Staff Software Engineer, Secure Execution

Harvey•New York, NY
•$231,000 - $346,400

About The Position

As a Staff Software Engineer on the Security Engineering team, you will join as a founding team member and build the security foundations that let Harvey put increasingly capable AI agents to work. You'll lead development of a platform for agents to perform security work, while shaping how agents are sandboxed across our product and internal platforms. One of the central challenges is enabling models with advanced cybersecurity capabilities to discover and validate vulnerabilities automatically, including through authorized penetration testing, while protecting sensitive data and systems. You'll build the execution environments, orchestration, and controls that make this possible, and help enable the internal use of open-source models with appropriate protections around inference, tool use, and data access. You'll work closely with the teams building Harvey's product sandbox and internal AI agent platform, shaping architecture and contributing production code to strengthen execution boundaries. Your impact will come from shipping systems, establishing a shared technical direction, and making security capabilities reusable across teams. You'll own work from design through rollout and operation, balancing containment with the reliability, performance, and flexibility that useful agents need.

Requirements

  • 10+ years developing and running production software, including technical leadership on initiatives spanning multiple engineering teams.
  • Strong software engineering skills in languages such as Go, Rust, Python, or C++, with practical experience in Linux systems, networking, and containerized infrastructure.
  • Deep expertise in one or more areas of execution security, such as sandboxing, operating-system isolation, container or virtual-machine security, or platforms that execute untrusted code. You can translate threats into enforceable boundaries and test how those boundaries fail.
  • Experience building shared platforms, services, or libraries and helping other teams adopt them through clear interfaces, documentation, and safe migrations.
  • Experience with cloud infrastructure and distributed systems, including observability, failure handling, capacity management, and dependable production operation.
  • Fluency with AI-assisted engineering and agentic workflows: you use models to accelerate development, validate their output, and reason about the risks introduced when agents use tools, execute code, or access sensitive data.
  • Strong communication and technical judgment, with a record of bringing teams to agreement on ambiguous problems and carrying decisions through to delivery.

Nice To Haves

  • Experience with microVMs, hypervisors, or sandbox runtimes such as Firecracker, gVisor, or Kata Containers, or Linux isolation mechanisms such as namespaces, seccomp, and Landlock.
  • Experience building agent runtimes, tool-execution frameworks, or automated security-testing platforms.
  • Experience with vulnerability research, penetration testing, or adversarial evaluation of agent systems, including turning findings into reproducible tests and effective controls.
  • Experience deploying or securing self-hosted inference and open-source models, including isolation of model-serving workloads and protection of sensitive inputs and outputs.

Responsibilities

  • Set the technical direction for secure agent execution, working across Security, Infrastructure, and Product Engineering to turn emerging capabilities and risks into a concrete roadmap.
  • Design, build, and operate a platform for security agents to discover and validate vulnerabilities within authorized targets and execution boundaries, producing reproducible evidence that engineers can act on.
  • Build reusable controls for agent tool use, code execution, network and filesystem access, resource consumption, and workload lifecycle. Integrate with identity and secrets platforms to limit access to the data and credentials each task needs.
  • Partner with the owners of Harvey's product sandbox and internal agent platform to make architectural decisions, implement protections, and integrate shared security capabilities into their execution environments.
  • Enable internal use of open-source models alongside infrastructure teams, building protections around model serving, agent execution, and sensitive-data handling.
  • Develop adversarial tests, evaluations, and telemetry that verify containment and expose failures. Build mechanisms to scope, observe, interrupt, and safely terminate agent activity.
  • Lead delivery and adoption across teams, mentor engineers, and remain hands-on through implementation and production operation, making clear tradeoffs across security, reliability, latency, and cost.

Benefits

  • 401k
  • health insurance
  • dental insurance
  • vision insurance
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service