.
- Work with a group of authentic, passionate people who love what they do.
- Genuine startup energy - small team, fast decisions, real trajectory, backed by one of the largest legal software companies in the world.
-
Flexible and hybrid working. We engage, share, and collaborate on ideas and workflows.
- Career and learning opportunities - we move fast and need smart people to get us where we're going. We are a scaling business and looking for people who want to grow with us.
-
Have fun with us. Celebrations. Socials. Sports teams. Access to sailing and yacht events.
- We value your well-being with additional time off, gym membership and other perks.
- Fast-paced tech environment, if we don't disrupt ourselves someone else will do it!
-
Access to LEAP Home - a program unique to the ATI Group to support you in buying your primary residence.