Staff Security Software Engineer, IAM

Harvey

$231K — $340K *
Enterprise Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 10+ years of experience in building and operating production software with multi-domain impact.
  • Deep expertise in identity and access engineering: authentication, federation, authorization, entitlement modeling, or privileged access.
  • Practical experience utilizing AI-assisted development tools with strong engineering judgment.
  • Experience designing identity or authorization platforms for engineering teams.
  • Proven track record in delivering foundational systems with meaningful adoption and outcomes.
  • Familiarity with cloud infrastructure (Azure, GCP, AWS) and modern distributed-system patterns.
  • Excellent communication skills for aligning technical and non-technical stakeholders.

Responsibilities

  • Define a multi-year technical strategy for identity and access management at Harvey.
  • Design and build complex, production-ready identity systems from scratch.
  • Lead cross-functional initiatives for scaling access management across multiple domains.
  • Extend the identity model to include AI agents for authenticated, auditable access.
  • Serve as a technical authority, guiding design reviews and roadmap decisions.

Benefits

  • Join a founding team in a crucial and innovative security role.
  • Be at the forefront of implementing AI in access management.
  • Opportunities for significant influence on technical strategy and cross-functional alignment.
  • Work in a fast-paced environment that encourages autonomy and creativity.
Full Job Description
Role Overview

As a Staff Software Engineer on the Security Engineering team, you will be a founding member of the team and define and drive the technical strategy for identity and access at Harvey - both how customers authenticate to Harvey, as well as how internal employees, contractors, and non-human identities access company systems, what they are authorized to do, and how seamlessly access adapts as needs change.

Challenges ahead include exploring how AI-powered access management can understand employee needs, recommend appropriate permissions, streamline decisions, and adapt access as roles and responsibilities evolve, as well as shaping an end user/agent authentication experience that makes signing in to Harvey fast, consistent, reliable, and secure across every surface where our customers work.

You will operate at the boundary of security, infrastructure, and product engineering - turning ambitious business and technical requirements into durable identity platforms, clear architectural direction, and exceptional user experiences. This role is hands-on, but its primary leverage comes through technical direction, platform adoption, cross-functional alignment, and enabling other engineers to build on strong identity foundations.

What you'll do
  • Define Harvey's multi-year technical strategy for identity, authentication, authorization, and privileged access.
  • Design and build complex identity systems from greenfield - writing the code, instrumenting it, and owning it in production.
  • Lead the architecture and execution of cross-functional initiatives to right-size access at scale, spanning identity and authentication, permissions and authorization, entitlement modeling, and access controls.
  • Extend the identity model to non-human and agentic identities, so that AI agents acting on behalf of users are authenticated, scoped, and auditable.
  • Serve as the technical authority for identity and access architecture and guide major design reviews, investment decisions, and long-term roadmaps.
What You Have
  • 10+ years experience building and operating production software, with demonstrated impact across multiple teams or technical domains.
  • Deep expertise in several identity and access engineering domains - authentication, federation, authorization, entitlement modeling, or privileged access.
  • Fluency with AI: you use AI-assisted development tools effectively while applying strong engineering judgment, and you design agentic workflows that automate repetitive toil and improve how teams operate.
  • Experience designing identity or authorization platforms, libraries, or abstractions used by other engineering teams.
  • Experience delivering foundational systems that achieve meaningful adoption and improve organizational or customer outcomes.
  • Experience with cloud infrastructure, such as Azure, Google Cloud Platform, or Amazon Web Services, and modern distributed-system patterns.
  • Strong communication skills and the ability to create alignment across technical and non-technical stakeholders.


Nice to have
  • Experience with System for Cross-domain Identity Management (SCIM), OpenID Connect (OIDC), Security Assertion Markup Language (SAML), policy engines such as Open Policy Agent (OPA) or Cedar, Zanzibar-style authorization systems, or hardware-backed credentials.
  • Experience with identity governance and administration (IGA) or privileged access management (PAM) platforms, and with automating joiner, mover, and leaver workflows.
  • Experience building identity platforms or programs at a hyper-growth startup.
  • Experience with regulated environments such as FedRAMP, including phishing-resistant authentication and authenticator assurance requirements.


Compensation

$231,000 - $340,000 USD

Depending on your location, an Applicant Privacy Notice may apply to you. You can find all of our Applicant Privacy Notices [here].

#LI-NP1

Similar Jobs

More Jobs at Harvey

More Enterprise Technology Jobs

Find similar Staff Security Software Engineer, IAM jobs: