1,184,220open jobs
66,514companies
212,240added this week
Browse all
Salary
≈ $97k – $251k per year (Estimated)
Location
Hybrid (Vancouver, Toronto, Calgary, Canada)
Seniority
Staff
Employment
Full-Time

Confirmed on the employer's own hiring board on Oct 4, 2026. First seen by Alion on Oct 2, 2026.

Overview
Company
Impact
Profile match
Clio is a legal technology company headquartered in Burnaby, British Columbia, that provides cloud-based practice management, client intake, billing, payments and AI tools for law firms and legal professionals. Founded in 2008, it has grown through acquisitions such as CalendarRules and the legal research platform vLex, and runs offices in Vancouver, Calgary, Toronto, Dublin, London and other markets while serving firms from solo practices to large enterprises. Its openings span software development and machine learning, product management and design, customer onboarding and support, account executives, legal content and marketing roles.

Clio is the global leader in legal AI technology, empowering legal professionals and law firms of every size to work smarter, faster, and more securely.

We are transforming the legal experience for all by bettering the lives of legal professionals while increasing access to justice.

Summary:

The Role

Clio is looking to build a dedicated threat intelligence capability. Today, adversary tracking, fraud pattern analysis, and abuse intelligence happen informally across a few teams. This role makes threat intelligence a standing discipline: characterize who is targeting Clio and organizations like it, what they're using, and turn that into work other teams can act on.

This is a senior individual-contributor role, where you'll be expected to establish and formalize how Clio tracks adversaries. This is the first hire in a function Clio intends to grow - the practices you establish become the foundation the rest of the team is built on.

You will work closely with Clio's internal red team and detection engineer. Threat Intelligence characterizes the adversary - who they are, how they operate, what to watch for. The Red Team takes your prioritized, evidence-backed picture of the threat and decides what to simulate and attack; the detection engineer turns the same picture into detection logic in our SIEM. As the detection platform matures, your intelligence requirements shape what gets built.

What We're Protecting Firms From

Clio has nearly every piece of data you can conceive: privileged litigation strategy, M&A documents, and trust accounts that can get a lawyer disbarred if they're not protected properly! The Panama Papers breach showed the stakes - 11.5 million client documents left Mossack Fonseca, and the firm shut down two years later. The legal field is rife with examples where security must be taken seriously:

  • Silent Ransom Group (Luna Moth) has extorted more than 100 US law firms since 2023, using IT-themed vishing calls and, recently, operatives who walk into firm offices posing as IT technicians (FBI advisories, 2025 and 2026)
  • INC Ransom claimed 20 legal-sector victims in 2026, ten of them inside a single 48-hour window
  • Chinese state actors breached Williams & Connolly and Wiley Rein to reach trade, sanctions, and M&A matters; Mandiant estimates 80 of the 100 largest US firms have been hacked since 2011

Most of Clio's customers are solo, small, and mid-size firms - the segment with the highest breach rate (ABA 2025 data) and the least in-house security. At the same time some of the largest legal organizations, including governments, rely on Clio. When you characterize an adversary, you protect tens of thousands of firms that cannot do this work themselves!

AI Is the Expectation:

Clio's security team works with AI every day, and this role is built on that assumption. You'll use AI agents to scale collection, enrichment, triage, and first-draft reporting - and apply your own judgment to everything they produce. The adversary side is part of your beat too: AI-enabled tradecraft belongs in the landscape you cover. If the idea of directing a fleet of agents sounds like how intelligence work should be done, you'll fit perfectly at Clio.

A Day in the Life

  • Digging through raw infrastructure data to attribute a phishing kit to a known actor before any vendor report names them
  • Briefing security leadership team on a geopolitical or sector-specific threat trend relevant to legal tech
  • Writing fraud pattern briefs from account-abuse signals and handing the Trust (anti-abuse) function specific patterns to detect
  • Working with our payment operations group to identify fraud patterns and rings within Clio Payments
  • Mentoring newer analysts on how to separate a credible early indicator from noise
  • Proposing a new data source or tracking method because the current one is missing a class of activity

What You'll Do

Building the program

  • Define and maintain Clio's Priority Intelligence Requirements with stakeholders across Security, Trust, Payments, and leadership, then run the full intelligence lifecycle against them - from requirements through dissemination and feedback
  • Stand up Clio's threat intelligence platform and make it the system of record for tracked actors, campaigns, and indicators
  • Shape vendor purchases and tooling rollouts - OSINT and dark-web monitoring, feeds, enrichment - as the program's collection needs take form
  • Measure whether intelligence changes outcomes: detection coverage in the SIEM (Splunk, ELK/OpenSearch), Red Team campaign success grounded in your reporting, and time-to-detect on incidents with prior intel coverage

