← Zurück zur Liste
Stelle · Principal

Staff Product Security Engineer

Security Engineer • Principal • Hybrid • Vollzeit Vereinigte Staaten San Francisco, USA

On Harvey's Product Security team, you'll build security into the AI platform from the ground up: owning critical product areas, driving high-leverage security initiatives, and raising the security bar across engineering.

Responsibilities

  • Define and own the product security roadmap, prioritizing initiatives based on risk, business impact, and engineering org maturity
  • Establish and evolve security posture across the engineering organization, setting standards that scale with the company
  • Partner with Product Engineering, Infrastructure, and Platform teams to incorporate secure design principles at every stage of development
  • Own and review security-critical code across key parts of the product, including authentication and access control
  • Architect secure-by-default libraries and tools that make the secure path the easiest choice for developers
  • Drive mitigation strategies during security-related incident responses, coordinating cross-functional efforts
  • Mentor engineers and raise the security bar across teams through code reviews and design reviews

Requirements

  • 8+ years of experience in product security, application security, offensive security, and/or security-focused software engineering
  • Long track record of identifying and remediating software vulnerabilities (CVEs, bug bounty awards, published research, or prior work experience)
  • Track record of leading complex cross-functional security initiatives with measurable improvements, influencing engineering teams without direct authority
  • Experience mentoring senior engineers and developing security talent within an engineering organization
  • Strong programming skills with demonstrated experience writing high-quality, production software
  • Excellent communication and collaboration skills, translating security risks into business terms for non-security stakeholders

Nice to have

  • Experience building security programs or practices at hyper-growth startups
  • Background with cloud environments (Azure, GCP, AWS) and cloud-native security patterns
  • Experience with AI/ML systems and emerging security considerations for LLM-based applications

Soft skills

Cross-functional leadership and mentorshipTranslating security risk into business terms for non-security stakeholdersEngineering-first, hands-on approach to security

What we offer

  • Compensation range: $220,000–$330,000

About the company

Harvey stores and processes its customers' most sensitive data, so security is paramount at every stage of the product lifecycle; the security program is backed by regular external penetration tests and red team exercises.

Ähnliche Stellen