Software Engineer, Security

Harvey

$130K — $155K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 2+ years of software engineering experience with production services
  • Experience with security infrastructure (identity and access management, authentication, secrets management)
  • Strong programming and debugging skills across diverse systems
  • Familiarity with cloud platforms (Azure, GCP, AWS) and distributed system patterns
  • Proven ability to automate security requirements into manageable systems
  • Experience with agentic coding tools and workflows
  • Strong communication skills for conveying technical risks and decisions
  • Understanding of common vulnerability classes and system failure under attack.

Responsibilities

  • Build and manage identity and access services for product and infrastructure
  • Enhance user experience for security configurations while ensuring security by default
  • Develop controls and monitoring systems for least privilege access
  • Create secure libraries and automation tools for security management processes
  • Lead security systems from design to operational reliability
  • Participate in on-call rotation and incident response for security services
  • Conduct design reviews, code reviews, and improve documentation standards.

Benefits

  • Collaborative team environment focused on engineering-driven security
  • Opportunity to work on foundational security services for cutting-edge technology
  • Hands-on involvement in building robust security solutions
  • Exposure to a range of security protocols and tools
  • Culture of continuous improvement and learning in security practices.
Full Job Description
Role Overview

As a Software Engineer on the Security Engineering team at Harvey, you'll build and operate foundational security services for both our customer-facing product and the internal systems our workforce depends on: identity and access management, secrets and privileged access, agent sandboxes, and tooling that makes the secure path the fast path. You'll turn security needs into production systems and own the reliability and security of what you build, working closely with engineers and partner teams along the way. Attackers increasingly operate at agent speed, so we're building defenses that can keep pace.

Security at Harvey is an engineering discipline, not a gatekeeper function. We build platforms and libraries that make it hard for engineers to get security wrong, and we measure ourselves on adoption and outcomes rather than tickets filed. Our program is informed by risk: we invest where the actual exposure to our most sensitive data and resources is greatest, rather than where a framework tells us to.

What You'll Do
  • Build and operate Harvey's core identity and access services across customer-facing product, workforce, and infrastructure systems, including authentication, authorization, access governance, secrets, and privileged access
  • Evolve how Harvey customers set up and manage their environments, making security-critical configuration-from identity and access to policies and integrations-delightful to use and secure by default
  • Build identity controls, sandboxes, and safety harnesses that let services and AI agents operate with least privilege, constrained actions, clear auditability, and effective monitoring
  • Create secure-by-default libraries, paved-road abstractions, self-service tooling, and agentic workflows that automate security triage, remediation, and evidence collection
  • Take security systems from design through production, accounting for trust boundaries, attacker paths, and operational failure modes while owning their reliability and security
  • Share an on-call rotation for Harvey's mission-critical security services, contribute to incident response, and raise the engineering bar through design reviews, code reviews, and clear documentation


What You Have
  • 2+ years of software engineering experience, including experience shipping and operating production services
  • Experience building or contributing to security infrastructure such as identity and access management, authentication and authorization, secrets management, or privileged access
  • Strong programming, debugging, testing, and problem-solving skills, with the ability to work across unfamiliar systems and domains
  • Experience with cloud infrastructure such as Microsoft Azure, Google Cloud Platform, or Amazon Web Services and familiarity with modern distributed-system patterns
  • A track record of translating security requirements into maintainable, automated systems
  • Experience using agentic coding tools and creating workflows that automate repetitive security work, with the judgment to review their output critically and measure whether they improve security outcomes
  • Clear communication and collaboration skills, including the ability to explain technical risks, decisions, and tradeoffs to engineering partners
  • Working knowledge of common vulnerability classes and the ability to reason about how a system fails under an attacker, not just under load


Nice to Have
  • Experience building security infrastructure at a fast-growing company
  • Experience with SCIM; OpenID Connect (OIDC); Security Assertion Markup Language (SAML); policy engines such as Open Policy Agent (OPA), Cedar, or Zanzibar-style systems; or hardware-backed credentials
  • Experience securing agentic or AI-powered systems, especially systems that act on behalf of users against sensitive data
  • Experience working in a highly regulated enterprise environment

Similar Jobs

More Jobs at Harvey

More Information Technology Jobs

Find similar Software Engineer, Security jobs: