SlipstreamJobsFresh Startup & VC-Backed Jobs

Staff Software Engineer, Secure Execution

Harvey - San Francisco, CA, United States - In-office - posted 2026-09-30

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 231,000 - 346,400 / annual

Harvey is an AI platform for legal and professional services, combining frontier agentic AI with enterprise-grade infrastructure and deep domain expertise. As a Staff Software Engineer on the Security Engineering team, you will join as a founding member to build the security foundations enabling Harvey to deploy increasingly capable AI agents safely and effectively. You will lead development of a platform for security agents to discover and validate vulnerabilities automatically, including through authorized penetration testing, while protecting sensitive data and systems. A central challenge is enabling models with advanced cybersecurity capabilities to operate within secure boundaries—you'll design execution environments, orchestration, and controls that balance containment with the reliability, performance, and flexibility that useful agents require. Key responsibilities include: - Setting technical direction for secure agent execution across Security, Infrastructure, and Product Engineering teams, translating emerging capabilities and risks into concrete roadmaps. - Designing, building, and operating a platform for security agents to discover and validate vulnerabilities within authorized targets, producing reproducible evidence for engineers. - Building reusable controls for agent tool use, code execution, network and filesystem access, resource consumption, and workload lifecycle management. Integrating with identity and secrets platforms to enforce least-privilege access. - Partnering with product sandbox and internal agent platform teams on architectural decisions, implementing protections, and integrating shared security capabilities. - Enabling internal use of open-source models alongside infrastructure teams, building protections around model serving, agent execution, and sensitive-data handling. - Developing adversarial tests, evaluations, and telemetry to verify containment and expose failures. Building mechanisms to scope, observe, interrupt, and safely terminate agent activity. - Leading delivery and adoption across teams, mentoring engineers, and remaining hands-on through implementation and production operation, making clear tradeoffs across security, reliability, latency, and cost. REQUIREMENTS: - 10+ years developing and running production software, including technical leadership on initiatives spanning multiple engineering teams. - Strong software engineering skills in languages such as Go, Rust, Python, or C++, with practical experience in Linux systems, networking, and containerized infrastructure. - Deep expertise in one or more areas of execution security, such as sandboxing, operating-system isolation, container or virtual-machine security, or platforms that execute untrusted code. Ability to translate threats into enforceable boundaries and test how those boundaries fail. - Experience building shared platforms, services, or libraries and helping other teams adopt them through clear interfaces, documentation, and safe migrations. - Experience with cloud infrastructure and distributed systems, including observability, failure handling, capacity management, and dependable production operation. - Fluency with AI-assisted engineering and agentic workflows: using models to accelerate development, validating their output, and reasoning about risks when agents use tools, execute code, or access sensitive data. - Strong communication and technical judgment, with a record of bringing teams to agreement on ambiguous problems and carrying decisions through to delivery. NICE TO HAVE: - Experience with microVMs, hypervisors, or sandbox runtimes such as Firecracker, gVisor, or Kata Containers, or Linux isolation mechanisms such as namespaces, seccomp, and Landlock. - Experience building agent runtimes, tool-execution frameworks, or automated security-testing platforms. - Experience with vulnerability research, penetration testing, or adversarial evaluation of agent systems. - Experience deploying or securing self-hosted inference and open-source models.

About Harvey

Legal / Compliance / Risk; AI / Data / Infrastructure — AI platform for legal and professional services work.

Similar roles