Skip to content
HarveyHarvey

Staff Security Software Engineer, IAM

Staff Security Software Engineer leading identity and access strategy, architecture, and hands-on platform development across customer, employee, contractor, and agentic identities. Requires 10+ years of production software experience and deep expertise in identity and authorization systems.

About the job

Responsibilities

  • Define Harvey’s multi-year technical strategy for identity, authentication, authorization, and privileged access.
  • Design and build complex identity systems from the ground up, including production code, instrumentation, and operational ownership.
  • Lead cross-functional initiatives covering identity and authentication, permissions and authorization, entitlement modeling, and access controls.
  • Extend identity models to non-human and agentic identities so AI agents acting for users are authenticated, scoped, and auditable.
  • Serve as the technical authority for identity and access architecture, guiding design reviews, investment decisions, and long-term roadmaps.

Requirements

  • 10+ years of experience building and operating production software, with demonstrated impact across multiple teams or technical domains.
  • Deep expertise in several identity and access domains, including authentication, federation, authorization, entitlement modeling, or privileged access.
  • Effective use of AI-assisted development tools and strong engineering judgment when designing agentic workflows.
  • Experience designing identity or authorization platforms, libraries, or abstractions adopted by other engineering teams.
  • Experience delivering foundational systems that improve organizational or customer outcomes.
  • Experience with cloud infrastructure and modern distributed-system patterns.
  • Strong communication skills and the ability to align technical and non-technical stakeholders.

Nice to Have

  • Experience with SCIM, OpenID Connect, SAML, policy engines such as Open Policy Agent or Cedar, Zanzibar-style authorization systems, or hardware-backed credentials.
  • Experience with identity governance and administration or privileged access management platforms, including automated joiner, mover, and leaver workflows.
  • Experience building identity platforms or programs at a hyper-growth startup.
  • Experience in regulated environments such as FedRAMP, including phishing-resistant authentication and authenticator assurance requirements.

Compensation

  • $231,000–$340,000 USD, depending on location.

Skills

IAM, Authentication, Authorization, Federation, Entitlement Modeling, Privileged Access, SCIM, Openid Connect, SAML, Open Policy Agent, Cedar, Cloud Infrastructure, Distributed Systems, AI Agents

Reddit

Reddit

United States

Staff Software Engineer - Site Defense
$217k+/yrRemote7+ YOESecurity Engineering

Design and operate distributed, low-latency infrastructure that protects Reddit from DDoS attacks, bots, scraping, and other network threats. The role requires 7+ years of distributed-systems experience plus expertise in security, networking, and production operations.

Gusto

Gusto

San Francisco, CA

Senior Staff IT Controls, Enterprise Applications
$245k+/yrHybrid10+ YOESecurity Engineering

Own and scale IT general controls, access governance, segregation of duties, and audit readiness across enterprise applications. The role combines SOX expertise with AI-enabled continuous controls monitoring and requires 10+ years of controls, audit, or enterprise governance experience.

Upside

Upside

Washington, DC
Staff Application Security Engineer
$210k+/yrRemote6+ YOESecurity Engineering

Staff-level AppSec engineer building secure coding practices and vulnerability management for a commerce platform. Requires 6+ years in application security with deep AWS and Python experience.

Lob

Lob

United States

Staff Security Engineer, Cloud and Product Security
$198k+/yrRemote8+ YOESecurity Engineering

Own the technical security function across cloud infrastructure, detection and response, application security, incident response, and automation. The role requires 8+ years of security engineering experience, deep AWS expertise, and the ability to lead security improvements across engineering teams.

Illumio

Illumio

Sunnyvale, CA

Staff Engineer - Container Security
$194k+/yrOn-site8+ YOESecurity Engineering

Build and scale container security capabilities that orchestrate Zero Trust Segmentation at the application and pod level. The role requires 8+ years developing distributed systems, proficiency in a higher-level language, and strong Kubernetes, networking, and Linux expertise.