Skip to content
HarveyHarvey

Staff Software Engineer, Product Security

Leads security integration into AI platform, owns critical code reviews for authentication and access control, architects secure tools, and mentors engineers on security practices. Requires 8+ years in product/application security with proven vulnerability remediation track record.

About the job

What You’ll Do

  • Establish and evolve security posture across the engineering organization, setting standards that scale with the company
  • Partner with Product Engineering, Infrastructure, and Platform teams to incorporate secure design principles at every stage of development
  • Own and review security-critical code across key parts of the product, including authentication and access control
  • Architect secure-by-default libraries and tools that make the secure path the easiest choice for developers
  • Drive mitigation strategies during security-related incident responses, coordinating cross-functional efforts
  • Mentor engineers and raise the security bar across teams through code reviews, design reviews, and technical guidance

What You Have

  • 8+ years of experience in product security, application security, offensive security, and/or security-focused software engineering
  • Long track record of identifying and remediating software vulnerabilities, demonstrated through CVEs, bug bounty awards, published research, or prior work experience
  • Demonstrated ability to lead cross-functional security initiatives and influence engineering teams without direct authority
  • Experience mentoring engineers and raising the quality bar of software engineering teams on security practices
  • Strong programming skills with demonstrated experience writing high-quality, production software
  • Excellent communication and collaboration skills, particularly when translating security risks into business terms for non-security stakeholders
  • Track record of leading complex cross-functional projects and delivering measurable security improvements

Nice to Have

  • Experience building security programs or practices at hyper-growth startups
  • Background with cloud environments (Azure, GCP, AWS) and cloud-native security patterns
  • Experience with AI/ML systems and emerging security considerations for LLM-based applications

Compensation Range

$238,000 - $312,000 USD

Skills

Application Security, Offensive Security, Vulnerability Remediation, Authentication, Access Control, Cloud Security, AWS, GCP, Azure, Ai/Ml Security, Penetration Testing, Incident Response, Secure Coding, Code Review, Design Review

Harvey

Harvey

San Francisco, CA

Staff Security Software Engineer, IAM
$231k+/yrHybrid10+ YOESecurity Engineering

Staff Security Software Engineer leading identity and access strategy, architecture, and hands-on platform development across customer, employee, contractor, and agentic identities. Requires 10+ years of production software experience and deep expertise in identity and authorization systems.

Gusto

Gusto

San Francisco, CA

Senior Staff IT Controls, Enterprise Applications
$245k+/yrHybrid10+ YOESecurity Engineering

Own and scale IT general controls, access governance, segregation of duties, and audit readiness across enterprise applications. The role combines SOX expertise with AI-enabled continuous controls monitoring and requires 10+ years of controls, audit, or enterprise governance experience.

Coinbase

Coinbase

United States

Senior Staff Software Engineer, Platform - IAM
$254k+/yrRemote12+ YOESecurity Engineering

Leads the multi-year technical strategy and architecture for Coinbase’s identity and access management platform across hundreds of systems and engineering teams. Requires 12+ years of software engineering experience, deep IAM and workload identity expertise, production Go, and distributed-systems experience on AWS.

Anthropic

Anthropic

San Francisco, CA
Customer Trust Specialist
$255k+/yrHybrid10+ YOESecurity Engineering

Handles complex customer-facing security engagements for regulated enterprises, including audits, questionnaires, contract terms, executive briefings, and trust documentation. Requires broad security expertise, strong writing, independent judgment, and 10+ years of security experience, including leadership experience preferred.

Reddit

Reddit

United States

Staff Software Engineer - Site Defense
$217k+/yrRemote7+ YOESecurity Engineering

Design and operate distributed, low-latency infrastructure that protects Reddit from DDoS attacks, bots, scraping, and other network threats. The role requires 7+ years of distributed-systems experience plus expertise in security, networking, and production operations.