Staff Software Engineer, Product Security

Harvey
San Francisco2026-05-01Hybrid

About the job

As a Staff Software Engineer on the Product Security team at Harvey, you'll play a critical role in shaping how security is built into our AI platform from the ground up. We store and process our customers’ most sensitive data, and as a result, security is paramount at every stage of our product lifecycle. You'll take ownership of securing critical parts of the product while driving high-leverage security initiatives that raise the bar for the entire engineering org — balancing hands-on technical work with cross-functional leadership and mentorship. This is a rare opportunity to define and build a product security program at a company scaling fast.

Responsibilities

- Define and own the product security roadmap, prioritizing initiatives based on risk, business impact, and engineering org maturity.

- Establish and evolve security posture across the engineering organization, setting standards that scale with the company

- Partner with Product Engineering, Infrastructure, and Platform teams to incorporate secure design principles at every stage of development

- Own and review security-critical code across key parts of the product, including authentication and access control

- Architect secure-by-default libraries and tools that make the secure path the easiest choice for developers

- Drive mitigation strategies during security-related incident responses, coordinating cross-functional efforts

- Mentor engineers and raise the security bar across teams through code reviews, design reviews, and technical guidance

Qualifications

Minimum

- 8+ years of experience in product security, application security, offensive security, and/or security-focused software engineering

- Long track record of identifying and remediating software vulnerabilities, demonstrated through CVEs, bug bounty awards, published research, or prior work experience

- Track record of leading complex cross-functional security initiatives and delivering measurable improvements, with demonstrated ability to influence engineering teams without direct authority.

- Experience mentoring senior engineers and developing security talent within an engineering organization

- Strong programming skills with demonstrated experience writing high-quality, production software

- Excellent communication and collaboration skills, particularly when translating security risks into business terms for non-security stakeholders

Preferred

- Experience building security programs or practices at hyper-growth startups

- Background with cloud environments (Azure, GCP, AWS) and cloud-native security patterns

- Experience with AI/ML systems and emerging security considerations for LLM-based applications