SlipstreamJobsFresh Startup & VC-Backed Jobs

Staff Software Engineer, Secure Execution

Harvey - New York, NY, United States - Hybrid - posted 2026-09-30

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 231,000 - 346,400 / annual

Harvey is an AI platform transforming legal and professional services by combining frontier agentic AI, enterprise-grade infrastructure, and deep domain expertise. The company is at a strong inflection point with product-market fit and world-class investor backing. As a Staff Software Engineer on the Security Engineering team, you will join as a founding member and build the security foundations enabling Harvey to deploy increasingly capable AI agents safely. You'll lead development of a platform for agents to perform security work—including discovering and validating vulnerabilities through authorized penetration testing—while protecting sensitive data and systems. Key responsibilities include: - Setting technical direction for secure agent execution across Security, Infrastructure, and Product Engineering teams, translating emerging capabilities and risks into concrete roadmaps. - Designing, building, and operating a platform for security agents to discover and validate vulnerabilities within authorized targets and execution boundaries, producing reproducible evidence for engineers. - Building reusable controls for agent tool use, code execution, network and filesystem access, resource consumption, and workload lifecycle. Integrating with identity and secrets platforms to enforce least-privilege access. - Partnering with product sandbox and internal agent platform owners on architectural decisions, implementing protections, and integrating shared security capabilities. - Enabling internal use of open-source models alongside infrastructure teams, building protections around model serving, agent execution, and sensitive-data handling. - Developing adversarial tests, evaluations, and telemetry to verify containment and expose failures. Building mechanisms to scope, observe, interrupt, and safely terminate agent activity. - Leading delivery and adoption across teams, mentoring engineers, and remaining hands-on through implementation and production operation, balancing security, reliability, latency, and cost. Harvey operates with three core values: Decisiveness (acting quickly on clear judgment), Simplicity (believing it scales), and Job's Not Finished (never satisfied with the status quo). The team moves fast, takes ownership, and is deeply committed to the mission. REQUIREMENTS: - 10+ years developing and running production software, including technical leadership on initiatives spanning multiple engineering teams. - Strong software engineering skills in Go, Rust, Python, or C++, with practical experience in Linux systems, networking, and containerized infrastructure. - Deep expertise in one or more areas of execution security: sandboxing, operating-system isolation, container or virtual-machine security, or platforms that execute untrusted code. Ability to translate threats into enforceable boundaries and test boundary failures. - Experience building shared platforms, services, or libraries and helping other teams adopt them through clear interfaces, documentation, and safe migrations. - Experience with cloud infrastructure and distributed systems, including observability, failure handling, capacity management, and dependable production operation. - Fluency with AI-assisted engineering and agentic workflows: using models to accelerate development, validating output, and reasoning about risks when agents use tools, execute code, or access sensitive data. - Strong communication and technical judgment, with a record of bringing teams to agreement on ambiguous problems and carrying decisions through to delivery. NICE TO HAVE: - Experience with microVMs, hypervisors, or sandbox runtimes (Firecracker, gVisor, Kata Containers) or Linux isolation mechanisms (namespaces, seccomp, Landlock). - Experience building agent runtimes, tool-execution frameworks, or automated security-testing platforms. - Experience with vulnerability research, penetration testing, or adversarial evaluation of agent systems, including turning findings into reproducible tests and effective controls. - Experience deploying or securing self-hosted inference and open-source models, including isolation of model-serving workloads and protection of sensitive inputs and outputs.

About Harvey

Legal / Compliance / Risk; AI / Data / Infrastructure — AI platform for legal and professional services work.

Similar roles