Staff Corporate Security Engineer

Harvey Harvey · AI Frontier · New York, NY · Security

This role joins Harvey's corporate security function, which secures the company's IT and business systems as Harvey grows rapidly, balancing risk with user experience while validating every assumption through threat modeling and real-world testing. It is a strong fit for someone at the intersection of security engineering and enterprise systems.

What you'd actually do

  1. Design, implement, and govern security controls for cross-application data flows, API integrations, OAuth connections, and third-party SaaS platforms. Own the security review lifecycle for new integrations and automate posture monitoring to catch drift early.
  2. Continue to build and operate Harvey's legal hold infrastructure, including data preservation, collection workflows, and custodian management. Partner with Legal and Compliance to meet litigation readiness requirements across our collaboration and productivity stack.
  3. Provide security oversight across the SaaS application lifecycle — vendor onboarding assessments, ongoing configuration review, and decommissioning.
  4. Support endpoint security policies and vulnerability management, ensuring endpoint telemetry feeds into detection and response workflows.
  5. Develop scripts and integrations that extend visibility across corporate systems, partnering with the Detection & Response team to surface signals from SaaS and business applications.

Skills

Required

  • Python
  • Go
  • Terraform
  • Pulumi
  • SAML
  • OIDC
  • SCIM
  • X.509
  • Okta
  • Google Workspace
  • Salesforce
  • Workday
  • NetSuite
  • Microsoft Entra/Azure/Intune
  • JAMF
  • Tines

Nice to have

  • eDiscovery workflows
  • legal holds
  • Purview
  • Vault
  • Relativity
  • Everlaw

What the JD emphasized

  • security controls for cross-application data flows, API integrations, OAuth connections, and third-party SaaS platforms
  • security review lifecycle for new integrations
  • eDiscovery and legal hold programs
  • data preservation workflows, custodian management
  • security oversight across the SaaS application lifecycle
  • endpoint security policies and vulnerability management
  • Security Detection & Response
  • scripts and integrations that extend visibility across corporate systems
  • Demonstrated experience securing enterprise SaaS environments
  • integration security, API token management, OAuth governance, and cross-application data flow risk
  • working knowledge of authentication/authorization standards (SAML, OIDC, SCIM, X.509)
  • ability to debug real-world integration failures
  • Experience building or managing eDiscovery and legal hold programs
  • data preservation workflows, custodian management, and coordination with Legal and outside counsel
  • Strong software engineering fundamentals with proficiency in Python and/or Go
  • building integrations against SaaS APIs
  • infrastructure-as-code tooling such as Terraform and/or Pulumi
  • Ability to identify risks and vulnerabilities in IT and business systems
  • communicate that risk clearly to stakeholders
  • Familiarity with endpoint security for macOS and Windows environments
  • experience with tools such as Okta, Google Workspace, Salesforce, Workday, NetSuite, Microsoft Entra/Azure/Intune, JAMF, Tines, or similar platforms
  • 4+ years of experience in security engineering, corporate engineering, IT, or a related program management function with a security focus