Staff Product Security Engineer

Harvey Harvey · AI Frontier · San Francisco, CA · Security

Staff Software Engineer on the Product Security team at Harvey, responsible for shaping how security is built into their AI platform. The role involves defining and owning the product security roadmap, establishing security posture, partnering with engineering teams, reviewing security-critical code, architecting secure libraries, driving mitigation strategies during incidents, and mentoring engineers. The company emphasizes its AI platform and the need for security at every stage of the product lifecycle.

What you'd actually do

  1. Define and own the product security roadmap, prioritizing initiatives based on risk, business impact, and engineering org maturity.
  2. Establish and evolve security posture across the engineering organization, setting standards that scale with the company
  3. Partner with Product Engineering, Infrastructure, and Platform teams to incorporate secure design principles at every stage of development
  4. Own and review security-critical code across key parts of the product, including authentication and access control
  5. Architect secure-by-default libraries and tools that make the secure path the easiest choice for developers

Skills

Required

  • 8+ years of experience in product security, application security, offensive security, and/or security-focused software engineering
  • Long track record of identifying and remediating software vulnerabilities, demonstrated through CVEs, bug bounty awards, published research, or prior work experience
  • Track record of leading complex cross-functional security initiatives and delivering measurable improvements, with demonstrated ability to influence engineering teams without direct authority.
  • Experience mentoring senior engineers and developing security talent within an engineering organization
  • Strong programming skills with demonstrated experience writing high-quality, production software
  • Excellent communication and collaboration skills, particularly when translating security risks into business terms for non-security stakeholders

Nice to have

  • Experience building security programs or practices at hyper-growth startups
  • Background with cloud environments (Azure, GCP, AWS) and cloud-native security patterns
  • Experience with AI/ML systems and emerging security considerations for LLM-based applications

What the JD emphasized

  • security is paramount at every stage of our product lifecycle
  • security-critical code
  • secure-by-default libraries and tools