Staff Product Security Engineer

Harvey Harvey · AI Frontier · New York, NY · Security

Staff Software Engineer, Product Security at Harvey, focusing on building security into their AI platform from the ground up. Responsibilities include defining the security roadmap, establishing security posture, partnering with engineering teams, reviewing security-critical code, architecting secure libraries, driving incident response, and mentoring engineers. Requires 8+ years of experience in product security, application security, or offensive security, with a strong track record of identifying and remediating vulnerabilities and leading cross-functional security initiatives. Experience with AI/ML systems and cloud environments is a plus.

What you'd actually do

  1. Define and own the product security roadmap, prioritizing initiatives based on risk, business impact, and engineering org maturity.
  2. Establish and evolve security posture across the engineering organization, setting standards that scale with the company
  3. Partner with Product Engineering, Infrastructure, and Platform teams to incorporate secure design principles at every stage of development
  4. Own and review security-critical code across key parts of the product, including authentication and access control
  5. Architect secure-by-default libraries and tools that make the secure path the easiest choice for developers

Skills

Required

  • product security
  • application security
  • offensive security
  • security-focused software engineering
  • identifying and remediating software vulnerabilities
  • leading complex cross-functional security initiatives
  • influencing engineering teams
  • mentoring senior engineers
  • developing security talent
  • high-quality production software development
  • communication
  • collaboration
  • translating security risks into business terms

Nice to have

  • building security programs at hyper-growth startups
  • cloud environments (Azure, GCP, AWS)
  • cloud-native security patterns
  • AI/ML systems
  • emerging security considerations for LLM-based applications

What the JD emphasized

  • security is paramount at every stage of our product lifecycle
  • security-critical code
  • secure-by-default libraries
  • security-related incident responses
  • security talent