SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Harvey is an AI platform transforming legal and professional services by combining frontier agentic AI, enterprise-grade infrastructure, and deep domain expertise. The company is at a critical inflection point with strong product-market fit and world-class investor backing, founded in 2022 and headquartered in San Francisco.
As a Software Engineer on the Security Engineering team, you will build and operate foundational security services for both customer-facing products and internal systems. Your focus will be on identity and access management, secrets and privileged access, agent sandboxes, and tooling that makes the secure path the fast path. You'll turn security requirements into production systems and own the reliability and security of what you build, collaborating closely with engineers and partner teams.
Key responsibilities include:
- Building and operating Harvey's core identity and access services across customer-facing product, workforce, and infrastructure systems, including authentication, authorization, access governance, secrets, and privileged access
- Evolving how Harvey customers set up and manage their environments, making security-critical configuration delightful to use and secure by default
- Building identity controls, sandboxes, and safety harnesses that let services and AI agents operate with least privilege, constrained actions, clear auditability, and effective monitoring
- Creating secure-by-default libraries, paved-road abstractions, self-service tooling, and agentic workflows that automate security triage, remediation, and evidence collection
- Taking security systems from design through production, accounting for trust boundaries, attacker paths, and operational failure modes
- Participating in on-call rotation for mission-critical security services and contributing to incident response
Required qualifications:
- 2+ years of software engineering experience, including shipping and operating production services
- Experience building or contributing to security infrastructure such as identity and access management, authentication and authorization, secrets management, or privileged access
- Strong programming, debugging, testing, and problem-solving skills with ability to work across unfamiliar systems
- Experience with cloud infrastructure (Azure, GCP, or AWS) and familiarity with modern distributed-system patterns
- Track record of translating security requirements into maintainable, automated systems
- Experience using agentic coding tools and creating workflows that automate repetitive security work
- Clear communication and collaboration skills
- Working knowledge of common vulnerability classes and ability to reason about system failures under attack
Nice-to-have experience includes security infrastructure at fast-growing companies, SCIM/OIDC/SAML/policy engines, securing agentic or AI-powered systems, and working in highly regulated enterprise environments.
About Harvey
Legal / Compliance / Risk; AI / Data / Infrastructure — AI platform for legal and professional services work.