Software Engineer, Security
$161k - $245k • San Francisco • FullTime
Posted 13d ago
About the job
As a Software Engineer on the Security Engineering team at Harvey, you will build and operate foundational security services for both our customer-facing product and the internal systems our workforce depends on. This includes identity and access management, secrets and privileged access, agent sandboxes, and tooling that makes the secure path the fast path. You will translate security needs into production systems and own the reliability and security of what you build, working closely with engineers and partner teams. Security at Harvey is an engineering discipline focused on building platforms and libraries that make it hard for engineers to get security wrong, measured by adoption and outcomes rather than tickets filed.
Responsibilities
- Build and operate core identity and access services across customer-facing product, workforce, and infrastructure systems.
- Evolve how customers set up and manage their environments, making security-critical configuration delightful and secure by default.
- Build identity controls, sandboxes, and safety harnesses for services and AI agents operating with least privilege.
- Create secure-by-default libraries, abstractions, self-service tooling, and agentic workflows to automate security triage and remediation.
- Take security systems from design through production, owning their reliability and security.
- Share on-call rotation for mission-critical security services, contribute to incident response, and improve engineering practices through reviews and documentation.
Requirements
- 2+ years of software engineering experience, including shipping and operating production services.
- Experience building or contributing to security infrastructure (e.g., IAM, authN/authZ, secrets management).
- Strong programming, debugging, testing, and problem-solving skills.
- Experience with cloud infrastructure (Azure, GCP, AWS) and distributed-system patterns.
- Track record of translating security requirements into maintainable, automated systems.
- Experience using agentic coding tools and automating security work.
- Clear communication and collaboration skills.
- Working knowledge of common vulnerability classes and system failure modes.