Staff Software Engineer, Security
San Francisco, CA - USA
Department:
Job Summary
At Harvey were transforming how legal and professional services operate. By combining frontier agentic AI an enterprise-grade platform and deep domain expertise were reshaping how critical knowledge work gets done for decades to come.
This is a rare chance to help build a generational company at a true inflection point. We have strong product-market fit and world-class investor support. Were scaling fast and defining a new category in real time. The work is ambitious the bar is high and the opportunity for growth personal professional and financial is unmatched.
Our team moves fast takes ownership and is deeply committed to the mission operating with intensity staying close to our customers and pushing each other for excellence. We live by three values: Decisiveness Simplicity and Jobs Not Finished. We act quickly on clear judgment over perfect information we believe simplicity is what scales and were never satisfied with where we are. If you want to do the best work of your career alongside people who share that drive wed love to build with you.
At Harvey the future of professional services is being written today and were just getting started.
As a Staff Software Engineer on the Security Engineering team you will be a founding member of the team and define/drive the technical strategy for the security foundations that protect Harveys workforce infrastructure production systems and customer data.
You will lead the evolution of identity authorization secrets privileged access and secure developer tooling across multiple engineering teams. You will operate at the boundary of security infrastructure and product engineeringturning ambiguous risk and business requirements into durable platforms clear architectural direction and measurable improvements in security outcomes.
This role is hands-on but its primary leverage comes through technical direction platform adoption cross-functional alignment and enabling other engineers to build securely by default.
Define Harveys multi-year technical strategy for identity authorization secrets management privileged access or secure developer tooling.
Design and build complex security systems from greenfield writing the code instrumenting it and owning it in production.
Identify the highest-impact security and reliability problems across engineering then prioritize initiatives against customer risk and business needs.
Lead the architecture and execution of cross-functional initiatives to right-size access at scale and protect Harveys most sensitive data and resources spanning secure storage key management identity and authentication permissions and authorization encryption and access controls; evaluate and evolve Harveys identity platform architecture.
Establish technical standards reference architectures and paved roads that allow engineering teams to adopt secure patterns without centralized security involvement.
Create measurable outcomes for Security Engineering including platform adoption reduction in privileged-access risk time to remediate authorization correctness reliability and incident reduction.
Partner with Engineering Infrastructure Product Legal and Trust to resolve trade-offs and align security investments with company priorities.
Serve as the technical authority for security architecture and guide major design reviews investment decisions and long-term roadmaps.
Lead technical response to high-severity security incidents and ensure that lessons become durable platform or architectural improvements.
7 years experience building and operating production software with demonstrated impact across multiple teams or technical domains.
A track record of defining technical direction for ambiguous high-risk or business-critical problems.
Deep expertise in one or more security engineering domains with enough breadth to reason across identity authorization infrastructure application security and developer platforms.
Experience designing security platforms libraries or abstractions used by other engineering teams.
Demonstrated ability to influence architecture roadmaps and engineering practices without relying on formal authority.
Experience delivering foundational systems that achieve meaningful adoption and improve organizational or customer outcomes.
Strong programming skills and a willingness to work across the stack and across unfamiliar domains.
Experience with cloud infrastructure such as Azure Google Cloud Platform or Amazon Web Services and modern distributed-system patterns.
Ability to translate threat models customer requirements and business priorities into scalable engineering strategy.
Strong communication skills and the ability to create alignment across technical and non-technical stakeholders.
Experience building security platforms or programs at a hyper-growth startup.
Background in developer platform infrastructure or site reliability engineering.
Experience with System for Cross-domain Identity Management (SCIM) OpenID Connect (OIDC) Security Assertion Markup Language (SAML) policy engines such as Open Policy Agent (OPA) or Cedar Zanzibar-style authorization systems or hardware-backed credentials.
Experience securing agentic or artificial-intelligence-powered systems especially systems that act on behalf of users against sensitive data
Experience using AI-assisted development tools effectively while applying strong engineering judgment.
Harvey is an equal opportunity employer and does not discriminate on the basis of race gender sexual orientation gender identity/expression national origin disability age genetic information veteran status marital status pregnancy or related condition or any other basis protected by law.
We are committed to providing reasonable accommodations to applicants with disabilities and requests can be made by emailing
Required Experience:
Staff IC
About Company
Professional Class AI – Harvey is the platform built to meet the standards of the world’s leading professional service firms.