Incident Handler

Harvey · San Francisco · $133.6K – $200.4K · Other

Posted 2026-10-09

Apply for this role →

ROLE OVERVIEW

Harvey’s products sit at the intersection of frontier AI, sensitive customer data, and critical business workflows. Our customers trust us to protect their information in an always-accelerating threat ecosystem, and security is how we foremost earn and keep our customers’ trust. We’re hiring an experienced Incident Response Handler to drive and ultimately lead incident response for security events. You will command incidents, coordinate containment, and enforce that real fixes are implemented, preventing recurrence. You’ll join a small, highly technical security team early in standing up a dedicated Detection & Response function, with real latitude to define how Harvey does incident response for years to come. Like the rest of Harvey’s security team, our program is built on offensive security experience - most engineers come from red-team, pentesting, or incident-response backgrounds, and we bring an attacker’s mindset to detection and response. This is an individual contributor role for someone who has operated in mature security organizations at leading technology companies and wants to help define incident response at one of the most important AI companies in the world.

WHAT YOU'LL DO

- Build strong relationships with key employees across the organization

- Participate in security incidents, leading investigations across cloud infrastructure, identity systems, corporate environments, and our AI platforms.

- Use, maintain, and contribute to an internally developed agentic SOC, fine tuned to Harvey’s threat environment

- Work cross functionally across technical and operational orgs, ensuring the right PRs ship and best policies are enforced

- Contribute to Harvey’s Detection & Response roadmap, including metrics, SLAs, threat modeling, and tabletop exercises for our most critical business risks.

- Work across teams to ensure incident follow ups are meaningfully closed

- Mentor engineers and incident responders, build playbooks and operational standards, and raise the security bar across the company.

WHAT YOU HAVE

- 3+ years of experience in Incident Response, Detection & Response, Security Operations, Threat Detection, or related security engineering disciplines.

- Experience participating in investigations and response efforts for complex security incidents in cloud-native environments.

- Deep understanding of attacker tactics, techniques, and procedures (MITRE ATT&CK and modern threat actor tradecraft).

- Experience with one or more major cloud platforms (AWS, GCP, Azure), plus strong knowledge of operating systems, networking, and identity systems.

- Experience building security automation and tooling, with strong scripting or software engineering skills in Python, Go, or similar languages.

- Experience communicating incident status and risk to senior leadership.

COMPENSATION

$133,600 - $200,400 USD

DEPENDING ON YOUR LOCATION, AN APPLICANT PRIVACY NOTICE MAY APPLY TO YOU. YOU CAN FIND ALL OF OUR APPLICANT PRIVACY NOTICES HERE https://harveyai.notion.site/Harvey-Candidate-Privacy-Notices-319ac3fcdd7a803bb807d5094f249922?pvs=74.

#LI-ES2

Apply for this role →

← Back to all jobs