Senior Software Engineer, Security
harveyUSAFull Time2d ago
AWSAzureGCPClaudeAISecuritySaaSLegalSupportGrowthSolutionsEngineering
Job description
Senior Software Engineer, Security at harvey.
About the role
Join harvey's Security Engineering team to develop and manage the core security services that underpin all engineering efforts. This role involves building critical infrastructure for identity, access, and secrets management, with a focus on securing agentic AI systems. You will be responsible for designing, coding, and operating these systems in a production environment.
Key facts
What you'll do
- Design, construct, and operate harvey's essential security services, covering authentication, authorization, access governance, and secrets management across all environments.
- Manage harvey's identity infrastructure from end-to-end, including single sign-on (SSO), SCIM, and detailed authorization for enterprise clients.
- Create secure-by-default libraries, standardized abstractions, and self-service tools to empower engineering teams in identifying, resolving, and preventing security issues independently.
- Guide new systems from initial concept through to production, defining architecture, deploying, instrumenting, and ensuring their reliability.
- Participate in incident response and lead technical resolutions when security problems arise.
- Elevate security standards across engineering through design and code reviews, and by providing technical guidance.
Requirements
- 5 or more years of experience in software engineering, with a history of deploying and maintaining production services.
- Practical experience building security infrastructure, such as Identity and Access Management (IAM), authentication/authorization, secrets management, or privileged access.
- Understanding of common vulnerability types and the ability to anticipate system failures under attack, not just under heavy load.
- Strong programming skills and a willingness to work across different parts of the tech stack and unfamiliar domains.
- Proficiency in developing and maintaining production services using agentic coding tools like Claude Code or Codex, understanding their effective use and when supervision is needed.
- Experience with cloud infrastructure (Azure, GCP, or AWS) and contemporary distributed system designs.
- Demonstrated ability to convert security requirements into scalable engineering solutions rather than manual processes.
- Excellent communication and collaboration skills, capable of influencing engineering teams without formal authority.
Nice to have
- Experience establishing security platforms or programs at rapidly growing startups.
- Background in developer platform or infrastructure engineering.
- Familiarity with SCIM, OIDC/SAML, policy engines (OPA, Cedar, Zanzibar-style systems), or hardware-backed credentials.
- Experience in highly regulated enterprise settings.
Skills & tools
- IAM
- Authn/Authz
- Secrets Management
- Privileged Access
- SSO
- SCIM
- Claude Code
- Codex
- Azure
- GCP
- AWS
Practical notes
An Applicant Privacy Notice may apply depending on your location. Requests for reasonable accommodations for disabilities can be made by emailing accommodations@harvey.ai.