Staff Corporate Security Engineer
harvey
Job Score
100 ptsWhy Harvey
At Harvey, we’re transforming how legal and professional services operate. By combining frontier agentic AI, an enterprise-grade platform, and deep domain expertise, we’re reshaping how critical knowledge work gets done for decades to come.
This is a rare chance to help build a generational company at a true inflection point. We have strong product-market fit and world-class investor support. We’re scaling fast and defining a new category in real time. The work is ambitious, the bar is high, and the opportunity for growth — personal, professional, and financial — is unmatched.
Our team moves fast, takes ownership, and is deeply committed to the mission — operating with intensity, staying close to our customers, and pushing each other for excellence. We live by three values: Decisiveness, Simplicity, and Job's Not Finished. We act quickly on clear judgment over perfect information, we believe simplicity is what scales, and we're never satisfied with where we are. If you want to do the best work of your career alongside people who share that drive, we'd love to build with you.
At Harvey, the future of professional services is being written today — and we’re just getting started.
Role Overview
Some of the world's largest companies and their law firms use Harvey's AI to deliver world-class client services at unprecedented scale, entrusting Harvey with their most sensitive documents in the process.
This role joins Harvey's corporate security function, which secures the company's IT and business systems as Harvey grows rapidly, balancing risk with user experience while validating every assumption through threat modeling and real-world testing rather than relying on best practice alone.
It is a strong fit for someone at the intersection of security engineering and enterprise systems- someone who understands how data flows between SaaS applications, can pinpoint where security breaks down in complex integrations, and knows how to build controls that scale. Experience with eDiscovery workflows and legal holds is a meaningful differentiator given the nature of Harvey's customer base.
What You'll Do
Enterprise Integrations & SaaS Security: Design, implement, and govern security controls for cross-application data flows, API integrations, OAuth connections, and third-party SaaS platforms. Own the security review lifecycle for new integrations and automate posture monitoring to catch drift early.
eDiscovery & Legal Hold Program: Continue to build and operate Harvey's legal hold infrastructure, including data preservation, collection workflows, and custodian management. Partner with Legal and Compliance to meet litigation readiness requirements across our collaboration and productivity stack.
IT & Business Systems Partnership: Provide security oversight across the SaaS application lifecycle — vendor onboarding assessments, ongoing configuration review, and decommissioning.
Endpoint Security: Support endpoint security policies and vulnerability management, ensuring endpoint telemetry feeds into detection and response workflows.
Security Detection & Response: Develop scripts and integrations that extend visibility across corporate systems, partnering with the Detection & Response team to surface signals from SaaS and business applications.
What You Have
Demonstrated experience securing enterprise SaaS environments, including integration security, API token management, OAuth governance, and cross-application data flow risk — with working knowledge of authentication/authorization standards (SAML, OIDC, SCIM, X.509) and the ability to debug real-world integration failures.
Experience building or managing eDiscovery and legal hold programs, including data preservation workflows, custodian management, and coordination with Legal and outside counsel. Familiarity with tools such as Purview, Vault, Relativity, Everlaw, or similar platforms is a plus.
Strong software engineering fundamentals with proficiency in Python and/or Go, including building integrations against SaaS APIs (not just configuring through consoles), and experience with infrastructure-as-code tooling such as Terraform and/or Pulumi for managing security configurations in a repeatable, auditable way.
Ability to identify risks and vulnerabilities in IT and business systems and communicate that risk clearly to stakeholders across engineering, legal, and executive audiences.
Familiarity with endpoint security for macOS and Windows environments, and experience with tools such as Okta, Google Workspace, Salesforce, Workday, NetSuite, Microsoft Entra/Azure/Intune, JAMF, Tines, or similar platforms.
4+ years of experience in security engineering, corporate engineering, IT, or a related program management function with a security focus. Experience with generative AI or the legal industry is not required — but genuine curiosity about both will serve you well here.
Compensation
$220,000 - $330,000 USD
Depending on your location, an Applicant Privacy Notice may apply to you. You can find all of our Applicant Privacy Notices here.
