RefolkCandidates
Open nowEngineeringSecuritySecurity

Senior Product Security Engineer

Harvey · San Francisco

Location
San Francisco
Workplace
Remote
Employment
Full time
Level
Senior
Posted
3 weeks ago

About this role

Why Harvey

At Harvey, we’re transforming how legal and professional services operate. By combining frontier agentic AI, an enterprise-grade platform, and deep domain expertise, we’re reshaping how critical knowledge work gets done for decades to come.

This is a rare chance to help build a generational company at a true inflection point. We have strong product-market fit and world-class investor support. We’re scaling fast and defining a new category in real time. The work is ambitious, the bar is high, and the opportunity for growth - personal, professional, and financial - is unmatched.

Our team moves fast, takes ownership, and is deeply committed to the mission - operating with intensity, staying close to our customers, and pushing each other for excellence. We live by three values: Decisiveness, Simplicity, and Job's Not Finished. We act quickly on clear judgment over perfect information, we believe simplicity is what scales, and we're never satisfied with where we are. If you want to do the best work of your career alongside people who share that drive, we'd love to build with you.

At Harvey, the future of professional services is being written today - and we’re just getting started.

Role Overview

As a Senior Software Engineer on the Product Security team at Harvey, you'll be a key technical contributor shaping how security is built into our AI platform. We store and process our customers’ most sensitive data, and as a result, security is paramount at every stage of our product lifecycle. You'll own the security of critical product areas, conduct deep vulnerability research and code review, and partner closely with engineering teams to raise the security bar in the areas you work in (both for humans and agents). You’ll implement both technical controls and security features within the Harvey platform.

Our security program is driven by our collective offensive security experience: breaking into systems at other companies (in white-hat capacities), responding to real security incidents, and learning from other companies’ data breaches. We regularly conduct penetration tests and red team exercises with external security firms. At the same time, we are all software engineers - contributing code daily and approaching security with an engineering-first mindset.

What You’ll Do

  • Help define and implement security standards across the teams you partner with

  • Incorporate secure design principles at every stage of development

  • Own and review security-critical code across key parts of the product, including authentication and access control

  • Build secure-by-default libraries and tooling that make secure path easier for the engineers

  • Drive mitigation during security-related incidents, working cross-functionally as needed with Detection & Response as well as other teams

  • Mentor engineers and raise the security bar across teams through code reviews, design reviews, and technical guidance

What You Have

  • 5+ years of experience in product security, application security, offensive security, and/or security-focused software engineering

  • Long track record of identifying and remediating software vulnerabilities, demonstrated through CVEs, bug bounty awards, published research, or prior work experience

  • Ability to collaborate on cross-functional security initiatives and influence engineering teams on security best practices

  • Experience educating engineers to improve security practices across a team

  • Strong programming skills with demonstrated experience writing high-quality, production software

  • Strong communication and collaboration skills across technical and non-technical audiences

  • Track record of executing on complex security projects and delivering measurable security improvements

Nice to Have

  • Experience building security programs or practices at hyper-growth startups

  • Background with cloud environments (Azure, GCP, AWS) and cloud-native security patterns

  • Experience with AI/ML systems and emerging security considerations for LLM-based applications

Compensation Range

$188,000-282,000 USD

Depending on your location, an Applicant Privacy Notice may apply to you. You can find all of our Applicant Privacy Notices [here].

#LI-KV1

Harvey is an equal opportunity employer and does not discriminate on the basis of race, gender, sexual orientation, gender identity/expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or related condition, or any other basis protected by law.

We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made by emailing accommodations@harvey.ai

As published by Harvey. Applications are handled on their site.

Skills this posting mentions

Product SecurityArtificial IntelligenceOffensive Security

About Harvey

Harvey is a generative AI company backed by Sequoia and OpenAI's startup fund building the future of professional services.

All 330 openings at Harvey

One click, then it is written

Apply to Harvey with a resume written for this role.

Queue Senior Product Security Engineer and I read the posting, rewrite your resume against it, draft the cover letter, and score the fit. Then you press send, or press one button and I fill in Harvey’s form for you.

  1. 01Drop your resume

    A PDF or a LinkedIn URL. About a minute, once.

  2. 02I rank the openings

    Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.

  3. 03Each one is written up

    Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.

  • 25 sent a week, free
  • No card
  • Nothing sent until you say so

More roles at Harvey

See all

Similar roles elsewhere

See more

Put this to work

Paste your career in once. Every application after that is written for you.

Drop a resume or a LinkedIn URL. I rank the live openings against it, rewrite the resume and write a cover letter for the best of them, and fill in the employer's form when you press the button. You read, you decide what goes out.

  1. 01Drop your resume

    A PDF or a LinkedIn URL. About a minute, once.

  2. 02I rank the openings

    Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.

  3. 03Each one is written up

    Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.

  • New matches ranked and written before you are up.
  • Every bullet stays inside what your history supports. Nothing invented.
  • Queued, submitted, interviewing, offer: one screen, not a spreadsheet.

500 free credits on sign-up. No card. Nothing is sent until you say so.

Listed from the job board Harvey publishes. Refolk is not the employer and does not handle their hiring. Applications go to Harvey directly.