Staff Product Security Engineer

Harvey

$220K — $330K *
Enterprise Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 8+ years in product security, application security, or security-focused software engineering
  • Demonstrated history of identifying and fixing software vulnerabilities
  • Experience leading complex cross-functional security initiatives
  • Ability to mentor senior engineers and develop security talent
  • Strong programming skills in writing production software
  • Excellent communication skills, especially in translating security terms for non-security stakeholders

Responsibilities

  • Define and manage the product security roadmap
  • Enhance the security posture across the engineering organization
  • Collaborate with teams to incorporate secure design principles
  • Review and secure critical code areas like authentication
  • Architect secure libraries and tools for developers
  • Lead incident response strategies for security-related issues
  • Mentor team members and elevate security awareness through reviews

Benefits

  • Opportunity to define and build a product security program
  • Engage in hands-on technical work alongside leadership and mentorship
  • Part of a fast-scaling company with significant growth
  • Work with a team experienced in offensive security and real incident responses
  • Collaborative environment emphasizing secure design throughout product lifecycle
Full Job Description
Role Overview

As a Staff Software Engineer on the Product Security team at Harvey, you'll play a critical role in shaping how security is built into our AI platform from the ground up. We store and process our customers' most sensitive data, and as a result, security is paramount at every stage of our product lifecycle. You'll take ownership of securing critical parts of the product while driving high-leverage security initiatives that raise the bar for the entire engineering org - balancing hands-on technical work with cross-functional leadership and mentorship. This is a rare opportunity to define and build a product security program at a company scaling fast.

Our security program is driven by our collective offensive security experience: breaking into systems at other companies (in white-hat capacities), responding to real security incidents, and learning from other companies' data breaches. We regularly conduct penetration tests and red team exercises with external security firms. At the same time, we are all software engineers - contributing code daily and approaching security with an engineering-first mindset.

What You'll Do
  • Define and own the product security roadmap, prioritizing initiatives based on risk, business impact, and engineering org maturity.
  • Establish and evolve security posture across the engineering organization, setting standards that scale with the company
  • Partner with Product Engineering, Infrastructure, and Platform teams to incorporate secure design principles at every stage of development
  • Own and review security-critical code across key parts of the product, including authentication and access control
  • Architect secure-by-default libraries and tools that make the secure path the easiest choice for developers
  • Drive mitigation strategies during security-related incident responses, coordinating cross-functional efforts
  • Mentor engineers and raise the security bar across teams through code reviews, design reviews, and technical guidance


What You Have
  • 8+ years of experience in product security, application security, offensive security, and/or security-focused software engineering
  • Long track record of identifying and remediating software vulnerabilities, demonstrated through CVEs, bug bounty awards, published research, or prior work experience
  • Track record of leading complex cross-functional security initiatives and delivering measurable improvements, with demonstrated ability to influence engineering teams without direct authority.
  • Experience mentoring senior engineers and developing security talent within an engineering organization
  • Strong programming skills with demonstrated experience writing high-quality, production software
  • Excellent communication and collaboration skills, particularly when translating security risks into business terms for non-security stakeholders
    Nice to Have
    • Experience building security programs or practices at hyper-growth startups
    • Background with cloud environments (Azure, GCP, AWS) and cloud-native security patterns
    • Experience with AI/ML systems and emerging security considerations for LLM-based applications


Compensation

$220,000 - $330,000

Depending on your location, an Applicant Privacy Notice may apply to you. You can find all of our Applicant Privacy Notices [here].

#LI-KV1

Similar Jobs

More Jobs at Harvey

More Enterprise Technology Jobs

Find similar Staff Product Security Engineer jobs: