Skip to content
HarveyHarvey

Senior Software Engineer, Security

Build and operate foundational security services covering identity, authorization, secrets, and privileged access for an AI-powered enterprise platform. The role requires 5+ years of production software engineering experience and hands-on security infrastructure expertise.

About the job

Responsibilities

  • Design, build, and operate core security services across workforce, infrastructure, and production environments, including authentication, authorization, access governance, secrets management, and privileged access.
  • Own identity infrastructure end to end, including SSO, SCIM, and fine-grained authorization for enterprise customers.
  • Build secure-by-default libraries, paved-road abstractions, and self-service tooling for identifying, remediating, and preventing security issues.
  • Take systems from greenfield design through production, including architecture, implementation, instrumentation, reliability, and operational ownership.
  • Contribute to incident response and drive technical mitigation for security issues.
  • Raise engineering security standards through design reviews, code reviews, and technical mentorship.

Requirements

  • 5+ years of software engineering experience shipping and operating production services.
  • Hands-on experience building security infrastructure, such as IAM, authentication and authorization, secrets management, or privileged access.
  • Knowledge of common vulnerability classes and attacker-oriented system analysis.
  • Strong programming skills and willingness to work across stacks and unfamiliar domains.
  • Experience building and maintaining production services with agentic coding tools such as Claude Code or Codex.
  • Experience with cloud infrastructure and modern distributed-system patterns.
  • Ability to turn security requirements into scalable engineering solutions.
  • Strong communication and collaboration skills, with the ability to influence without formal authority.

Nice to Have

  • Experience building security platforms or programs at hyper-growth startups.
  • Developer platform or infrastructure engineering background.
  • Experience with SCIM, OIDC/SAML, policy engines such as OPA, Cedar, or Zanzibar-style systems, or hardware-backed credentials.
  • Experience in highly regulated enterprise environments.

Skills

Identity And Access Management, Authentication, Authorization, Secrets Management, Privileged Access Management, SSO, SCIM, OIDC, SAML, Cloud Infrastructure, Distributed Systems, Claude Code, Codex, Opa, Cedar

Front

Front

San Francisco, CA

Senior AI Platform Security Engineer
$187k+/yrOn-site7+ YOESecurity Engineering

This role defines, builds, and secures the internal platform supporting Front’s engineering, GTM, data, and AI tooling. It owns AWS and Snowflake infrastructure, paved-road delivery, observability, access controls, vulnerability management, incident response, compliance support, and AI-client security.

Square

Square

United States

Senior GRC Engineer
$185k+/yrRemote7+ YOESecurity Engineering

Build data pipelines, integrations, policy-as-code, and agentic AI workflows that automate security governance and continuous compliance. The role requires 7+ years of production software engineering experience plus expertise in LLMs, APIs, distributed data, and cloud infrastructure.

Instacart

Instacart

United States
Senior Detection Engineer II
$192k+/yrRemote6+ YOESecurity Engineering

Develops and operates detection engineering systems across endpoint, cloud, container, and SaaS environments. The role requires at least six years in detection, incident response, or offensive security, strong attacker TTP knowledge, macOS expertise, and detection-as-code experience.

Flexport

Flexport

San Francisco, CA

Senior Security Engineer, Detection & Response
$183k+/yrOn-site5+ YOESecurity Engineering

Own end-to-end security detection engineering, incident response, automation, and threat hunting across endpoint, identity, SaaS, and cloud environments. The role requires substantial hands-on experience with production detection logic, incident response, programming, and modern SIEM or detection pipelines.

Gusto

Gusto

San Francisco, CA

Senior GRC Analyst
$183k+/yrHybrid8+ YOESecurity Engineering

The Senior GRC Analyst will manage security governance, risk, and compliance programs, including SOC 2 controls, risk assessments, vendor reviews, audits, and data governance. The role requires 8+ years of GRC experience, a bachelor’s degree, and familiarity with compliance platforms and SaaS environments.