Software Engineer, Product Security at Harvey
San Francisco, CA 94102, USA -
Full Time


Start Date

Immediate

Expiry Date

08 Nov, 25

Salary

250000.0

Posted On

09 Aug, 25

Experience

4 year(s) or above

Remote Job

Yes

Telecommute

Yes

Sponsor Visa

No

Skills

Good communication skills

Industry

Information Technology/IT

Description

Location
San Francisco
Employment Type
Full time
Department
Engineering
Compensation
$215K – $250K • Offers Equity
Additionally, this role is eligible to participate in our equity plan and benefits program. Benefits include, but not limited to: Comprehensive health, dental and vision coverage, retirement benefits (401k match up to 4%), and flexible PTO.

How To Apply:

Incase you would like to apply to this job directly from the source, please click here

Responsibilities

ROLE OVERVIEW

Some of the world’s largest companies and their law firms use Harvey’s AI capabilities to deliver world-class client services at unprecedented scale and efficiency. Harvey allows high-performing professionals to gain deep domain knowledge faster, understand the big picture, and tackle more complex challenges in less time.
Our customers depend on us to deliver a secure, trustworthy, and compliant platform. Earning the trust of our customers is a business enabler and we value it more than anything else.
As part of the Product Security team, you’ll help ensure Harvey is built in the most secure way possible. You’ll take ownership of securing a specific part of the product and build strong relationships with the developers working in that area. With these insights, you’ll advocate for and implement high-leverage security controls across the organization.
Our security program at Harvey is driven by our collective offensive security experience: Breaking into systems at other companies (in white-hat capacities), responding to real security incidents, and learning from other companies’ data breaches. We regularly conduct penetration tests and red team exercises with external security firms. At the same time, we are all software engineers - contributing code daily and approaching security with an engineering-first mindset.

WHAT YOU’LL DO

  • Partner closely with engineering teams to incorporate secure design principles at every stage of development
  • Review security-critical code and own key parts of the product, including authentication and access control
  • Contribute meaningfully to the Harvey code base. Some prior projects include:
  • Refactoring our authentication stack to improve streamline execution
  • Removing password use from the application
  • Designing secure APIs for critical data access
  • Build secure-by-default libraries and tools that make the secure path the easiest and most attractive choice for developers and their AI agents
  • Audit the existing codebase for vulnerabilities
  • Improve our static analysis and vulnerability management tooling
  • Discover vulnerabilities through red team exercises
  • Participate in and drive mitigation strategies during security related incident responses
Loading...