> Markdown version of [/jobs/ext/1916013-staff-corporate-security-engineer](https://www.wearedevelopers.com/jobs/ext/1916013-staff-corporate-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Staff Corporate Security Engineer - **Company:** Harvey, Inc. - **Location:** San Francisco, CA, United States - **Experience:** Experienced - **Salary:** $220,000.0 - $330,000.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Apple Mac Systems, Microsoft Azure, Business Software, Business Systems, Software as a Service, Cloud Computing Security, Software Debugging, Internet Security, Python (Programming Language), Netsuite, OAuth, OpenID, X.509, Azure Active Directory, Application Data, Salesforce.Com, Security Assertion Markup Language (SAML), Systems Integration, Software Vulnerability Management, Pulumi, Okta, Microsoft InTune, Casper Suite, Gsuite, Terraform, Api Management, Workday - **Published:** August 4, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=662d23c4403eaa01 ## About the Role * Demonstrated experience securing enterprise SaaS environments, including integration security, API token management, OAuth governance, and cross-application data flow risk - with working knowledge of authentication/authorization standards (SAML, OIDC, SCIM, X.509) and the ability to debug real-world integration failures. * Experience building or managing eDiscovery and legal hold programs, including data preservation workflows, custodian management, and coordination with Legal and outside counsel. Familiarity with tools such as Purview, Vault, Relativity, Everlaw, or similar platforms is a plus. * Strong software engineering fundamentals with proficiency in Python and/or Go, including building integrations against SaaS APIs (not just configuring through consoles), and experience with infrastructure-as-code tooling such as Terraform and/or Pulumi for managing security configurations in a repeatable, auditable way. * Ability to identify risks and vulnerabilities in IT and business systems and communicate that risk clearly to stakeholders across engineering, legal, and executive audiences. * Familiarity with endpoint security for macOS and Windows environments, and experience with tools such as Okta, Google Workspace, Salesforce, Workday, NetSuite, Microsoft Entra/Azure/Intune, JAMF, Tines, or similar platforms. * 4+ years of experience in security engineering, corporate engineering, IT, or a related program management function with a security focus. Experience with generative AI or the legal industry is not required - but genuine curiosity about both will serve you well here. ## Description * Enterprise Integrations & SaaS Security: Design, implement, and govern security controls for cross-application data flows, API integrations, OAuth connections, and third-party SaaS platforms. Own the security review lifecycle for new integrations and automate posture monitoring to catch drift early. * eDiscovery & Legal Hold Program: Continue to build and operate Harvey's legal hold infrastructure, including data preservation, collection workflows, and custodian management. Partner with Legal and Compliance to meet litigation readiness requirements across our collaboration and productivity stack. * IT & Business Systems Partnership: Provide security oversight across the SaaS application lifecycle - vendor onboarding assessments, ongoing configuration review, and decommissioning. * Endpoint Security: Support endpoint security policies and vulnerability management, ensuring endpoint telemetry feeds into detection and response workflows. * Security Detection & Response: Develop scripts and integrations that extend visibility across corporate systems, partnering with the Detection & Response team to surface signals from SaaS and business applications. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Advanced Cypress: custom assertions and tasks](https://www.wearedevelopers.com/videos/790-advanced-cypress-custom-assertions-and-tasks) ## Related Articles - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 137 - AI'm not sure about this](https://www.wearedevelopers.com/magazine/485-dev-digest-137-ai-m-not-sure-about-this) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)