About the job
As a Staff Software Engineer on the Product Security team at Harvey, you'll play a critical role in shaping how security is built into our AI platform from the ground up. We store and process our customers’ most sensitive data, and as a result, security is paramount at every stage of our product lifecycle. You'll take ownership of securing critical parts of the product while driving high-leverage security initiatives that raise the bar for the entire engineering org — balancing hands-on technical work with cross-functional leadership and mentorship. This is a rare opportunity to define and build a product security program at a company scaling fast.
Responsibilities
- Define and own the product security roadmap, prioritizing initiatives based on risk, business impact, and engineering org maturity.
- Establish and evolve security posture across the engineering organization, setting standards that scale with the company
- Partner with Product Engineering, Infrastructure, and Platform teams to incorporate secure design principles at every stage of development
- Own and review security-critical code across key parts of the product, including authentication and access control
- Architect secure-by-default libraries and tools that make the secure path the easiest choice for developers
- Drive mitigation strategies during security-related incident responses, coordinating cross-functional efforts
- Mentor engineers and raise the security bar across teams through code reviews, design reviews, and technical guidance
Qualifications
Minimum
- 8+ years of experience in product security, application security, offensive security, and/or security-focused software engineering
- Long track record of identifying and remediating software vulnerabilities, demonstrated through CVEs, bug bounty awards, published research, or prior work experience
- Track record of leading complex cross-functional security initiatives and delivering measurable improvements, with demonstrated ability to influence engineering teams without direct authority.
- Experience mentoring senior engineers and developing security talent within an engineering organization
- Strong programming skills with demonstrated experience writing high-quality, production software
- Excellent communication and collaboration skills, particularly when translating security risks into business terms for non-security stakeholders
Preferred
- Experience building security programs or practices at hyper-growth startups
- Background with cloud environments (Azure, GCP, AWS) and cloud-native security patterns
- Experience with AI/ML systems and emerging security considerations for LLM-based applications