This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Harvey is looking for a Head of Trust to own and scale our trust and compliance function as the company grows rapidly and our product continues to evolve for legal and professional services teams. This role sits at the intersection of security, product, and go-to-market, serving as both the internal authority on compliance and the external face of Harvey’s security posture with customers, prospects, auditors, and internal stakeholders. You’ll lead and expand a growing Trust team while acting as a key escalation point for enterprise deals, audits, and high-stakes security decisions. This role reports to the Head of Security and owns Harvey’s Trust function, including security governance, risk management, and compliance across the company.
Job Responsibility:
Own and lead Harvey’s global trust, risk, and compliance strategy, including FedRAMP, SOC 2, ISO 27001, ISO 27701, ISO 42001, and IRAP
Serve as the primary security and compliance escalation point for enterprise deals, partnering closely with Account Executives on redlines, customer calls, and security reviews
Lead internal and external audits end-to-end, ensuring controls remain effective as the product and organization change rapidly
Partner with executive leadership to define compliance priorities, and long-term trust strategy, including preparing materials and recommendations for leadership review
Establish and track clear metrics for audit readiness, deal velocity impacted by security reviews, and ongoing control effectiveness
Build, scale, and lead a high-performing Trust organization, including hiring and managing TPMs and setting operating rhythms in a high-growth environment
Communicate Harvey’s security architecture, product changes, and risk posture clearly to customers, prospects, auditors, and internal stakeholders
Develop and execute a differentiated security narrative that positions Harvey’s strong security posture as a competitive advantage in the legal AI market
Evaluate and guide long-term regulatory and compliance strategy, including the business case, timing, and readiness for additional compliance frameworks
Requirements:
Deep technical understanding of modern cloud infrastructure, IT, security architecture, and how controls map to fast-changing products
Strong business judgment and GTM instincts, with experience making pragmatic decisions on contract redlines, risk acceptance, and compliance tradeoffs
Hands-on expertise with major compliance frameworks (FedRAMP, SOC 2, ISO 27001, IRAP), with the ability to navigate nuances beyond the auditor playbook
Proven experience leading compliance programs and internal and external audits
Demonstrated ability to manage complex relationships with customers, auditors, and senior stakeholders, including navigating disagreement and ambiguity
Experience designing and scaling security or compliance organizations, including hiring, mentoring, and leading teams through periods of rapid change
Experience operating in a high-growth environment, maintaining compliance while products, teams, and priorities change rapidly