Staff Corporate Security Engineer
$220k - $330k • Remote • New York • FullTime
Posted 2d ago
About the job
Harvey is seeking a Staff Corporate Security Engineer to join its growing corporate security function. This role will be responsible for securing the company's IT and business systems, balancing risk with user experience through threat modeling and real-world testing. The ideal candidate will have a strong understanding of how data flows between SaaS applications, can identify security weaknesses in complex integrations, and can build scalable controls. Experience with eDiscovery workflows and legal holds is a significant advantage given Harvey's client base.
Responsibilities
- Design, implement, and govern security controls for cross-application data flows, API integrations, OAuth connections, and third-party SaaS platforms.
- Own the security review lifecycle for new integrations and automate posture monitoring.
- Build and operate legal hold infrastructure, including data preservation, collection workflows, and custodian management.
- Partner with Legal and Compliance to meet litigation readiness requirements.
- Provide security oversight across the SaaS application lifecycle, including vendor onboarding, configuration review, and decommissioning.
- Support endpoint security policies and vulnerability management, ensuring telemetry feeds into detection and response.
- Develop scripts and integrations to extend visibility across corporate systems and surface signals from SaaS and business applications.
Requirements
- Demonstrated experience securing enterprise SaaS environments, including integration security, API token management, OAuth governance, and cross-application data flow risk.
- Working knowledge of authentication/authorization standards (SAML, OIDC, SCIM, X.509) and ability to debug integration failures.
- Experience building or managing eDiscovery and legal hold programs.
- Familiarity with tools such as Purview, Vault, Relativity, Everlaw, or similar platforms is a plus.
- Strong software engineering fundamentals with proficiency in Python and/or Go.
- Experience building integrations against SaaS APIs.
- Experience with infrastructure-as-code tooling such as Terraform and/or Pulumi.
- Ability to identify risks and vulnerabilities and communicate them clearly to stakeholders.
- Familiarity with endpoint security for macOS and Windows environments.
- Experience with tools such as Okta, Google Workspace, Salesforce, Workday, NetSuite, Microsoft Entra/Azure/Intune, JAMF, Tines, or similar platforms.
- 4+ years of experience in security engineering, corporate engineering, IT, or a related program management function with a security focus.