Senior Software Engineer, Product Security

Harvey Harvey · AI Frontier · San Francisco, CA · Security

Senior Software Engineer on the Product Security team at Harvey, focusing on building security into their AI platform. Responsibilities include owning security of critical product areas, vulnerability research, code review, implementing technical controls and security features, and mentoring engineers. The role emphasizes an engineering-first mindset and leverages offensive security experience.

What you'd actually do

  1. Help define and implement security standards across the teams you partner with
  2. Incorporate secure design principles at every stage of development
  3. Own and review security-critical code across key parts of the product, including authentication and access control
  4. Build secure-by-default libraries and tooling that make secure path easier for the engineers
  5. Drive mitigation during security-related incidents, working cross-functionally as needed with Detection & Response as well as other teams

Skills

Required

  • 5+ years of experience in product security, application security, offensive security, and/or security-focused software engineering
  • Ability to collaborate on cross-functional security initiatives and influence engineering teams on security best practices
  • Experience educating engineers to improve security practices across a team
  • Strong programming skills with demonstrated experience writing high-quality, production software
  • Strong communication and collaboration skills across technical and non-technical audiences

Nice to have

  • Experience building security programs or practices at hyper-growth startups
  • Background with cloud environments (Azure, GCP, AWS) and cloud-native security patterns
  • Experience with AI/ML systems and emerging security considerations for LLM-based applications

What the JD emphasized

  • security is paramount at every stage of our product lifecycle
  • own the security of critical product areas
  • partner closely with engineering teams to raise the security bar
  • implement both technical controls and security features
  • collective offensive security experience
  • regularly conduct penetration tests and red team exercises
  • software engineers - contributing code daily and approaching security with an engineering-first mindset
  • Long track record of identifying and remediating software vulnerabilities, demonstrated through CVEs, bug bounty awards, published research, or prior work experience
  • Track record of executing on complex security projects and delivering measurable security improvements