Skip to content

Open nowPosted 32 hours ago

Staff Software Engineer, Secure Execution

Harvey308 open roles

Pay
$231,000 – $346,400 a year
Where
San Francisco
Work mode
Hybrid
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowStaff Software Engineer, Secure ExecutionHarvey · San Francisco
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Harvey's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market. Harvey postings stay open a median of 27 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.4%3 days
  3. 7.8%7 days
  4. 14.3%14 days
  5. 33.6%30 days
This job: posted 32 hours ago

Harvey median: 27 days open

The posting

WHY HARVEY

At Harvey, we’re transforming how legal and professional services operate. By combining frontier agentic AI, an enterprise-grade platform, and deep domain expertise, we’re reshaping how critical knowledge work gets done for decades to come.

This is a rare chance to help build a generational company at a true inflection point. We have strong product-market fit and world-class investor support. We’re scaling fast and defining a new category in real time. The work is ambitious, the bar is high, and the opportunity for growth — personal, professional, and financial — is unmatched.

Our team moves fast, takes ownership, and is deeply committed to the mission — operating with intensity, staying close to our customers, and pushing each other for excellence. We live by three values: Decisiveness, Simplicity, and Job's Not Finished. We act quickly on clear judgment over perfect information, we believe simplicity is what scales, and we're never satisfied with where we are. If you want to do the best work of your career alongside people who share that drive, we'd love to build with you.

At Harvey, the future of professional services is being written today — and we’re just getting started.

ROLE OVERVIEW

As a Staff Software Engineer on the Security Engineering team, you will join as a founding team member and build the security foundations that let Harvey put increasingly capable AI agents to work. You'll lead development of a platform for agents to perform security work, while shaping how agents are sandboxed across our product and internal platforms.

One of the central challenges is enabling models with advanced cybersecurity capabilities to discover and validate vulnerabilities automatically, including through authorized penetration testing, while protecting sensitive data and systems. You'll build the execution environments, orchestration, and controls that make this possible, and help enable the internal use of open-source models with appropriate protections around inference, tool use, and data access.

You'll work closely with the teams building Harvey's product sandbox and internal AI agent platform, shaping architecture and contributing production code to strengthen execution boundaries. Your impact will come from shipping systems, establishing a shared technical direction, and making security capabilities reusable across teams. You'll own work from design through rollout and operation, balancing containment with the reliability, performance, and flexibility that useful agents need.

WHAT YOU'LL DO

- Set the technical direction for secure agent execution, working across Security, Infrastructure, and Product Engineering to turn emerging capabilities and risks into a concrete roadmap.

- Design, build, and operate a platform for security agents to discover and validate vulnerabilities within authorized targets and execution boundaries, producing reproducible evidence that engineers can act on.

- Build reusable controls for agent tool use, code execution, network and filesystem access, resource consumption, and workload lifecycle. Integrate with identity and secrets platforms to limit access to the data and credentials each task needs.

- Partner with the owners of Harvey's product sandbox and internal agent platform to make architectural decisions, implement protections, and integrate shared security capabilities into their execution environments.

- Enable internal use of open-source models alongside infrastructure teams, building protections around model serving, agent execution, and sensitive-data handling.

- Develop adversarial tests, evaluations, and telemetry that verify containment and expose failures. Build mechanisms to scope, observe, interrupt, and safely terminate agent activity.

- Lead delivery and adoption across teams, mentor engineers, and remain hands-on through implementation and production operation, making clear tradeoffs across security, reliability, latency, and cost.

WHAT YOU HAVE

- 10+ years developing and running production software, including technical leadership on initiatives spanning multiple engineering teams.

- Strong software engineering skills in languages such as Go, Rust, Python, or C++, with practical experience in Linux systems, networking, and containerized infrastructure.

- Deep expertise in one or more areas of execution security, such as sandboxing, operating-system isolation, container or virtual-machine security, or platforms that execute untrusted code. You can translate threats into enforceable boundaries and test how those boundaries fail.

- Experience building shared platforms, services, or libraries and helping other teams adopt them through clear interfaces, documentation, and safe migrations.

- Experience with cloud infrastructure and distributed systems, including observability, failure handling, capacity management, and dependable production operation.

- Fluency with AI-assisted engineering and agentic workflows: you use models to accelerate development, validate their output, and reason about the risks introduced when agents use tools, execute code, or access sensitive data.

- Strong communication and technical judgment, with a record of bringing teams to agreement on ambiguous problems and carrying decisions through to delivery.

NICE TO HAVE

- Experience with microVMs, hypervisors, or sandbox runtimes such as Firecracker, gVisor, or Kata Containers, or Linux isolation mechanisms such as namespaces, seccomp, and Landlock.

- Experience building agent runtimes, tool-execution frameworks, or automated security-testing platforms.

- Experience with vulnerability research, penetration testing, or adversarial evaluation of agent systems, including turning findings into reproducible tests and effective controls.

- Experience deploying or securing self-hosted inference and open-source models, including isolation of model-serving workloads and protection of sensitive inputs and outputs.

COMPENSATION

$231,000 - $346,400 USD

DEPENDING ON YOUR LOCATION, AN APPLICANT PRIVACY NOTICE MAY APPLY TO YOU. YOU CAN FIND ALL OF OUR APPLICANT PRIVACY NOTICES [HERE https://www.notion.so/harveyai/Harvey-Candidate-Privacy-Policies-319ac3fcdd7a803bb807d5094f249922].

#LI-NP1

Harvey is an equal opportunity employer and does not discriminate on the basis of race, gender, sexual orientation, gender identity/expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or related condition, or any other basis protected by law.

We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made by emailing [email protected]

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Harvey's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Harvey's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Harvey's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.