All jobs

Staff Software Engineer, Product Security

100% Remote Full-time Open now

Why Harvey At Harvey, we’re transforming how legal and professional services operate — not incrementally, but end-to-end. By combining frontier agentic AI, an enterprise-grade platform, and deep domain expertise, we’re reshaping how critical knowledge work gets done for decades to come. This is a rare chance to help build a generational company at a true inflection point. With 1000+ customers in 58+ countries, strong product-market fit, and world-class investor support, we’re scaling fast and defining a new category in real time. The work is ambitious, the bar is high, and the opportunity for growth — personal, professional, and financial — is unmatched. Our team is sharp, motivated, and deeply committed to the mission. We move fast, operate with intensity, and take real ownership of the problems we tackle — from early thinking to long-term outcomes. We stay close to our customers — from leadership to engineers — and work together to solve real problems with urgency and care. If you thrive in ambiguity, push for excellence, and want to help shape the future of work alongside others who raise the bar, we invite you to build with us. At Harvey, the future of professional services is being written today — and we’re just getting started. Role Overview As a Staff Software Engineer on the Product Security team at Harvey, you'll play a critical role in shaping how security is built into our AI platform from the ground up. We store and process our customers’ most sensitive data, and as a result, security is paramount at every stage of our product lifecycle. You'll take ownership of securing critical parts of the product while driving high-leverage security initiatives that raise the bar for the entire engineering org — balancing hands-on technical work with cross-functional leadership and mentorship. You’ll lead and implement both technical controls and security features within the Harvey platform. Our security program is driven by our collective offensive security experience: breaking into systems at other companies (in white-hat capacities), responding to real security incidents, and learning from other companies’ data breaches. We regularly conduct penetration tests and red team exercises with external security firms. At the same time, we are all software engineers - contributing code daily and approaching security with an engineering-first mindset. What You’ll Do

  • Establish and evolve security posture across the engineering organization, setting standards that scale with the company
  • Partner with Product Engineering, Infrastructure, and Platform teams to incorporate secure design principles at every stage of development
  • Own and review security-critical code across key parts of the product, including authentication and access control
  • Architect secure-by-default libraries and tools that make the secure path the easiest choice for developers
  • Drive mitigation strategies during security-related incident responses, coordinating cross-functional efforts
  • Mentor engineers and raise the security bar across teams through code reviews, design reviews, and technical guidance

What You Have

  • 8+ years of experience in product security, application security, offensive security, and/or security-focused software engineering
  • Long track record of identifying and remediating software vulnerabilities, demonstrated through CVEs, bug bounty awards, published research, or prior work experience
  • Demonstrated ability to lead cross-functional security initiatives and influence engineering teams without direct authority
  • Experience mentoring engineers and raising the quality bar of software engineering teams on security practices
  • Strong programming skills with demonstrated experience writing high-quality, production software
  • Excellent communication and collaboration skills, particularly when translating security risks into business terms for non-security stakeholders
  • Track record of leading complex cross-functional projects and delivering measurable security improvements

Nice to Have

  • Experience building security programs or practices at hyper-growth startups
  • Background with cloud environments (Azure, GCP, AWS) and cloud-native security patterns
  • Experience with AI/ML systems and emerging security considerations for LLM-based applications

Compensation

Range $238,000 - $312,000 USD Please find our CA applicant privacy notice here. #LI-KV1 Harvey is an equal opportunity employer and does not discriminate on the basis of race, gender, sexual orientation, gender identity/expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or related condition, or any other basis protected by law. We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made by emailing [email protected] Apply tot his job Apply To this Job

You might also like

Project Manager - Cybersecurity

100% Remote Full-time

Cyber Security Software Engineer

100% Remote Full-time

Senior Analyst, Cyber Security GRC (Penetration Tester)

100% Remote Full-time

Test Engineer Security Clearance

100% Remote Full-time

VP of Paid Search

100% Remote Full-time

Senior Accountant, Financial Reporting & Technical Accounting

100% Remote Full-time

Senior Accountant (Remote in US)

100% Remote Full-time

Senior Legal Counsel, Privacy (Remote)

100% Remote Full-time

Senior Legal Counsel, Fiduciary Litigation job at Northern Trust in Chicago, IL

100% Remote Full-time

Sr Consultant - Education

100% Remote Full-time

Global Live Operations Specialist

100% Remote Full-time

Experienced Part-Time Customer Support Representative – Remote Opportunity at arenaflex

100% Remote Full-time

Food Service Cleaner

100% Remote Full-time

Remote Data Entry Operator – Full‑Time & Part‑Time Roles in Data Management, Quality Assurance, and Remote Collaboration

100% Remote Full-time

Remote Supported Education Counselor - Empowering Individuals with Mental Health Challenges to Achieve Educational Success through Personalized Support and Guidance

100% Remote Full-time

Oracle Health Clinical Informaticist Site Practitioner

100% Remote Full-time

[Hiring] Virtual Safety Companion @Mercy Health

100% Remote Full-time

[Remote] Mobile Developer (IOS & Android - 2 Separate Roles)

100% Remote Full-time

R&D Engineer - SVD

100% Remote Full-time

Senior Software Engineer | CARE

100% Remote Full-time