← Sottava, jobs the hour they open
18 h agofound 1 h ago
Incident Handler
Posted by Harvey on 9 October 2026. Still on their Ashby board when we checked 1 h ago.
Read out of the posting
LevelNot stated
Experience askedNot stated
EmploymentNot stated
LocationSan Francisco
RemoteNot stated
Visa sponsorshipNot stated
SalaryNot published, and most postings do not
Posted2026-10-09
Found viaashby, direct from their system
We saw it 17 hours after it went up.
The posting, as the company wrote it
WHY HARVEY
At Harvey, we’re transforming how legal and professional services operate. By combining frontier agentic AI, an enterprise-grade platform, and deep domain expertise, we’re reshaping how critical knowledge work gets done for decades to come.
This is a rare chance to help build a generational company at a true inflection point. We have strong product-market fit and world-class investor support. We’re scaling fast and defining a new category in real time. The work is ambitious, the bar is high, and the opportunity for growth — personal, professional, and financial — is unmatched.
Our team moves fast, takes ownership, and is deeply committed to the mission — operating with intensity, staying close to our customers, and pushing each other for excellence. We live by three values: Decisiveness, Simplicity, and Job's Not Finished. We act quickly on clear judgment over perfect information, we believe simplicity is what scales, and we're never satisfied with where we are. If you want to do the best work of your career alongside people who share that drive, we'd love to build with you.
At Harvey, the future of professional services is being written today — and we’re just getting started.
ROLE OVERVIEW
Harvey’s products sit at the intersection of frontier AI, sensitive customer data, and critical business workflows. Our customers trust us to protect their information in an always-accelerating threat ecosystem, and security is how we foremost earn and keep our customers’ trust. We’re hiring an experienced Incident Response Handler to drive and ultimately lead incident response for security events. You will command incidents, coordinate containment, and enforce that real fixes are implemented, preventing recurrence. You’ll join a small, highly technical security team early in standing up a dedicated Detection & Response function, with real latitude to define how Harvey does incident response for years to come. Like the rest of Harvey’s security team, our program is built on offensive security experience - most engineers come from red-team, pentesting, or incident-response backgrounds, and we bring an attacker’s mindset to detection and response. This is an individual contributor role for someone who has operated in mature security organizations at leading technology companies and wants to help define incident response at one of the most important AI companies in the world.
WHAT YOU'LL DO
- Build strong relationships with key employees across the organization
- Participate in security incidents, leading investigations across cloud infrastructure, identity systems, corporate environments, and our AI platforms.
- Use, maintain, and contribute to an internally developed agentic SOC, fine tuned to Harvey’s threat environment
- Work cross functionally across technical and operational orgs, ensuring the right PRs ship and best policies are enforced
- Contribute to Harvey’s Detection & Response roadmap, including metrics, SLAs, threat modeling, and tabletop exercises for our most critical business risks.
- Work across teams to ensure incident follow ups are meaningfully closed
- Mentor engineers and incident responders, build playbooks and operational standards, and raise the security bar across the company.
WHAT YOU HAVE
- 3+ years of experience in Incident Response, Detection & Response, Security Operations, Threat Detection, or related security engineering disciplines.
- Experience participating in investigations and response efforts for complex security incidents in cloud-native environments.
- Deep understanding of attacker tactics, techniques, and procedures (MITRE ATT&CK and modern threat actor tradecraft).
- Experience with one or more major cloud platforms (AWS, GCP, Azure), plus strong knowledge of operating systems, networking, and identity systems.
- Experience building security automation and tooling, with strong scripting or software engineering skills in Python, Go, or similar languages.
- Experience communicating incident status and risk to senior leadership.
COMPENSATION
$133,600 - $200,400 USD
DEPENDING ON YOUR LOCATION, AN APPLICANT PRIVACY NOTICE MAY APPLY TO YOU. YOU CAN FIND ALL OF OUR APPLICANT PRIVACY NOTICES HERE https://harveyai.notion.site/Harvey-Candidate-Privacy-Notices-319ac3fcdd7a803bb807d5094f249922?pvs=74.
#LI-ES2
Harvey is an equal opportunity employer and does not discriminate on the basis of race, gender, sexual orientation, gender identity/expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or related condition, or any other basis protected by law.
We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made by emailing accommodations@harvey.ai
Also open at Harvey
Why this page exists
We read companies’ own hiring systems every hour, 1,769 of them, and show a job the hour it opens instead of when a job board gets around to indexing it. We saw it 17 hours after it went up.
The feed is free. No card, no trial to expire.
Apply at HarveyA free account first, no card