Staff Corporate Security Engineer

Harvey

San Francisco (CA)

On-site

USD 220,000 - 330,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Harvey is seeking a security engineer to safeguard enterprise SaaS environments, manage eDiscovery and legal hold workflows, and strengthen integrations across the organization. You will partner with Legal, Compliance, and IT to uphold threat modeling and secure data flows.

Ideal candidates have 4+ years in security engineering, hands-on coding with Python/Go, and experience with IAM/OAuth standards, plus IaC tooling.

Qualifications

  • Demonstrated experience securing enterprise SaaS environments, with API token management and cross-application data flow risk.
  • Experience building or managing eDiscovery and legal hold programs, data preservation workflows, custodian management.
  • Strong software engineering fundamentals with Python and/or Go, and IaC tooling (Terraform/Pulumi).
  • Ability to identify risks in IT/business systems and communicate to stakeholders clearly.
  • Familiarity with endpoint security for macOS/Windows and tools like Okta, Google Workspace, Salesforce, NetSuite.

Responsibilities

  • Design, implement, and govern security controls for cross-application data flows and SaaS integrations.
  • Build and operate Harvey's eDiscovery and legal hold infrastructure in collaboration with Legal and Compliance.
  • Provide security oversight across the SaaS application lifecycle, including vendor onboarding and configuration review.
  • Support endpoint security policies and vulnerability management across systems.
  • Develop scripts and integrations to extend visibility and detect threats in enterprise apps.

Skills

SaaS security
eDiscovery programs
Python/Go coding
IaC tooling
OAuth/SAML/OIDC
Endpoint security
Risk communication
Security integrations

Tools

Purview
Vault
Relativity
Everlaw

Job description

Why Harvey

At Harvey, we're transforming how legal and professional services operate. By combining frontier agentic AI, an enterprise-grade platform, and deep domain expertise, we're reshaping how critical knowledge work gets done for decades to come.

Why Harvey

At Harvey, we're transforming how legal and professional services operate. By combining frontier agentic AI, an enterprise-grade platform, and deep domain expertise, we're reshaping how critical knowledge work gets done for decades to come. This is a rare chance to help build a generational company at a true inflection point. We have strong product-market fit and world-class investor support. We're scaling fast and defining a new category in real time. The work is ambitious, the bar is high, and the opportunity for growth - personal, professional, and financial - is unmatched. Our team moves fast, takes ownership, and is deeply committed to the mission - operating with intensity, staying close to our customers, and pushing each other for excellence. We live by three values: Decisiveness, Simplicity, and Job's Not Finished. We act quickly on clear judgment over perfect information, we believe simplicity is what scales, and we're never satisfied with where we are. If you want to do the best work of your career alongside people who share that drive, we'd love to build with you. At Harvey, the future of professional services is being written today - and we're just getting started.

Role Overview

Some of the world's largest companies and their law firms use Harvey's AI to deliver world-class client services at unprecedented scale, entrusting Harvey with their most sensitive documents in the process.

This role joins Harvey's corporate security function, which secures the company's IT and business systems as Harvey grows rapidly, balancing risk with user experience while validating every assumption through threat modeling and real-world testing rather than relying on best practice alone.

It is a strong fit for someone at the intersection of security engineering and enterprise systems- someone who understands how data flows between SaaS applications, can pinpoint where security breaks down in complex integrations, and knows how to build controls that scale. Experience with eDiscovery workflows and legal holds is a meaningful differentiator given the nature of Harvey's customer base.

What You'll Do
  • Enterprise Integrations & SaaS Security: Design, implement, and govern security controls for cross-application data flows, API integrations, OAuth connections, and third-party SaaS platforms. Own the security review lifecycle for new integrations and automate posture monitoring to catch drift early.
  • eDiscovery & Legal Hold Program: Continue to build and operate Harvey's legal hold infrastructure, including data preservation, collection workflows, and custodian management. Partner with Legal and Compliance to meet litigation readiness requirements across our collaboration and productivity stack.
  • IT & Business Systems Partnership: Provide security oversight across the SaaS application lifecycle - vendor onboarding assessments, ongoing configuration review, and decommissioning.
  • Endpoint Security: Support endpoint security policies and vulnerability management, ensuring endpoint telemetry feeds into detection and response workflows.
  • Security Detection & Response: Develop scripts and integrations that extend visibility across corporate systems, partnering with the Detection & Response team to surface signals from SaaS and business applications.
What You Have
  • Demonstrated experience securing enterprise SaaS environments, including integration security, API token management, OAuth governance, and cross-application data flow risk - with working knowledge of authentication/authorization standards (SAML, OIDC, SCIM, X.509) and the ability to debug real-world integration failures.
  • Experience building or managing eDiscovery and legal hold programs, including data preservation workflows, custodian management, and coordination with Legal and outside counsel. Familiarity with tools such as Purview, Vault, Relativity, Everlaw, or similar platforms is a plus.
  • Strong software engineering fundamentals with proficiency in Python and/or Go, including building integrations against SaaS APIs (not just configuring through consoles), and experience with infrastructure-as-code tooling such as Terraform and/or Pulumi for managing security configurations in a repeatable, auditable way.
  • Ability to identify risks and vulnerabilities in IT and business systems and communicate that risk clearly to stakeholders across engineering, legal, and executive audiences.
  • Familiarity with endpoint security for macOS and Windows environments, and experience with tools such as Okta, Google Workspace, Salesforce, Workday, NetSuite, Microsoft Entra/Azure/Intune, JAMF, Tines, or similar platforms.
  • 4+ years of experience in security engineering, corporate engineering, IT, or a related program management function with a security focus. Experience with generative AI or the legal industry is not required - but genuine curiosity about both will serve you well here.
Compensation

$220,000 - $330,000 USD

Depending on your location, an Applicant Privacy Notice may apply to you. You can find all of our Applicant Privacy Notices here.

Harvey is an equal opportunity employer and does not discriminate on the basis of race, gender, sexual orientation, gender identity/expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or related condition, or any other basis protected by law.

We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made by emailing accommodations@harvey.ai

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff Corporate Security Engineer
Staff Corporate Security Engineer

Harvey • New York (NY)

On-site
USD 220,000 - 330,000
Staff Corporate Security Engineer
Staff Corporate Security Engineer

Harvey • United States

On-site
USD 220,000 - 330,000
Health insurance
Remote work stipend
Senior Software Engineer, Security Harvey AI San Francisco $220,000 - $330,000/yr
Senior Software Engineer, Security Harvey AI San Francisco $220,000 - $330,000/yr

Neura Market • San Francisco (CA)

On-site
USD 220,000 - 330,000
Senior Software Engineer, Security
Senior Software Engineer, Security

Harvey • United States

On-site
USD 220,000 - 330,000
Senior Product Security Engineer
Senior Product Security Engineer

Harvey, Inc. • New York (NY)

On-site
USD 200,000 - 280,000
Equity plan
Health, dental, vision coverage
401k match up to 4%
+1
Head of Product Security
Head of Product Security

Harvey • United States

On-site
USD 285,000 - 350,000
Head of Security Engineering
Head of Security Engineering

Harvey • New York (NY)

On-site
USD 285,000 - 350,000
Generous Compensation
Professional Development Opportunities
Remote Work Flexibility
Head of Security Engineering
Head of Security Engineering

Harvey • San Francisco (CA)

On-site
USD 285,000 - 350,000
Analyst, Customer Trust
Analyst, Customer Trust

Harvey • United States

On-site
USD 94,000 - 142,000
Analyst, Customer Trust
Analyst, Customer Trust

Harvey • New York (NY)

On-site
USD 94,000 - 142,000