Director of Detection and Response
Harvey · San Francisco
About this role
## Director of Detection and Response ### Why Harvey At Harvey, we’re transforming how legal and professional services operate. By combining frontier agentic AI, an enterprise-grade platform, and deep domain expertise, we’re reshaping how critical knowledge work gets done for decades to come. This is a rare chance to help build a generational company at a true inflection point—strong product-market fit, world-class investor support, and rapid scaling. Our team moves fast, takes ownership, and is deeply committed to the mission. **Values:** Decisiveness, Simplicity, and Job’s Not Finished. --- ### Role Overview Harvey is building AI-native software for professional services. Because our customers trust us with highly sensitive information and critical business workflows, **security is fundamental** to everything we build. We’re looking for a **Director of Detection and Response** to build and lead the team that: - identifies threats, - responds decisively to incidents, and - turns what we learn into stronger defenses. You will own Harvey’s **Detection and Response strategy**, **technical direction**, and **operational readiness** across our production platform and corporate environment. Working with the CISO and leaders across Engineering, Infrastructure, IT, Legal, and Customer Trust, you’ll translate business risk into a focused program that protects customer data and enables Harvey to move quickly with confidence. This is a technical leadership role for someone who can build an exceptional team, earn the trust of senior engineers, and bring clarity to high-stakes situations. --- ### What You’ll Do - **Build and lead the organization** - Hire and develop detection engineers, incident responders, and technical leaders - Establish clear ownership and a culture of curiosity, sound judgment, and continuous learning - Own the roadmap, staffing plan, and investment decisions - **Own incident response and crisis readiness** - Lead response to major security incidents (investigation, containment, recovery, executive communication) - Define severity criteria, escalation paths, playbooks, and sustainable **24/7 coverage** for critical threats - Develop incident commanders and cross-functional responders through exercises - **Build detection as an engineering capability** - Set technical direction for telemetry, detection pipelines, forensic tooling, and response automation across cloud, endpoint, identity, SaaS, and application environments - Apply software engineering practices to test detections, improve signal quality, and reduce manual work - Evaluate AI-assisted investigation with measurable quality and appropriate human oversight - **Focus defenses on meaningful threats** - (Additional responsibilities continue in the source description.)
Listing freshness
CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.