Senior Software Engineer, Security
Posted Aug 19, 2026 · Listed on Harvey's Ashby board, re-checked daily
Why Harvey
At Harvey, we’re transforming how legal and professional services operate. By combining frontier agentic AI, an enterprise-grade platform, and deep domain expertise, we’re reshaping how critical knowledge work gets done for decades to come.
This is a rare chance to help build a generational company at a true inflection point. We have strong product-market fit and world-class investor support. We’re scaling fast and defining a new category in real time. The work is ambitious, the bar is high, and the opportunity for growth — personal, professional, and financial — is unmatched.
Our team moves fast, takes ownership, and is deeply committed to the mission — operating with intensity, staying close to our customers, and pushing each other for excellence. We live by three values: Decisiveness, Simplicity, and Job's Not Finished. We act quickly on clear judgment over perfect information, we believe simplicity is what scales, and we're never satisfied with where we are. If you want to do the best work of your career alongside people who share that drive, we'd love to build with you.
At Harvey, the future of professional services is being written today — and we’re just getting started.
Role Overview
As a Senior Software Engineer on the Security Engineering team at Harvey, you'll build and operate the foundational security services every other engineer at Harvey depends on: encryption and key management, public key infrastructure (PKI), secrets management, identity and access, and the tooling that makes the secure path the fast path. You'll design these systems, write the code, run them in production, and own the results. Agentic systems make this harder than it is at a typical SaaS company: when an AI agent acts on a user's behalf against their most sensitive documents, protecting data, credentials, and execution boundaries becomes essential to every workflow.
Security at Harvey is an engineering discipline, not a gatekeeper function. We build platforms and libraries that make it hard for engineers to get security wrong, and we measure ourselves on adoption and outcomes rather than tickets filed. Our program is informed by risk: we invest where the actual exposure to our customers' data is greatest, rather than where a framework tells us to.
What You'll Do
Design, build, and operate shared services for encryption, key management, and secure storage, partnering with Product and Infrastructure teams to protect sensitive data
Build PKI and certificate lifecycle automation, including issuance, renewal, revocation, and trust rotation
Build secrets management workflows that discover exposed credentials, enable secure storage and delivery, automate rotation, and support rapid revocation
Build secure-by-default libraries and self-service tooling for data protection and identity and access, making shared security controls easy for engineering teams to adopt
Build reusable tooling for code, dependency, and secret scanning, CI/CD enforcement, and remediation, including infrastructure to safely run and observe security agents
Take these systems from greenfield to production-grade: define the architecture, ship it, instrument it, and own its reliability
Contribute to incident response and drive technical mitigation when security issues surface
Raise the security bar across engineering through design reviews, code reviews, and technical mentorship
What You Have
5+ years of software engineering experience with a track record of shipping and operating production services
Hands-on experience designing, building, and operating security infrastructure in one or more areas such as PKI, encryption and key management, secrets management, secure software delivery, or identity and access
Working knowledge of common vulnerability classes and the ability to reason about how a system fails under an attacker, not just under load
Strong programming skills and a willingness to work across the stack and across unfamiliar domains
Fluency building and maintaining production services with agentic coding tools (Claude Code, Codex, or similar) — you know how to get real leverage from them and where they need supervision
Experience with cloud infrastructure (Azure, GCP, or AWS) and modern distributed system patterns
Demonstrated ability to turn security requirements into scalable engineering solutions rather than manual process
Strong communication and collaboration skills; you can influence engineering teams without formal authority
Nice to Have
Experience building security platforms or programs at hyper-growth startups
Background in developer platform or infrastructure engineering
Experience applying cryptography in production through established libraries, envelope encryption, cloud key management services (KMS), or hardware security modules (HSMs)
Experience with PKI, TLS/mTLS, certificate lifecycle automation, or secrets rotation at scale
Experience in highly regulated enterprise environments
Compensation
$188,000 - $282,000 USD
Depending on your location, an Applicant Privacy Notice may apply to you. You can find all of our Applicant Privacy Notices [here].
#LI-NP1
Harvey is an equal opportunity employer and does not discriminate on the basis of race, gender, sexual orientation, gender identity/expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or related condition, or any other basis protected by law.
We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made by emailing accommodations@harvey.ai
Source: Harvey on Ashby. Ciphire is not the employer and doesn't take applications.