Staff Corporate Security Engineer
harveyUSAFull Time2d ago
PythonGoAzureTerraformAISecurityComplianceSaaSLegalSupportGrowthEngineering
Job description
Staff Corporate Security Engineer at harvey.
About the role
Join harvey's corporate security team to safeguard IT and business systems as the company expands. This role focuses on balancing security with user experience, using threat modeling and real-world testing to validate assumptions. It's ideal for someone who understands data flow in SaaS applications and can build scalable security controls.
Key facts
What you'll do
- Design, implement, and manage security controls for data flows, API integrations, and third-party SaaS platforms.
- Oversee the security review process for new integrations and automate posture monitoring.
- Develop and maintain harvey's legal hold infrastructure, including data preservation and custodian management.
- Collaborate with Legal and Compliance to ensure readiness for litigation across productivity tools.
- Provide security oversight for SaaS applications throughout their lifecycle, from vendor assessment to decommissioning.
- Support endpoint security policies and vulnerability management, integrating endpoint data into detection and response.
- Create scripts and integrations to enhance visibility across corporate systems, assisting the Detection & Response team.
Requirements
- Proven experience securing enterprise SaaS environments, including integration security, API token management, and OAuth governance.
- Working knowledge of authentication/authorization standards like SAML, OIDC, SCIM, and X.509, with the ability to debug integration issues.
- Experience building or managing eDiscovery and legal hold programs, including data preservation and custodian coordination.
- Strong software engineering skills in Python or Go, including building integrations with SaaS APIs.
- Experience with infrastructure-as-code tools like Terraform or Pulumi for managing security configurations.
- Ability to identify risks in IT and business systems and clearly communicate them to various stakeholders.
- Familiarity with endpoint security for macOS and Windows.
- 4+ years of experience in security engineering, corporate engineering, IT, or a security-focused program management role.
Nice to have
- Familiarity with eDiscovery tools such as Purview, Vault, Relativity, or Everlaw.
- Curiosity about generative AI or the legal industry.
Skills & tools
- Python
- Go
- Terraform
- Pulumi
- SAML
- OIDC
- SCIM
- X.509
- Okta
- Google Workspace
- Salesforce
- Workday
- NetSuite
- Microsoft Entra/Azure/Intune
- JAMF
- Tines
Practical notes
- This is a hybrid work role.
- Compensation includes equity and bonus.