Intelligence production

  • Track external threat actors, techniques, and infrastructure relevant to legal tech and Clio's customer base
  • Produce intelligence at three tiers: tactical indicators and TTPs for detection, operational campaign briefs for security leadership, and strategic landscape assessments for executives
  • Establish and refine Clio's methodology for tracking adversary campaigns, rather than running someone else's playbook
  • Produce original research: infrastructure hunting from raw data, malware and campaign attribution
  • Analyze fraud and abuse patterns and insider-threat signals, and turn them into briefs the Trust (anti-abuse) function can act on
  • Track BEC and trust-account wire-fraud tradecraft targeting law firms, and feed it into fraud detection for Clio Payments
  • Assess coordinated disclosure and patch-storm events for real exploitation urgency

Feeding other teams

  • Hand Red Team a prioritized, evidence-backed list of techniques worth simulating
  • Hand our detection engineer intel-backed detection requirements
  • Brief security leadership directly, in addition to the SOC and engineering teams
  • Alert Payment Operations of external signals: tracked actors, fraud rings, known malicious domains/IPs, etc. to filter fraud from our payments business before they can act

External relationships

  • Manage commercial threat-intel feed vendors and evaluate new ones against cost and signal quality
  • Participate in industry intel-sharing groups and represent Clio in those relationships
  • Collaborate and code with the blue team on defensive remediations

What You Bring

  • 5+ years in threat intelligence or a closely adjacent function, with original research you can point to
  • Experience establishing or scaling a security function/team from the ground up, not just operating inside an existing one. Self-starter.
  • Scripting ability (Ruby, Python, or similar) for building, upgrading, and maintaining automation
  • Fluency with MITRE ATT&CK, the Diamond Model, and structured analytic techniques such as Analysis of Competing Hypotheses, applied in your own analysis
  • Track record of establishing or materially improving a tracking methodology someone else now uses
  • Comfort briefing both technical teams and director+ level, and adjusting the message for each
  • Ability to turn raw intelligence into a specific, actionable ask for another team - a detection to write, a technique to simulate, a vendor risk to flag
  • Fluency with AI tooling in analytical work - agents for collection, enrichment, and drafting - and the judgment to validate what they produce
  • Experience mentoring more junior analysts

Bonus Points

  • Existing relationships in industry intel-sharing communities
  • Experience with fraud or insider-threat analysis in addition to external threat tracking, or financial services cybercrime experience
  • Familiarity with the legal-tech or professional-services threat landscape, or ability to build that context quickly
This role is a backfill for an existing position.

What you will find here:

Compensation is one of the main components of Clio’s Total Rewards Program. We have developed a series of programs and processes to ensure we are creating fair and competitive pay practices that form the foundation of our human and high-performing culture.

Some highlights of our Total Rewards program include:

  • Competitive, equitable salary with top-tier health benefits, dental, and vision insurance

  • Hybrid work environment, with expectation for local Clions (Vancouver, Calgary, Toronto, Dublin, London, New York City and Sydney) to be in office min. twice per week.

  • Flexible time off policy, with an encouraged 20 days off per year.

  • $2000 annual counseling benefit

  • RRSP matching and RESP contribution

  • Clioversary recognition program with special acknowledgement at 3, 5, 7, and 10 years

The expected salary range for this role is $157,300 to $212,800 CAD. Initial placement within the range is informed by geographic region, experience, and skillset, with room to progress as impact and tenure grow. Final offer amounts will vary based on candidate profile.

Diversity, Inclusion, Belonging and Equity (DIBE) & Accessibility

Our team shows up as their authentic selves, and are united by our mission. We are dedicated todiversity, equity and inclusion. We pride ourselves in building and fostering an environment where our teams feel included, valued, and enabled to do the best work of their careers, wherever they choose to log in from. We believe that different perspectives, skills, backgrounds, and experiences result in higher-performing teams and better innovation. We are committed to equal employment and we encourage candidates from all backgrounds to apply.

Clio provides accessibility accommodations during the recruitment process. Should you require any accommodation, please let us know and we will work with you to meet your needs.

Learn more about our culture atclio.com/careers

We're a Human and High Performing AI company, meaning we use artificial intelligence to improve all of our operations. In recruitment, AI helps us streamline the process for greater efficiency. However, we've built our systems to ensure that a human always reviews AI-generated output, and we never make automated hiring decisions.

