Haystack
← Back to Jobs
Full time
Other
HA

Incident Handler

HarveyNew York🇺🇸United StatesPosted Oct 9, 2026

Quick Overview

Seniority
Mid Senior
Employment type
Full Time
Work mode
Hybrid
Location
New York, United States
Posted
4 hours ago
GCPAWSAzurePythonREST

Job Description

Why Harvey

At Harvey, we’re transforming how legal and professional services operate. By combining frontier agentic AI, an enterprise-grade platform, and deep domain expertise, we’re reshaping how critical knowledge work gets done for decades to come.

This is a rare chance to help build a generational company at a true inflection point. We have strong product-market fit and world-class investor support. We’re scaling fast and defining a new category in real time. The work is ambitious, the bar is high, and the opportunity for growth — personal, professional, and financial — is unmatched.

Our team moves fast, takes ownership, and is deeply committed to the mission — operating with intensity, staying close to our customers, and pushing each other for excellence. We live by three values: Decisiveness, Simplicity, and Job's Not Finished. We act quickly on clear judgment over perfect information, we believe simplicity is what scales, and we're never satisfied with where we are. If you want to do the best work of your career alongside people who share that drive, we'd love to build with you.

At Harvey, the future of professional services is being written today — and we’re just getting started.

Role Overview

Harvey’s products sit at the intersection of frontier AI, sensitive customer data, and critical business workflows. Our customers trust us to protect their information in an always-accelerating threat ecosystem, and security is how we foremost earn and keep our customers’ trust. We’re hiring an experienced Incident Response Handler to drive and ultimately lead incident response for security events. You will command incidents, coordinate containment, and enforce that real fixes are implemented, preventing recurrence. You’ll join a small, highly technical security team early in standing up a dedicated Detection & Response function, with real latitude to define how Harvey does incident response for years to come. Like the rest of Harvey’s security team, our program is built on offensive security experience - most engineers come from red-team, pentesting, or incident-response backgrounds, and we bring an attacker’s mindset to detection and response. This is an individual contributor role for someone who has operated in mature security organizations at leading technology companies and wants to help define incident response at one of the most important AI companies in the world.

What You'll Do

  • Build strong relationships with key employees across the organization

  • Participate in security incidents, leading investigations across cloud infrastructure, identity systems, corporate environments, and our AI platforms.

  • Use, maintain, and contribute to an internally developed agentic SOC, fine tuned to Harvey’s threat environment

  • Work cross functionally across technical and operational orgs, ensuring the right PRs ship and best policies are enforced

  • Contribute to Harvey’s Detection & Response roadmap, including metrics, SLAs, threat modeling, and tabletop exercises for our most critical business risks.

  • Work across teams to ensure incident follow ups are meaningfully closed

  • Mentor engineers and incident responders, build playbooks and operational standards, and raise the security bar across the company.


What You Have

  • 3+ years of experience in Incident Response, Detection & Response, Security Operations, Threat Detection, or related security engineering disciplines.

  • Experience participating in investigations and response efforts for complex security incidents in cloud-native environments.

  • Deep understanding of attacker tactics, techniques, and procedures (MITRE ATT&CK and modern threat actor tradecraft).

  • Experience with one or more major cloud platforms (AWS, GCP, Azure), plus strong knowledge of operating systems, networking, and identity systems.

  • Experience building security automation and tooling, with strong scripting or software engineering skills in Python, Go, or similar languages.

  • Experience communicating incident status and risk to senior leadership.


Compensation

$133,600 - $200,400 USD

Depending on your location, an Applicant Privacy Notice may apply to you. You can find all of our Applicant Privacy Notices here.

#LI-ES2

Harvey is an equal opportunity employer and does not discriminate on the basis of race, gender, sexual orientation, gender identity/expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or related condition, or any other basis protected by law.

We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made by emailing accommodations@harvey.ai