Join Harvey as a Senior Software Engineer to build and operate core security services in a fast-growing AI-driven company.
Posted by employer 1 month ago
First seen on Joblaze 1 month ago
Last verified on the company career page 1 day ago
Skills & Technologies
AI in the day-to-day
Fluency building and maintaining production services with agentic coding tools (Claude Code, Codex, or similar).
Requirements
Not disclosed in this posting: compensation, work arrangement, visa sponsorship.
Joblaze summary
In the role of Senior Software Engineer on the Security Engineering team at Harvey, the individual will design and implement essential security services that support the entire engineering organization. Key skills include hands-on experience with identity and access management, secrets management, and a strong grasp of security vulnerabilities. This position is ideal for seasoned engineers with a background in security infrastructure, particularly those who thrive in fast-paced, high-growth environments. Harvey emphasizes a collaborative culture where security is integrated into engineering practices rather than treated as a separate function.
Joblaze insights
Quick facts
From the original posting
As a Senior Software Engineer on the Security Engineering team at Harvey, you'll build and operate the foundational security services every other engineer at Harvey depends on: encryption and key management, public key infrastructure (PKI), secrets management, identity and access, and the tooling that makes the secure path the fast path. You'll design these systems, write the code, run them in production, and own the results. Agentic systems make this harder than it is at a typical SaaS company: when an AI agent acts on a user's behalf against their most sensitive documents, protecting data, credentials, and execution boundaries becomes essential to every workflow.
Security at Harvey is an engineering discipline, not a gatekeeper function. We build platforms and libraries that make it hard for engineers to get security wrong, and we measure ourselves on adoption and outcomes rather than tickets filed. Our program is informed by risk: we invest where the actual exposure to our customers' data is greatest, rather than where a framework tells us to.
Design, build, and operate shared services for encryption, key management, and secure storage, partnering with Product and Infrastructure teams to protect sensitive data
Build PKI and certificate lifecycle automation, including issuance, renewal, revocation, and trust rotation
Build secrets management workflows that discover exposed credentials, enable secure storage and delivery, automate rotation, and support rapid revocation
Build secure-by-default libraries and self-service tooling for data protection and identity and access, making shared security controls easy for engineering teams to adopt
Build reusable tooling for code, dependency, and secret scanning, CI/CD enforcement, and remediation, including infrastructure to safely run and observe security agents
Take these systems from greenfield to production-grade: define the architecture, ship it, instrument it, and own its reliability
Contribute to incident response and drive technical mitigation when security issues surface
Raise the security bar across engineering through design reviews, code reviews, and technical mentorship
5+ years of software engineering experience with a track record of shipping and operating production services
Hands-on experience designing, building, and operating security infrastructure in one or more areas such as PKI, encryption and key management, secrets management, secure software delivery, or identity and access
Working knowledge of common vulnerability classes and the ability to reason about how a system fails under an attacker, not just under load
Strong programming skills and a willingness to work across the stack and across unfamiliar domains
Fluency building and maintaining production services with agentic coding tools (Claude Code, Codex, or similar) — you know how to get real leverage from them and where they need supervision
Experience with cloud infrastructure (Azure, GCP, or AWS) and modern distributed system patterns
Demonstrated ability to turn security requirements into scalable engineering solutions rather than manual process
Strong communication and collaboration skills; you can influence engineering teams without formal authority
Experience building security platforms or programs at hyper-growth startups
Background in developer platform or infrastructure engineering
Experience applying cryptography in production through established libraries, envelope encryption, cloud key management services (KMS), or hardware security modules (HSMs)
Experience with PKI, TLS/mTLS, certificate lifecycle automation, or secrets rotation at scale
Experience in highly regulated enterprise environments
$188,000 - $282,000 USD
#LI-NP1
Standard company text repeated across Harvey AI's postings is omitted here.