SlipstreamJobsFresh Startup & VC-Backed Jobs

Staff Corporate Security Engineer

Harvey - San Francisco, CA, United States - In-office - posted 2026-08-01

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 220,000 - 330,000 / annual

Harvey is an AI platform transforming legal and professional services by combining frontier agentic AI with enterprise-grade infrastructure and deep domain expertise. The company serves some of the world's largest enterprises and law firms, handling their most sensitive documents and data. This Staff-level security engineering role joins Harvey's corporate security function during rapid scaling. You'll secure Harvey's IT and business systems while balancing risk with user experience through threat modeling and real-world testing rather than relying solely on best practices. Key responsibilities include: **Enterprise Integrations & SaaS Security**: Design and implement security controls for cross-application data flows, API integrations, OAuth connections, and third-party SaaS platforms. Own the security review lifecycle for new integrations and automate posture monitoring to catch configuration drift early. **eDiscovery & Legal Hold Program**: Build and operate Harvey's legal hold infrastructure, including data preservation, collection workflows, and custodian management. Partner with Legal and Compliance teams to meet litigation readiness requirements across collaboration and productivity stacks. **IT & Business Systems Partnership**: Provide security oversight across the SaaS application lifecycle—vendor onboarding assessments, ongoing configuration review, and decommissioning. **Endpoint Security**: Support endpoint security policies and vulnerability management, ensuring endpoint telemetry feeds into detection and response workflows. **Security Detection & Response**: Develop scripts and integrations that extend visibility across corporate systems, partnering with the Detection & Response team to surface signals from SaaS and business applications. You bring 4+ years of security engineering, corporate engineering, IT, or related program management experience with a security focus. You have demonstrated expertise securing enterprise SaaS environments, including integration security, API token management, OAuth governance, and cross-application data flow risk. You understand authentication/authorization standards (SAML, OIDC, SCIM, X.509) and can debug real-world integration failures. Experience building or managing eDiscovery and legal hold programs is a meaningful differentiator given Harvey's customer base. Familiarity with tools such as Purview, Vault, Relativity, or Everlaw is valuable. You have strong software engineering fundamentals with proficiency in Python and/or Go, including building integrations against SaaS APIs (not just console configuration). You're comfortable with infrastructure-as-code tooling such as Terraform or Pulumi for managing security configurations in repeatable, auditable ways. You can identify risks and vulnerabilities in IT and business systems and communicate that risk clearly to stakeholders across engineering, legal, and executive audiences. Familiarity with endpoint security for macOS and Windows environments and experience with tools such as Okta, Google Workspace, Salesforce, Workday, NetSuite, Microsoft Entra/Azure/Intune, JAMF, or Tines is expected. Genuine curiosity about generative AI and the legal industry will serve you well, though prior experience is not required.

About Harvey

Legal / Compliance / Risk; AI / Data / Infrastructure — AI platform for legal and professional services work.

Similar roles