Lead the Detection and Response team at Harvey AI, focusing on security incident management and threat detection.
Posted by employer 2 days ago
First seen on Joblaze 1 day ago
Last verified on the company career page 17 hours ago
Skills & Technologies
What you'll build
Must have
Not disclosed in this posting: years of experience, work arrangement, visa sponsorship.
Joblaze summary
The Director of Detection and Response at Harvey AI is responsible for leading a team that identifies security threats and manages incident responses to protect sensitive customer data. This role requires a strong technical background in cloud infrastructure and security engineering, along with experience in building and scaling teams. Ideal candidates will have a proven track record in incident response and the ability to translate business risks into actionable security strategies. The position plays a crucial role in establishing a robust security framework as the company continues to grow.
Joblaze insights
Quick facts
From the original posting
Harvey is building AI-native software for professional services. Our customers trust us with highly sensitive information and critical business workflows, making security fundamental to everything we build. We’re looking for a Director of Detection and Response to build and lead the team that identifies threats, responds decisively to incidents, and turns what we learn into stronger defenses.
You will own Harvey’s Detection and Response strategy, technical direction, and operational readiness across our production platform and corporate environment. Working with the CISO and leaders across Engineering, Infrastructure, IT, Legal, and Customer Trust, you’ll translate business risk into a focused program that protects customer data and enables Harvey to move quickly with confidence.
This is a technical leadership role for someone who can build an exceptional team, earn the trust of senior engineers, and bring clarity to high-stakes situations. You’ll develop a function that scales through software, automation, and strong partnerships, while staying close enough to the work to challenge detection designs and guide complex investigations.
Build and lead the organization. Hire and develop detection engineers, incident responders, and technical leaders; establish clear ownership and a culture of curiosity, sound judgment, and continuous learning. Own the roadmap, staffing plan, and investment decisions.
Own incident response and crisis readiness. Lead Harvey’s response to major security incidents, coordinating investigation, containment, recovery, and executive communication. Build clear severity criteria, escalation paths, playbooks, and sustainable 24/7 coverage for critical threats; develop incident commanders and cross-functional responders through exercises.
Build detection as an engineering capability. Set the technical direction for telemetry, detection pipelines, forensic tooling, and response automation across cloud, endpoint, identity, SaaS, and application environments. Apply software engineering practices to test detections, improve signal quality, and reduce manual work; evaluate AI-assisted investigation with measurable quality and appropriate human oversight.
Focus defenses on meaningful threats. Use threat intelligence, hunting, and an attacker’s perspective to prioritize scenarios that matter to Harvey, including account compromise, data theft, insider risk, privileged-access abuse, and abuse of AI-enabled workflows. Partner with offensive security and platform owners to validate coverage and close blind spots.
Make response a company capability. Partner with Engineering, IT, Legal, Privacy, Communications, and Customer Trust on sensitive investigations and crisis decisions. Establish clear escalation and decision authority, preserve evidence, and provide accurate findings to support Legal-led notification and disclosure decisions. Prepare cross-functional responders to contribute when incidents require broader support.
Turn incidents into lasting improvements. Drive blameless reviews and ensure corrective actions have owners, deadlines, and verified outcomes. Measure detection coverage, time to detect and contain, recurring failure modes, and responder workload, and use those results to guide investments and reduce customer impact.
Experience building and leading Detection and Response, incident response, or security engineering teams in a technology company with complex production systems. A record of hiring strong engineers, developing technical leaders, and scaling both the team and its operating model.
Deep incident response experience and demonstrated judgment during serious security events. You can lead investigations with incomplete information, make timely containment decisions, and communicate clearly with executives, engineers, and business partners. You bring composure, integrity, and discretion to sensitive investigations and decisions under scrutiny.
Strong technical foundations in cloud infrastructure, operating systems, networking, identity, and attacker tradecraft, with depth in detection engineering, threat hunting, or digital forensics. You understand how to investigate across corporate and production environments.
An engineering approach to security operations, backed by experience building detection platforms, investigation tools, or response automation. You can evaluate architecture and code, guide senior engineers, and make practical decisions about what to build, buy, or retire.
The ability to turn business risk into a focused strategy and deliver it through influence and partnership. You balance urgent response with long-term engineering work and build a demanding, supportive environment where people can do their best work.
Experience protecting enterprise SaaS, sensitive customer data, or AI/ML environments is especially valuable, as is experience investigating insider threats, partnering on privileged-access governance, or leading response under regulatory and public scrutiny.
At Harvey, you’ll shape how an AI company detects and responds to threats as its products and customers evolve. Your team’s work will directly protect customer trust and help make security a durable foundation for the business.
$280,000 - $385,000 USD
#LI-DZ1
Standard company text repeated across Harvey AI's postings is omitted here.