Senior Software Engineer, Security

Harvey

$220K — $330K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of software engineering experience with a proven track record in production services
  • Hands-on experience with security infrastructure components like IAM, authentication/authorization, and secrets management
  • Ability to analyze system vulnerabilities from an attacker's perspective
  • Strong programming capabilities with a willingness to tackle various tech stacks
  • Experience with coding tools designed for agentic systems (e.g., Claude Code, Codex)
  • Familiarity with cloud environments such as Azure, GCP, or AWS
  • Proven ability to translate security requirements into scalable engineering solutions
  • Excellent communication skills to influence teams without authority

Responsibilities

  • Design and operate core security services including authentication and access governance
  • Take ownership of the identity infrastructure, including SSO and SCIM
  • Create secure-by-default libraries and self-service tools for engineers
  • Establish systems from initial concept to production-grade reliability
  • Contribute to incident response and mitigation of security incidents
  • Enhance the overall security awareness and practices within the engineering team

Benefits

  • Opportunity to work on impactful security solutions for a rapidly growing company
  • Be part of a security engineering culture that prioritizes outcomes over gatekeeping
  • Chance to influence and mentor engineering teams on best security practices
  • Access to professional development opportunities within an innovative environment
Full Job Description
Role Overview

As a Senior Software Engineer on the Security Engineering team at Harvey, you'll build and operate the foundational security services every other engineer at Harvey depends on: identity and access management, secrets and privileged access, and the tooling that makes the secure path the fast path. You'll design these systems, write the code, run them in production, and own the results. Agentic systems make this harder than it is at a typical SaaS company: when an AI agent acts on a user's behalf against their most sensitive documents, identity and authorization stop being solved problems.

Security at Harvey is an engineering discipline, not a gatekeeper function. We build platforms and libraries that make it hard for engineers to get security wrong, and we measure ourselves on adoption and outcomes rather than tickets filed. Our program is informed by risk: we invest where the actual exposure to our customers' data is greatest, rather than where a framework tells us to.

What You'll Do
  • Design, build, and operate Harvey's core security services - authentication, authorization, access governance, secrets management, and privileged access - across workforce, infrastructure, and production environments
  • Own Harvey's identity infrastructure end-to-end, including SSO, SCIM, and the fine-grained authorization our enterprise customers require
  • Build secure-by-default libraries, paved-road abstractions, and self-service tooling so engineering teams can identify, remediate, and prevent security issues without waiting on us
  • Take these systems from greenfield to production-grade: define the architecture, ship it, instrument it, and own its reliability
  • Contribute to incident response and drive technical mitigation when security issues surface
  • Raise the security bar across engineering through design reviews, code reviews, and technical mentorship
What You Have
  • 5+ years of software engineering experience with a track record of shipping and operating production services
  • Hands-on experience building security infrastructure - IAM, authn/authz, secrets management, or privileged access
  • Working knowledge of common vulnerability classes and the ability to reason about how a system fails under an attacker, not just under load
  • Strong programming skills and a willingness to work across the stack and across unfamiliar domains
  • Fluency building and maintaining production services with agentic coding tools (Claude Code, Codex, or similar) - you know how to get real leverage from them and where they need supervision
  • Experience with cloud infrastructure (Azure, GCP, or AWS) and modern distributed system patterns
  • Demonstrated ability to turn security requirements into scalable engineering solutions rather than manual process
  • Strong communication and collaboration skills; you can influence engineering teams without formal authority
Nice to Have
  • Experience building security platforms or programs at hyper-growth startups
  • Background in developer platform or infrastructure engineering
  • Experience with SCIM, OIDC/SAML, policy engines (OPA, Cedar, Zanzibar-style systems), or hardware-backed credentials
  • Experience in highly regulated enterprise environments
Compensation

$220,000 - $330,000 USD

Depending on your location, an Applicant Privacy Notice may apply to you. You can find all of our Applicant Privacy Notices here.

#LI-AH1

Similar Jobs

More Jobs at Harvey

More Information Technology Jobs

Find similar Senior Software Engineer, Security jobs: