Skip to content
HarveyHarveySan Francisco, CA

Staff Corporate Security Engineer

Staff Corporate Security Engineer building and governing security for enterprise SaaS integrations, API data flows, and eDiscovery/legal hold programs at a rapidly scaling AI company. Requires strong security engineering and software development skills (Python/Go, IaC) plus experience with corporate IT systems and litigation readiness.

220k – 330k/yr
Hybrid7+ YOESecurity Engineering

About the role

What You'll Do

  • Design, implement, and govern security controls for cross-application data flows, API integrations, OAuth connections, and third-party SaaS platforms.
  • Own the security review lifecycle for new integrations and automate posture monitoring to catch drift early.
  • Build and operate Harvey's legal hold infrastructure, including data preservation, collection workflows, and custodian management. Partner with Legal and Compliance to meet litigation readiness requirements.
  • Provide security oversight across the SaaS application lifecycle — vendor onboarding assessments, ongoing configuration review, and decommissioning.
  • Support endpoint security policies and vulnerability management, ensuring endpoint telemetry feeds into detection and response workflows.
  • Develop scripts and integrations that extend visibility across corporate systems, partnering with the Detection & Response team to surface signals from SaaS and business applications.

What You Have

  • Demonstrated experience securing enterprise SaaS environments, including integration security, API token management, OAuth governance, and cross-application data flow risk.
  • Working knowledge of authentication/authorization standards (SAML, OIDC, SCIM, X.509) and the ability to debug real-world integration failures.
  • Experience building or managing eDiscovery and legal hold programs, including data preservation workflows, custodian management, and coordination with Legal and outside counsel. Familiarity with tools such as Purview, Vault, Relativity, Everlaw, or similar platforms is a plus.
  • Strong software engineering fundamentals with proficiency in Python and/or Go, including building integrations against SaaS APIs and experience with infrastructure-as-code tooling such as Terraform and/or Pulumi.
  • Ability to identify risks and vulnerabilities in IT and business systems and communicate that risk clearly to stakeholders across engineering, legal, and executive audiences.
  • Familiarity with endpoint security for macOS and Windows environments, and experience with tools such as Okta, Google Workspace, Salesforce, Workday, NetSuite, Microsoft Entra/Azure/Intune, JAMF, Tines, or similar platforms.
  • 4+ years of experience in security engineering, corporate engineering, IT, or a related program management function with a security focus.

Skills

saas securityAPI IntegrationsOAuthSAMLOIDCSCIMPythonGoTerraformPulumiediscoverylegal holdOktamicrosoft entraJamf
Perplexity

Member of Technical Staff

PerplexitySan Francisco, CA

Conduct original research on AI security, privacy, and threat modeling for frontier intelligence systems. Translate advances into practical defenses, publish at top venues, and partner with engineering to ship hardened features. Requires PhD and publications in security conferences.

220k – 405k/yrOn-siteSecurity Engineering
Pomelo Care

Staff Security Engineer

Pomelo CareSan Francisco, CA +1

Staff Security Engineer who owns security problems end-to-end by identifying real risks, building direct controls, secure-by-default libraries, guardrails, and tooling. Requires 7+ years software engineering experience plus deep security expertise in threat modeling, auth, OWASP, cloud, and supply chain security. Healthcare/HIPAA/HITRUST and GCP experience preferred.

220k – 260k/yrRemote7+ YOESecurity Engineering
Grow Therapy

Staff Engineer, Security

Grow TherapyNew York, NY +2

Lead security engineering as the most senior hands-on engineer, shaping multi-year roadmap and building secure-by-default infrastructure including auth, data security, and vulnerability management.

220k – 240k/yrRemote7+ YOESecurity Engineering
Skydio

Staff Software Engineer - Security

SkydioSan Mateo, CA

As a Staff Software Engineer - Security, you will design, review, and build systems to secure Skydio's cloud and corporate environments. You will partner with cross-functional teams on architectural decisions and build internal security tooling, playing a key role in protecting commercial, government, and DoD customers.

220k – 270k/yrHybrid7+ YOESecurity Engineering
Harvey

Staff Software Engineer, Product Security

HarveySan Francisco, CA +1

Staff Software Engineer builds security into AI platform, owns product security roadmap, reviews critical code like authentication/access control, leads cross-functional initiatives, and mentors engineers on secure practices. Requires 8+ years in product/application/offensive security with proven vulnerability remediation track record.

220k – 330k/yrHybrid8+ YOESecurity Engineering