Director of Detection and Response

harvey· Security
Apply Now ↗
📍 San FranciscoFullTime💰 USD 280K–385K

About this role

Why Harvey

At Harvey, we’re transforming how legal and professional services operate. By combining frontier agentic AI, an enterprise-grade platform, and deep domain expertise, we’re reshaping how critical knowledge work gets done for decades to come.

This is a rare chance to help build a generational company at a true inflection point. We have strong product-market fit and world-class investor support. We’re scaling fast and defining a new category in real time. The work is ambitious, the bar is high, and the opportunity for growth — personal, professional, and financial — is unmatched.

Our team moves fast, takes ownership, and is deeply committed to the mission — operating with intensity, staying close to our customers, and pushing each other for excellence. We live by three values: Decisiveness, Simplicity, and Job's Not Finished. We act quickly on clear judgment over perfect information, we believe simplicity is what scales, and we're never satisfied with where we are. If you want to do the best work of your career alongside people who share that drive, we'd love to build with you.

At Harvey, the future of professional services is being written today — and we’re just getting started.

Role Overview

Harvey is building AI-native software for professional services. Our customers trust us with highly sensitive information and critical business workflows, making security fundamental to everything we build. We’re looking for a Director of Detection and Response to build and lead the team that identifies threats, responds decisively to incidents, and turns what we learn into stronger defenses.

You will own Harvey’s Detection and Response strategy, technical direction, and operational readiness across our production platform and corporate environment. Working with the CISO and leaders across Engineering, Infrastructure, IT, Legal, and Customer Trust, you’ll translate business risk into a focused program that protects customer data and enables Harvey to move quickly with confidence.

This is a technical leadership role for someone who can build an exceptional team, earn the trust of senior engineers, and bring clarity to high-stakes situations. You’ll develop a function that scales through software, automation, and strong partnerships, while staying close enough to the work to challenge detection designs and guide complex investigations.

What You'll Do

  • Build and lead the organization. Hire and develop detection engineers, incident responders, and technical leaders; establish clear ownership and a culture of curiosity, sound judgment, and continuous learning. Own the roadmap, staffing plan, and investment decisions.

  • Own incident response and crisis readiness. Lead Harvey’s response to major security incidents, coordinating investigation, containment, recovery, and executive communication. Build clear severity criteria, escalation paths, playbooks, and sustainable 24/7 coverage for critical threats; develop incident commanders and cross-functional responders through exercises.

  • Build detection as an engineering capability. Set the technical direction for telemetry, detection pipelines, forensic tooling, and response automation across cloud, endpoint, identity, SaaS, and application environments. Apply software engineering practices to test detections, improve signal quality, and reduce manual work; evaluate AI-assisted investigation with measurable quality and appropriate human oversight.

  • Focus defenses on meaningful threats. Use threat intelligence, hunting, and an attacker’s perspective to prioritize scenarios that matter to Harvey, including account compromise, data theft, insider risk, privileged-access abuse, and abuse of AI-enabled workflows. Partner with offensive security and platform owners to validate coverage and close blind spots.

  • Make response a company capability. Partner with Engineering, IT, Legal, Privacy, Communications, and Customer Trust on sensitive investigations and crisis decisions. Establish clear escalation and decision authority, preserve evidence, and provide accurate findings to support Legal-led notification and disclosure decisions. Prepare cross-functional responders to contribute when incidents require broader support.

  • Turn incidents into lasting improvements. Drive blameless reviews and ensure corrective actions have owners, deadlines, and verified outcomes. Measure detection coverage, time to detect and contain, recurring failure modes, and responder workload, and use those results to guide investments and reduce customer impact.

What You Have

  • Experience building and leading Detection and Response, incident response, or security engineering teams in a technology company with complex production systems. A record of hiring strong engineers, developing technical leaders, and scaling both the team and its operating model.

  • Deep incident response experience and demonstrated judgment during serious security events. You can lead investigations with incomplete information, make timely containment decisions, and communicate clearly with executives, engineers, and business partners. You bring composure, integrity, and discretion to sensitive investigations and decisions under scrutiny.

  • Strong technical foundations in cloud infrastructure, operating systems, networking, identity, and attacker tradecraft, with depth in detection engineering, threat hunting, or digital forensics. You understand how to investigate across corporate and production environments.

  • An engineering approach to security operations, backed by experience building detection platforms, investigation tools, or response automation. You can evaluate architecture and code, guide senior engineers, and make practical decisions about what to build, buy, or retire.

  • The ability to turn business risk into a focused strategy and deliver it through influence and partnership. You balance urgent response with long-term engineering work and build a demanding, supportive environment where people can do their best work.

Experience protecting enterprise SaaS, sensitive customer data, or AI/ML environments is especially valuable, as is experience investigating insider threats, partnering on privileged-access governance, or leading response under regulatory and public scrutiny.

At Harvey, you’ll shape how an AI company detects and responds to threats as its products and customers evolve. Your team’s work will directly protect customer trust and help make security a durable foundation for the business.

Compensation

$280,000 - $385,000 USD

Depending on your location, an Applicant Privacy Notice may apply to you. You can find all of our Applicant Privacy Notices here.

#LI-DZ1

Harvey is an equal opportunity employer and does not discriminate on the basis of race, gender, sexual orientation, gender identity/expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or related condition, or any other basis protected by law.

We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made by emailing accommodations@harvey.ai

Frequently Asked Questions

What is the salary for the Director of Detection and Response role at harvey?
The listed salary for this Director of Detection and Response position at harvey is USD 280K–385K. This is an FullTime role.
Where is the Director of Detection and Response position at harvey located?
This Director of Detection and Response role at harvey is based in San Francisco. The position is listed as on-site or hybrid. Check the full job description or apply directly to confirm the work arrangement.
Is the Director of Detection and Response role at harvey full-time or part-time?
This is listed as a FullTime position. It is posted as a Director of Detection and Response role in the Security department at harvey.
Which team or department does the Director of Detection and Response at harvey belong to?
This Director of Detection and Response position is part of the Security department at harvey. See the full job description for more information about the team structure and responsibilities.
How do I apply for the Director of Detection and Response position at harvey?
Click the "Apply Now" button on this page. You will be redirected to harvey's official application portal hosted on ashby where you can submit your application directly.
When was the Director of Detection and Response job at harvey posted?
This Director of Detection and Response position at harvey was posted on Oct 8, 2026. Apply as soon as possible — early applications are often reviewed first.
Director of Detection and Response
harvey · 💰 USD 280K–385K
Apply for this role ↗

You'll be redirected to harvey's official application page on Ashby ATS.