SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Harvey is an AI platform for legal and professional services, combining frontier agentic AI with enterprise-grade infrastructure and deep domain expertise. As a Senior Software Engineer on the Security Engineering team, you will design, build, and operate Harvey's foundational security services that every engineer depends on: identity and access management, secrets and privileged access management, and tooling that makes the secure path the fast path.
You'll own Harvey's identity infrastructure end-to-end, including SSO, SCIM, and fine-grained authorization for enterprise customers. A key challenge: when AI agents act on users' behalf against sensitive documents, identity and authorization become significantly more complex than at typical SaaS companies.
Security at Harvey is treated as an engineering discipline, not a gatekeeper function. You'll build platforms and libraries that make it hard for engineers to get security wrong, measure success on adoption and outcomes rather than tickets filed, and invest where actual customer data exposure is greatest.
Key responsibilities include designing and operating core security services across workforce, infrastructure, and production environments; building secure-by-default libraries and self-service tooling so teams can identify and remediate issues independently; taking systems from greenfield to production-grade; contributing to incident response; and raising the security bar through design reviews, code reviews, and mentorship.
You'll need 5+ years of software engineering experience with a track record of shipping and operating production services. Hands-on experience building security infrastructure (IAM, authentication/authorization, secrets management, or privileged access) is essential. You should understand common vulnerability classes and how systems fail under attack, not just under load. Strong programming skills across the stack, fluency with agentic coding tools (Claude Code, Codex, or similar), and experience with cloud infrastructure (Azure, GCP, AWS) and modern distributed systems are required. You must demonstrate the ability to turn security requirements into scalable engineering solutions and communicate effectively to influence teams without formal authority.
Nice-to-have experience includes building security platforms at hyper-growth startups, developer platform or infrastructure engineering, SCIM/OIDC/SAML/policy engines (OPA, Cedar, Zanzibar-style systems), hardware-backed credentials, and highly regulated enterprise environments.
About Harvey
Legal / Compliance / Risk; AI / Data / Infrastructure — AI platform for legal and professional services work.