ForgeApply · Job listing
Staff Software Engineer, Security
Harvey
See all 278 open roles at Harvey →
Tailor your resume for this Harvey job in about a minute.
ForgeApply rewrites your resume for this exact posting, then autofills the application on Harvey's site with it. You review everything before it's sent. Free trial, no card required.
About this role
WHY HARVEY
At Harvey, we’re transforming how legal and professional services operate. By combining frontier agentic AI, an enterprise-grade platform, and deep domain expertise, we’re reshaping how critical knowledge work gets done for decades to come.
This is a rare chance to help build a generational company at a true inflection point. We have strong product-market fit and world-class investor support. We’re scaling fast and defining a new category in real time. The work is ambitious, the bar is high, and the opportunity for growth — personal, professional, and financial — is unmatched.
Our team moves fast, takes ownership, and is deeply committed to the mission — operating with intensity, staying close to our customers, and pushing each other for excellence. We live by three values: Decisiveness, Simplicity, and Job's Not Finished. We act quickly on clear judgment over perfect information, we believe simplicity is what scales, and we're never satisfied with where we are. If you want to do the best work of your career alongside people who share that drive, we'd love to build with you.
At Harvey, the future of professional services is being written today — and we’re just getting started.
ROLE OVERVIEW
As a Staff Software Engineer on the Security Engineering team, you will be a founding member of the team and define/drive the technical strategy for the security foundations that protect Harvey’s workforce, infrastructure, production systems, and customer data.
You will lead the evolution of identity, authorization, secrets, privileged access, and secure developer tooling across multiple engineering teams. You will operate at the boundary of security, infrastructure, and product engineering—turning ambiguous risk and business requirements into durable platforms, clear architectural direction, and measurable improvements in security outcomes.
This role is hands-on, but its primary leverage comes through technical direction, platform adoption, cross-functional alignment, and enabling other engineers to build securely by default.
WHAT YOU’LL DO
- Define Harvey’s multi-year technical strategy for identity, authorization, secrets management, privileged access, or secure developer tooling.
- Design and build complex security systems from greenfield — writing the code, instrumenting it, and owning it in production.
- Identify the highest-impact security and reliability problems across engineering, then prioritize initiatives against customer risk and business needs.
- Lead the architecture and execution of cross-functional initiatives to right-size access at scale and protect Harvey’s most sensitive data and resources, spanning secure storage, key management, identity and authentication, permissions and authorization, encryption, and access controls; evaluate and evolve Harvey’s identity platform architecture.
- Establish technical standards, reference architectures, and paved roads that allow engineering teams to adopt secure patterns without centralized security involvement.
- Create measurable outcomes for Security Engineering, including platform adoption, reduction in privileged-access risk, time to remediate, authorization correctness, reliability, and incident reduction.
- Partner with Engineering, Infrastructure, Product, Legal, and Trust to resolve trade-offs and align security investments with company priorities.
- Serve as the technical authority for security architecture and guide major design reviews, investment decisions, and long-term roadmaps.
- Lead technical response to high-severity security incidents and ensure that lessons become durable platform or architectural improvements.
WHAT YOU HAVE
- 7+ years experience building and operating production software, with demonstrated impact across multiple teams or technical domains.
- A track record of defining technical direction for ambiguous, high-risk, or business-critical problems.
- Deep expertise in one or more security engineering domains, with enough breadth to reason across identity, authorization, infrastructure, application security, and developer platforms.
- Experience designing security platforms, libraries, or abstractions used by other engineering teams.
- Demonstrated ability to influence architecture, roadmaps, and engineering practices without relying on formal authority.
- Experience delivering foundational systems that achieve meaningful adoption and improve organizational or customer outcomes.
- Strong programming skills and a willingness to work across the stack and across unfamiliar domains.
- Experience with cloud infrastructure, such as Azure, Google Cloud Platform, or Amazon Web Services, and modern distributed-system patterns.
- Ability to translate threat models, customer requirements, and business priorities into scalable engineering strategy.
- Strong communication skills and the ability to create alignment across technical and non-technical stakeholders.
NICE TO HAVE
- Experience building security platforms or programs at a hyper-growth startup.
- Background in developer platform, infrastructure, or site reliability engineering.
- Experience with System for Cross-domain Identity Management (SCIM), OpenID Connect (OIDC), Security Assertion Markup Language (SAML), policy engines such as Open Policy Agent (OPA) or Cedar, Zanzibar-style authorization systems, or hardware-backed credentials.
- Experience securing agentic or artificial-intelligence-powered systems, especially systems that act on behalf of users against sensitive data
- Experience using AI-assisted development tools effectively while applying strong engineering judgment.
Harvey is an equal opportunity employer and does not discriminate on the basis of race, gender, sexual orientation, gender identity/expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or related condition, or any other basis protected by law.
We are com
Salary insight
The midpoint of this range ($275k) is about 38% above the median disclosed salary for San Francisco roles listed on ForgeApply ($200k across 8,465 jobs).
See full Software Engineer salary data for San Francisco →
Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.
Tailor your resume for this Harvey role before you apply.
Tailor my resume for this jobSimilar jobs
- Staff Software Engineer, Security — Crusoe · San Francisco, CA - US
- Staff Software Engineer - Security — Flowengineering · San Francisco
- Staff Software Engineer - Security — Skydio · Remote
- Staff Software Engineer - Security Infrastructure — Databricks · Bellevue, Washington
- Staff Software Engineer - Security Infrastructure — Databricks · Mountain View, California
- Staff Software Engineer, Product Security — Snowflake · Remote
- Staff Software Engineer - Product Security — Mavenclinic · New York, NY; Remote, US (Hub cities)
- Staff Software Engineer, Security & Privacy — Abnormalsecurity · Remote
More like this: Software Engineer Jobs · Software Engineer Jobs in San Francisco · Browse all jobs
Free ATS checker · How to Tailor Your Resume to a Job Description (Step by Step)