Staff Software Engineer, Security

Posted:
8/19/2026, 8:52:13 AM

Location(s):
California, United States ⋅ San Francisco, California, United States

Experience Level(s):
Expert or higher ⋅ Senior

Field(s):
Software Engineering

Workplace Type:
Hybrid

Pay:
$220k–$330k/yr

Why Harvey

At Harvey, we’re transforming how legal and professional services operate. By combining frontier agentic AI, an enterprise-grade platform, and deep domain expertise, we’re reshaping how critical knowledge work gets done for decades to come.

This is a rare chance to help build a generational company at a true inflection point. We have strong product-market fit and world-class investor support. We’re scaling fast and defining a new category in real time. The work is ambitious, the bar is high, and the opportunity for growth — personal, professional, and financial — is unmatched.

Our team moves fast, takes ownership, and is deeply committed to the mission — operating with intensity, staying close to our customers, and pushing each other for excellence. We live by three values: Decisiveness, Simplicity, and Job's Not Finished. We act quickly on clear judgment over perfect information, we believe simplicity is what scales, and we're never satisfied with where we are. If you want to do the best work of your career alongside people who share that drive, we'd love to build with you.

At Harvey, the future of professional services is being written today — and we’re just getting started.

Role overview

As a Staff Software Engineer on the Security Engineering team, you will be a founding member of the team and define/drive the technical strategy for the security foundations that protect Harvey’s workforce, infrastructure, production systems, and customer data.

You will lead the evolution of identity, authorization, secrets, privileged access, and secure developer tooling across multiple engineering teams. You will operate at the boundary of security, infrastructure, and product engineering—turning ambiguous risk and business requirements into durable platforms, clear architectural direction, and measurable improvements in security outcomes.

This role is hands-on, but its primary leverage comes through technical direction, platform adoption, cross-functional alignment, and enabling other engineers to build securely by default.

What you’ll do

  • Define Harvey’s multi-year technical strategy for identity, authorization, secrets management, privileged access, or secure developer tooling.

  • Design and build complex security systems from greenfield — writing the code, instrumenting it, and owning it in production.

  • Identify the highest-impact security and reliability problems across engineering, then prioritize initiatives against customer risk and business needs.

  • Lead the architecture and execution of cross-functional initiatives to right-size access at scale and protect Harvey’s most sensitive data and resources, spanning secure storage, key management, identity and authentication, permissions and authorization, encryption, and access controls; evaluate and evolve Harvey’s identity platform architecture.

  • Establish technical standards, reference architectures, and paved roads that allow engineering teams to adopt secure patterns without centralized security involvement.

  • Create measurable outcomes for Security Engineering, including platform adoption, reduction in privileged-access risk, time to remediate, authorization correctness, reliability, and incident reduction.

  • Partner with Engineering, Infrastructure, Product, Legal, and Trust to resolve trade-offs and align security investments with company priorities.

  • Serve as the technical authority for security architecture and guide major design reviews, investment decisions, and long-term roadmaps.

  • Lead technical response to high-severity security incidents and ensure that lessons become durable platform or architectural improvements.

What You Have

  • 7+ years experience building and operating production software, with demonstrated impact across multiple teams or technical domains.

  • A track record of defining technical direction for ambiguous, high-risk, or business-critical problems.

  • Deep expertise in one or more security engineering domains, with enough breadth to reason across identity, authorization, infrastructure, application security, and developer platforms.

  • Experience designing security platforms, libraries, or abstractions used by other engineering teams.

  • Demonstrated ability to influence architecture, roadmaps, and engineering practices without relying on formal authority.

  • Experience delivering foundational systems that achieve meaningful adoption and improve organizational or customer outcomes.

  • Strong programming skills and a willingness to work across the stack and across unfamiliar domains.

  • Experience with cloud infrastructure, such as Azure, Google Cloud Platform, or Amazon Web Services, and modern distributed-system patterns.

  • Ability to translate threat models, customer requirements, and business priorities into scalable engineering strategy.

  • Strong communication skills and the ability to create alignment across technical and non-technical stakeholders.

Nice to have

  • Experience building security platforms or programs at a hyper-growth startup.

  • Background in developer platform, infrastructure, or site reliability engineering.

  • Experience with System for Cross-domain Identity Management (SCIM), OpenID Connect (OIDC), Security Assertion Markup Language (SAML), policy engines such as Open Policy Agent (OPA) or Cedar, Zanzibar-style authorization systems, or hardware-backed credentials.

  • Experience securing agentic or artificial-intelligence-powered systems, especially systems that act on behalf of users against sensitive data

  • Experience using AI-assisted development tools effectively while applying strong engineering judgment.

Harvey is an equal opportunity employer and does not discriminate on the basis of race, gender, sexual orientation, gender identity/expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or related condition, or any other basis protected by law.

We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made by emailing [email protected]

Harvey

Website: https://www.harvey.ai/

Headquarter Location: San Francisco, California, United States

Employee Count: 251-500

Year Founded: 2022

IPO Status: Private

Last Funding Type: Series F

Industries: Artificial Intelligence (AI) ⋅ Information Technology ⋅ Legal ⋅ Legal Tech

Visa Sponsorship: Sponsors work visas