Senior Software Engineer, Security

Harvey Harvey · AI Frontier · San Francisco, CA · Security

Senior Software Engineer on the Security Engineering team at Harvey, responsible for building and operating foundational security services like identity and access management, secrets management, and privileged access. The role focuses on designing, coding, and running these systems in production, with a specific emphasis on the unique challenges posed by agentic AI systems operating on sensitive data. The goal is to build secure-by-default platforms and tooling to enable other engineering teams.

What you'd actually do

  1. Design, build, and operate Harvey's core security services — authentication, authorization, access governance, secrets management, and privileged access — across workforce, infrastructure, and production environments
  2. Own Harvey's identity infrastructure end-to-end, including SSO, SCIM, and the fine-grained authorization our enterprise customers require
  3. Build secure-by-default libraries, paved-road abstractions, and self-service tooling so engineering teams can identify, remediate, and prevent security issues without waiting on us
  4. Take these systems from greenfield to production-grade: define the architecture, ship it, instrument it, and own its reliability
  5. Contribute to incident response and drive technical mitigation when security issues surface

Skills

Required

  • 5+ years of software engineering experience with a track record of shipping and operating production services
  • Hands-on experience building security infrastructure — IAM, authn/authz, secrets management, or privileged access
  • Working knowledge of common vulnerability classes and the ability to reason about how a system fails under an attacker, not just under load
  • Strong programming skills and a willingness to work across the stack and across unfamiliar domains
  • Fluency building and maintaining production services with agentic coding tools (Claude Code, Codex, or similar)
  • Experience with cloud infrastructure (Azure, GCP, or AWS) and modern distributed system patterns
  • Demonstrated ability to turn security requirements into scalable engineering solutions rather than manual process
  • Strong communication and collaboration skills; you can influence engineering teams without formal authority

Nice to have

  • Experience building security platforms or programs at hyper-growth startups
  • Background in developer platform or infrastructure engineering
  • Experience with SCIM, OIDC/SAML, policy engines (OPA, Cedar, Zanzibar-style systems), or hardware-backed credentials
  • Experience in highly regulated enterprise environments

What the JD emphasized

  • identity and authorization stop being solved problems
  • agentic coding tools