Disclaimer: We only communicate with candidates through official @clio.com email addresses.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
1,184,220 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
Vancouver
≈ $91k – $262k per year (Estimated) • In office • 10+ years exp • Bachelor's Degree • Toronto
AI/ML
AI Agents
DevOps
Incident Management
IAM
Cybersecurity
Microsoft Entra ID
Active Directory
PKI
Apply
≈ $79k – $210k per year (Estimated) • In office • Contractor • Montreal
Apply
≈ $85k – $196k per year (Estimated) • Hybrid • Full-Time • 7+ years exp • Bachelor's Degree • Montreal
JavaScript
Java
SQL
Node JS
Java
Maven
Gradle
DevOps
Azure DevOps
Kustomize
Azure
CI/CD
ArgoCD
Jenkins
Kubernetes
Tekton
GitHub
Unix
Cybersecurity
CyberArk
Management
Scrum
Apply
$41k – $59k per year • In office • Full-Time • 5+ years exp • Bachelor's Degree • Toronto
Cybersecurity
Wireshark
Metasploit
Nmap
Nessus
John the Ripper
PCI DSS
Apply
$65k – $85k per year • Equity • Hybrid • Full-Time • 8+ years exp • Bachelor's Degree • Saint-Laurent
Management
SharePoint
Agile
Scrum
Microsoft Office
Apply
≈ $19k – $45k per year (Estimated) • In office • Full-Time • Bachelor's Degree • Makati
Python
DevOps
Ansible
GCP
Azure
AWS
TCP/IP
VPN
VLAN
BGP
OSPF
MPLS
Apply
≈ $60k – $116k per year (Estimated) • In office • 2+ years exp • Associate's Degree • United States
Python
PowerShell
Bash
DevOps
Red Hat
VMWare
Linux
Windows
Cybersecurity
Qualys Cloud Platform
Tanium
Active Directory
Management
ITIL
Apply
$82k – $108k per year • In office • 2+ years exp • Bachelor's Degree • Princeton
Python
C++
AI/ML
OpenCV
NumPy
DevOps
Linux
Apply
$160k – $225k per year • Remote (United States) • 8+ years exp • Bachelor's Degree
AI/ML
AI Agents
Agentic Workflows
Apply
$120k – $165k per year • Remote (United States) • 5+ years exp • Bachelor's Degree
AI/ML
AI Agents
Agentic Workflows
Apply
≈ $90k – $208k per year (Estimated) • Hybrid • Full-Time • 5+ years exp • Burnaby • Toronto • Calgary
Python
JavaScript
PowerShell
Node JS
Node JS
Commander.js
AI/ML
LLM Guardrails
Agentic Workflows
Cybersecurity
ISO 27001
PCI DSS
SOC 2
FedRAMP
SIEM
DLP
Management
Google Workspace
Apply
≈ $59k – $133k per year (Estimated) • Hybrid • Full-Time • 2+ years exp • Burnaby • Toronto • Calgary
Python
Cybersecurity
Okta
ISO 27001
SOC 2
SIEM
DLP
Management
Google Workspace
Apply
$271k – $406k per year • Hybrid • Full-Time • Dublin • London
Apply
$111k – $150k per year • Hybrid • Full-Time • 5+ years exp • Bachelor's Degree • New York
Management
Slack
Microsoft Office
Apply
≈ $42k – $93k per year (Estimated) • Hybrid • Full-Time • Barcelona
Python
Ruby
Ruby
Ruby on Rails
Apply
$97k – $162k per year • Equity • In office • Full-Time • 3+ years exp • Bachelor's Degree • Vancouver
Python
Java
Ruby
C#
C++
C#
.NET
AI/ML
AWS Bedrock
Amazon SageMaker
DevOps
AWS
TCP/IP
DNS
Cybersecurity
Threat Modeling
Apply
$76k – $126k per year • Equity • In office • Full-Time • 2+ years exp • Bachelor's Degree • Vancouver
AI/ML
Amazon SageMaker
DevOps
CI/CD
Cybersecurity
Threat Modeling
Management
Agile
Apply
≈ $55k – $133k per year (Estimated) • In office • Vancouver
Apply
≈ $99k – $216k per year (Estimated) • In office • Full-Time • 10+ years exp • Vancouver
DevOps
Azure
AWS
IAM
Cybersecurity
Okta
CyberArk
ISO 27001
SOC 2
Zero Trust
Microsoft Entra ID
Active Directory
Management
Agile
Scrum
Apply
≈ $82k – $171k per year (Estimated) • In office • 6+ years exp • Vancouver
Design
Figma
Apply
See all jobs
This is one of many
1,184,220 more open roles from verified company boards, updated every day.