5 months ago
Base Salary
$220k - $330k/yr
Responsibilities
- Define and own the product security roadmap based on risk, business impact, and engineering maturity.
- Establish scalable security standards and evolve the engineering organization’s security posture.
- Partner with Product Engineering, Infrastructure, and Platform teams to apply secure design principles throughout development.
- Own and review security-critical product code, including authentication and access control.
- Architect secure-by-default libraries and tools that make secure development easier for engineers.
- Drive mitigation strategies during security incidents and coordinate cross-functional response efforts.
- Mentor engineers and raise security standards through code reviews, design reviews, and technical guidance.
Requirements
- 8+ years of experience in product security, application security, offensive security, and/or security-focused software engineering.
- Demonstrated record of identifying and remediating software vulnerabilities through CVEs, bug bounty awards, published research, or prior work experience.
- Experience leading complex cross-functional security initiatives and influencing engineering teams without direct authority.
- Experience mentoring senior engineers and developing security talent within an engineering organization.
- Strong programming skills and experience writing high-quality production software.
- Excellent communication and collaboration skills, including translating security risks into business terms for non-security stakeholders.
- Preferred experience building security programs at hyper-growth startups.
- Preferred background with Azure, GCP, AWS, and cloud-native security patterns.
- Preferred experience with AI/ML systems and security considerations for LLM-based applications.
Tech Stack
Categories
About Harvey
Harvey builds domain-specific generative AI for legal and other professional services, delivered as an enterprise platform and APIs to automate contract analysis, due diligence, compliance, and litigation workflows. Founded in 2022 and headquartered in San Francisco, it sells to law firms and corporate legal departments on enterprise agreements; investors include Sequoia Capital and OpenAI. Customers include multiple Am Law 100 firms and Fortune 500 companies’ legal teams.
