Skip to main content

Incident Handler

Harvey AISecuritySecurity
Pay
$134K–$200K
per year
Work mode
On-site
Full Time
Experience
3+ yrs
Mid

San Francisco, CA at a glance

Rent
#2 of 51
$2,680/mo+46% vs US avg
Weather
#17 of 51
295 mild days0 hot · 0 cold
Income tax
#1 of 51
13.3% top rateCalifornia

What you need

  • 3+ yrs incident response, detection, or security ops
  • Experience with complex cloud-native incident response
  • Deep knowledge of MITRE ATT&CK and threat tradecraft
  • Experience with AWS, GCP, or Azure cloud platforms
  • Scripting in Python, Go, or similar languages

What you'll do

  • Lead security incident investigations across cloud, identity, corporate, and AI environments
  • Maintain and contribute to an internally developed agentic SOC
  • Contribute to Detection & Response roadmap, metrics, and SLAs
  • Mentor engineers and build playbooks and operational standards

Why Harvey

At Harvey, we’re transforming how legal and professional services operate. By combining frontier agentic AI, an enterprise-grade platform, and deep domain expertise, we’re reshaping how critical knowledge work gets done for decades to come.

This is a rare chance to help build a generational company at a true inflection point. We have strong product-market fit and world-class investor support. We’re scaling fast and defining a new category in real time. The work is ambitious, the bar is high, and the opportunity for growth — personal, professional, and financial — is unmatched.

Our team moves fast, takes ownership, and is deeply committed to the mission — operating with intensity, staying close to our customers, and pushing each other for excellence. We live by three values: Decisiveness, Simplicity, and Job's Not Finished. We act quickly on clear judgment over perfect information, we believe simplicity is what scales, and we're never satisfied with where we are. If you want to do the best work of your career alongside people who share that drive, we'd love to build with you.

At Harvey, the future of professional services is being written today — and we’re just getting started.


Role Overview

Harvey’s products sit at the intersection of frontier AI, sensitive customer data, and critical business workflows. Our customers trust us to protect their information in an always-accelerating threat ecosystem, and security is how we foremost earn and keep our customers’ trust. We’re hiring an experienced Incident Response Handler to drive and ultimately lead incident response for security events. You will command incidents, coordinate containment, and enforce that real fixes are implemented, preventing recurrence. You’ll join a small, highly technical security team early in standing up a dedicated Detection & Response function, with real latitude to define how Harvey does incident response for years to come. Like the rest of Harvey’s security team, our program is built on offensive security experience - most engineers come from red-team, pentesting, or incident-response backgrounds, and we bring an attacker’s mindset to detection and response. This is an individual contributor role for someone who has operated in mature security organizations at leading technology companies and wants to help define incident response at one of the most important AI companies in the world.


What You'll Do

  • Build strong relationships with key employees across the organization

  • Participate in security incidents, leading investigations across cloud infrastructure, identity systems, corporate environments, and our AI platforms.

  • Use, maintain, and contribute to an internally developed agentic SOC, fine tuned to Harvey’s threat environment

  • Work cross functionally across technical and operational orgs, ensuring the right PRs ship and best policies are enforced

  • Contribute to Harvey’s Detection & Response roadmap, including metrics, SLAs, threat modeling, and tabletop exercises for our most critical business risks.

  • Work across teams to ensure incident follow ups are meaningfully closed

  • Mentor engineers and incident responders, build playbooks and operational standards, and raise the security bar across the company.



What You Have

  • 3+ years of experience in Incident Response, Detection & Response, Security Operations, Threat Detection, or related security engineering disciplines.

  • Experience participating in investigations and response efforts for complex security incidents in cloud-native environments.

  • Deep understanding of attacker tactics, techniques, and procedures (MITRE ATT&CK and modern threat actor tradecraft).

  • Experience with one or more major cloud platforms (AWS, GCP, Azure), plus strong knowledge of operating systems, networking, and identity systems.

  • Experience building security automation and tooling, with strong scripting or software engineering skills in Python, Go, or similar languages.

  • Experience communicating incident status and risk to senior leadership.



Compensation

$133,600 - $200,400 USD


Depending on your location, an Applicant Privacy Notice may apply to you. You can find all of our Applicant Privacy Notices here.


#LI-ES2


Harvey is an equal opportunity employer and does not discriminate on the basis of race, gender, sexual orientation, gender identity/expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or related condition, or any other basis protected by law.

We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made by emailing [email protected]

Optimize your resume for this job

Get a match score and the keywords you're missing

Optimize resume

About Harvey AI

Harvey is domain-specific AI for legal and professional services. Built on advanced LLMs trained alongside veteran attorneys, Harvey delivers true legal reasoning capabilities tailored for each firm's unique practices.

Similar Security roles

Incident Handler
$134K–$200K · Harvey AI
Apply