06 Oct
|
Themis Solutions
|
Toronto
06 Oct
Themis Solutions
Toronto
Clio is the global leader in legal AI technology, empowering legal professionals and law firms of every size to work smarter, faster, and more securely. We are transforming the legal experience for all by bettering the lives of legal professionals while increasing access to justice. Summary: The Role Clio is looking to build a dedicated threat intelligence capability. Today, adversary tracking, fraud pattern analysis, and abuse intelligence happen informally across a few teams. This role makes threat intelligence a standing discipline: characterize who is targeting Clio and organizations like it, what they're using, and turn that into work other teams can act on. This is a senior individual-contributor role, where you'll be expected to establish and formalize how Clio tracks adversaries. This is the first hire in a function Clio intends to grow — the practices you establish become the foundation the rest of the team is built on. You will work closely with Clio's internal red team and detection engineer. Threat Intelligence characterizes the adversary — who they are, how they operate, what to watch for. The Red Team takes your prioritized, evidence-backed picture of the threat and decides what to simulate and attack; the detection engineer turns the same picture into detection logic in our SIEM. What We're Protecting Firms From Clio has nearly every piece of data you can conceive: privileged litigation strategy, M&A documents, and trust accounts that can get a lawyer disbarred if they're not protected properly! The Panama Papers breach showed the stakes — 11.5 million client documents left Mossack Fonseca, and the firm shut down two years later.
The legal field is rife with examples where security must be taken seriously: Silent Ransom Group (Luna Moth) has extorted more than 100 US law firms since 2023, using IT-themed vishing calls and, recently, operatives who walk into firm offices posing as IT technicians (FBI advisories, 2025 and 2026) INC Ransom claimed 20 legal-sector victims in 2026, ten of them inside a single 48-hour window Chinese state actors breached Williams & Connolly and Wiley Rein to reach trade, sanctions, and M&A matters; Mandiant estimates 80 of the 100 largest US firms have been hacked since 2011 Most of Clio's customers are solo, small, and mid-size firms — the segment with the highest breach rate (ABA 2025 data) and the least in-house security. At the same time some of the largest legal organizations, including governments, rely on Clio. When you characterize an adversary, you protect tens of thousands of firms that cannot do this work themselves! AI Is the Expectation Clio's security team works with AI every day, and this role is built on that assumption. You'll use AI agents to scale collection, enrichment, triage, and first-draft reporting — and apply your own judgment to everything they produce. The adversary side is part of your beat too: AI-enabled tradecraft belongs in the landscape you cover. If the idea of directing a fleet of agents sounds like how intelligence work should be done, you'll fit perfectly at Clio. A Day in the Life Digging through raw infrastructure data to attribute a phishing kit to a known actor before any vendor report names them Briefing security leadership team on a geopolitical or sector-specific threat trend relevant to legal tech Writing fraud pattern briefs from
📌 Lead Threat Intelligence Engineer (Toronto)
🏢 Themis Solutions
📍 Toronto