SlipstreamJobsFresh Startup & VC-Backed Jobs

Staff Corporate Security Engineer

Harvey - New York, NY, United States - Hybrid - posted 2026-08-01

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 220,000 - 330,000 / annual

Harvey is an AI platform transforming legal and professional services by combining frontier agentic AI with enterprise-grade infrastructure and deep domain expertise. The company serves some of the world's largest enterprises and law firms, handling their most sensitive documents and data. You'll join Harvey's corporate security function as a Staff-level security engineer, responsible for securing the company's IT and business systems as it scales rapidly. This role sits at the intersection of security engineering and enterprise systems, requiring deep understanding of how data flows between SaaS applications, where security breaks down in complex integrations, and how to build controls that scale. Key responsibilities include: **Enterprise Integrations & SaaS Security**: Design, implement, and govern security controls for cross-application data flows, API integrations, OAuth connections, and third-party SaaS platforms. Own the security review lifecycle for new integrations and automate posture monitoring to catch configuration drift early. **eDiscovery & Legal Hold Program**: Build and operate Harvey's legal hold infrastructure, including data preservation, collection workflows, and custodian management. Partner with Legal and Compliance to meet litigation readiness requirements across collaboration and productivity stacks. **IT & Business Systems Partnership**: Provide security oversight across the SaaS application lifecycle—vendor onboarding assessments, ongoing configuration review, and decommissioning. **Endpoint Security**: Support endpoint security policies and vulnerability management, ensuring endpoint telemetry feeds into detection and response workflows. **Security Detection & Response**: Develop scripts and integrations that extend visibility across corporate systems, partnering with the Detection & Response team to surface signals from SaaS and business applications. You bring 4+ years of security engineering, corporate engineering, IT, or related program management experience with a security focus. You have demonstrated expertise securing enterprise SaaS environments, including integration security, API token management, OAuth governance, and cross-application data flow risk. You understand authentication/authorization standards (SAML, OIDC, SCIM, X.509) and can debug real-world integration failures. Experience building or managing eDiscovery and legal hold programs is a meaningful differentiator—familiarity with tools like Purview, Vault, Relativity, Everlaw, or similar platforms is valuable. You have strong software engineering fundamentals with proficiency in Python and/or Go, including building integrations against SaaS APIs and experience with infrastructure-as-code tooling (Terraform, Pulumi). You're comfortable with endpoint security for macOS and Windows, and familiar with platforms like Okta, Google Workspace, Salesforce, Workday, NetSuite, Microsoft Entra/Azure/Intune, JAMF, or Tines. You can identify risks and vulnerabilities in IT and business systems and communicate risk clearly to engineering, legal, and executive stakeholders.

About Harvey

Legal / Compliance / Risk; AI / Data / Infrastructure — AI platform for legal and professional services work.

Similar roles