#LI-AH1
Harvey is an equal opportunity employer and does not discriminate on the basis of race, gender, sexual orientation, gender identity/expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or related condition, or any other basis protected by law.
We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made by emailing accommodations@harvey.ai
About Information Security
The Information Security area is one of the most strategic and in-demand fields in the technology market. With the rise of cyberattacks, data breaches, and regulations like LGPD and GDPR, companies of all sizes invest heavily in professionals who can protect their digital assets.
Key specializations include Network Security, Cloud Security (AWS, Azure, GCP), Offensive Security (Penetration Testing, Red Team), Defensive Security (SOC, Blue Team), AppSec, and Security Governance. Tools like SIEM (Splunk, QRadar), firewalls, EDR, and Vulnerability Management platforms are essential.
Certifications like CISSP, CEH, OSCP, CompTIA Security+, and AWS Security Specialty are important differentiators. Information security professionals are among the highest-paid in the sector, with growing demand especially in fintechs, healthtechs, and large enterprises.
About Product Owner
The Product Owner (PO) is the professional responsible for maximizing the value of the product delivered by the development team. They act as the voice of the customer and stakeholders, managing and prioritizing the product backlog, defining clear user stories, and ensuring the team works on the most valuable items for the business.
Key skills include backlog management, user story writing, prioritization (Mascow, RICE), agile methodologies (Scrum, Kanban), and stakeholder communication. Knowledge of tools like Jira, Trello, Azure DevOps, and Miro is essential.
Product Owners are highly sought-after professionals in the technology market, working collaboratively with Scrum Masters, Product Managers, and engineering teams to drive agility and continuous value delivery.
Discover Other Areas
Understand the scope of work, key skills, and tools used in different career areas.
About SEO Analyst
The SEO Analyst is the professional responsible for optimizing websites for search engines, increasing organic visibility and qualified traffic. With the growing importance of digital marketing, SEO professionals are fundamental to any online presence strategy.
Key skills include on-page and off-page SEO, technical SEO, keyword research, SEO audits, link building, optimized content creation, and metrics analysis. Tools like Google Search Console, Google Analytics, Ahrefs, Semrush, Moz, and Screaming Frog are essential for daily work.
SEO analysts in technology companies are highly valued, especially those who master technical SEO, Core Web Vitals, and data-driven content strategies. The field offers opportunities from junior analyst to head of SEO, with a focus on organic growth, domain authority, and return on investment.
About Finance
The Finance area in technology companies combines traditional financial knowledge with advanced digital tools. FP&A, controlling, and corporate finance professionals are essential for the organization's financial health.
Key skills include financial modeling, metrics analysis (MRR, ARR, LTV, CAC), ERP (SAP, Oracle), and BI tools. Certifications like CFA and CPA-20 are differentiators.
The financial sector offers stable opportunities with competitive salaries, especially in fintechs and large technology companies.
About Product Management
Product Management is one of the most strategically relevant areas in technology organizations. The Product Manager is responsible for defining product vision, prioritizing features, and coordinating multidisciplinary teams to deliver value to users.
Essential skills include strategic thinking, data analysis, communication, leadership, and technical knowledge. Tools like Jira, Confluence, Miro, and analytics platforms are fundamental in daily work.
Salaries for PMs range from entry-level to senior positions at major tech companies, with growing opportunities for international remote work.
About Agile
The Agile and Digital Transformation area is fundamental for organizations seeking efficiency and rapid adaptation. Agile professionals facilitate processes, eliminate bottlenecks, and promote a culture of continuous improvement.
Key certifications include CSM, PSM, SAFe, ICP, and Kanban. Knowledge of Scrum, Kanban, XP, and agile frameworks is essential, as are leadership and facilitation soft skills.
Senior Agile coaches and Scrum Masters are highly valued, especially in technology companies that adopt agile methodologies at scale.
About Blockchain
The Blockchain area involves the development and implementation of secure and distributed transaction ledgers. Professionals in this field work with smart contract development, cryptography, consensus algorithms, and platforms such as Ethereum, Hyperledger, and Solana, ensuring security and decentralization for various types of applications.
Comments 0