Join Harvey AI as a Senior Product Security Engineer to enhance the security and privacy of our innovative legal automation platform.
Skills & Technologies
Requirements
Benefits
Joblaze summary
In this role, the Senior Product Security Engineer at Harvey AI will focus on integrating secure design principles into product development while reviewing and enhancing security-critical code. The position requires expertise in security-focused software engineering, with a strong emphasis on identifying vulnerabilities and managing security aspects of the release process. This role is ideal for someone with significant experience in a fast-paced startup environment, looking to contribute to a mission-driven team committed to excellence in security. Harvey AI's dynamic growth and commitment to innovation make it an exciting place for professionals eager to shape the future of legal technolog
Joblaze insights
Quick facts
From the original posting
At Harvey, we’re transforming how legal and professional services operate. By combining frontier agentic AI, an enterprise-grade platform, and deep domain expertise, we’re reshaping how critical knowledge work gets done for decades to come.
This is a rare chance to help build a generational company at a true inflection point. We have strong product-market fit and world-class investor support. We’re scaling fast and defining a new category in real time. The work is ambitious, the bar is high, and the opportunity for growth — personal, professional, and financial — is unmatched.
Our team moves fast, takes ownership, and is deeply committed to the mission — operating with intensity, staying close to our customers, and pushing each other for excellence. We live by three values: Decisiveness, Simplicity, and Job's Not Finished. We act quickly on clear judgment over perfect information, we believe simplicity is what scales, and we're never satisfied with where we are. If you want to do the best work of your career alongside people who share that drive, we'd love to build with you.
At Harvey, the future of professional services is being written today — and we’re just getting started.
Some of the word’s largest companies and their law firms use Harvey to make sense of their legal documents and automate legal work. Our customers depend on us to deliver a secure, trustworthy, and compliant platform. Earning the trust of our customers is a business enabler and we value it more than anything else.
As an early member of our Security team, you will you will play a key role in laying the foundation of the security and privacy of our products.
Our security program at Harvey is driven by our collective offensive security experience: Breaking into systems at other companies (in white-hat capacities), responding to real security incidents, and learning from other companies’ data breaches. We conduct regular pentests and red team exercises with external security firms.
Closely work with engineering teams to incorporate secure design principles into engineering designs.
Review security-critical code and act as Codeowner for security-critical parts of the product, including authentication, access control, and administration.
Make well-scoped code contributions, e.g. add unit and integration tests for security controls, implement security features in collaboration with engineering teams.
Manage the security aspects of our release process.
Audit the existing codebase for vulnerabilities.
Improve our static analysis and vulnerability management tooling.
Discover vulnerabilities through red team exercises.
Participate in and drive mitigation strategies during security related incident responses.
4+ years’ experience in security-focused software engineering.
Experience working at or with a small company or a hyper-growth startup.
Demonstrated experience writing high-quality software and raising the quality bar of software engineering teams.
Demonstrated ability to identify vulnerabilities in software, e.g. through CVEs, bug bounty awards, blog posts, and prior work experience.
Open source contributions.
Experience managing cloud environments (e.g. Azure, GCP, AWS)
In consideration of market analysis and relevant factors, the salary range for this position is set between $200,000 and $280,000. However, adjustments outside of this range may be considered for candidates whose qualifications significantly differ from those outlined in the job description. Additionally, this role is eligible to participate in our equity plan and benefits program. Benefits include, but not limited to: Comprehensive health, dental and vision coverage, retirement benefits (401k match up to 4%), and flexible PTO.
Harvey is an equal opportunity employer and does not discriminate on the basis of race, gender, sexual orientation, gender identity/expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or related condition, or any other basis protected by law.
We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made by emailing accommodations@harvey.ai