Harness - Staff Product Security Engineer - DAST/SAST

2 months ago


bangalore, India Harness.io Full time

As a Staff Security Engineer, you will lead efforts to extend visibility into Harness' security posture, integrate and automate core security technologies, and drive continuous improvement across our technical estate.

You'll use your knowledge to test, design, and secure solutions that enable Harness' business goals, and collaborate directly with engineering teams to Get Ship Done.

You will be responsible for cross-team projects with Engineering and Product, and will sharpen new skills as we continue to scale.

In this role, you will :

- Design and develop product security APIs, tools and utilities for internal and external stakeholders.

- Conduct threat modeling and secure design review of applications backend services and business integrations.

- Good understanding of cyber security frameworks like OWASP, SANS, NIST, CIS, etc.

- Perform advanced penetration tests and simulate adversarial attacks against Harness modules APIs, and codebase using industry standard frameworks.

- Participate in the creation, review and implementation of technical security across global Engineering teams.

- Consult and advise with developers and Product Managers to analyze and implement security standards, methods, vulnerability remediation, and security architecture.

- Assess risks and trade-offs, and propose solutions for product security features such as authentication and authorization.

- Lead manual and automated code review and testing efforts to discover vulnerabilities, weaknesses, and anti-patterns in the Harness platform.

- Implement and own operation of security tooling, including but not limited to SAST, DAST, and SCA.

- Use the Harness platform to integrate security processes like vulnerability management into the SDLC.

About You :

- You have a BS in Computer Science or a related degree.

- You have at least 7 years of relevant industry experience as a software engineer with a strong security focus.

- Experienced with DevSecOps.

- Ability to describe Secure SDLC best practices and software supply chain risks.

- Experience with any of the Public/Private cloud environments (K8s, AWS, GCP, Azure, etc.).

- You have expert professional knowledge of enterprise applications, API development, and modern software delivery processes.

- You have previous experience in a cloud-native environment.

- You are proficient with Java or any similar language and object-oriented programming methodology.

(ref:hirist.tech)

  • Bangalore, India Harness.io Full time

    As a Staff Security Engineer, you will lead efforts to extend visibility into Harness' security posture, integrate and automate core security technologies, and drive continuous improvement across our technical estate. You'll use your knowledge to test, design, and secure solutions that enable Harness' business goals, and collaborate directly...


  • Bangalore, Karnataka, India Harness.io Full time

    As a Staff Security Engineer, you will lead efforts to extend visibility into Harness' security posture, integrate and automate core security technologies, and drive continuous improvement across our technical estate. You'll use your knowledge to test, design, and secure solutions that enable Harness' business goals, and collaborate directly with...


  • bangalore, India Programming.com Full time

    Position : Application Security EngineerLocation : Pune and Bangalore, IndiaJob Description :Programming.com is seeking highly skilled and experienced Application Security Engineers to join our team in Pune and Bangalore. As an Application Security Engineer, you will play a crucial role in ensuring the security of our applications by performing manual code...


  • Bangalore/Pune, India Programming.com Full time

    Position : Application Security EngineerLocation : Pune and Bangalore, IndiaJob Description :Programming.com is seeking highly skilled and experienced Application Security Engineers to join our team in Pune and Bangalore. As an Application Security Engineer, you will play a crucial role in ensuring the security of our applications by performing manual code...


  • Bangalore/Pune, India Employee Hub LLP Full time

    Requirements : - Bachelor's Degree in Computer Science, Engineering, or related field- 4 - 8 years of experience performing manual code review and threat modeling.- 4 - 8 years of experience with SCA, SAST, DAST application security tools- Deep technical knowledge and experience identifying, triaging, and remediating application vulnerabilities...


  • bangalore, India FIS Full time

    Position Type : Full time Type Of Hire : Experienced (relevant combo of work and education) Education Desired : Bachelor of Computer Science Travel Percentage : 0% As the world works and lives faster, FIS is leading the way. Our fintech solutions touch nearly every market, company and person on the planet. Our teams are inclusive and...


  • bangalore, India Jobs for Humanity Full time

    Job Description Position Type : Full time Type Of Hire : Experienced (relevant combo of work and education) Education Desired : Bachelor of Computer Science Travel Percentage : 0%As the world works and lives faster, FIS is leading the way. Our fintech solutions touch nearly every market, company and person on the planet. Our teams are inclusive and...


  • Bangalore,Anywhere in India,Multiple Locations Zyoin group Full time

    Responsibilities : - Work closely with the engineering team to address technical and product-related queries from both customers and L1/L2 teams.- Replicate issues in test environments to diagnose and resolve.- Utilize SQL skills to extract data relevant to customer queries or issues.- Use REST APIs to diagnose and resolve integration or data flow...


  • Anywhere in India,Multiple Locations,Any Location,Bangalore Zyoin Full time

    Company - Software Development5 Days workingWFH / Remote WorkingJob Description : - Work closely with the engineering team to address technical and product-related queries from both customers and L1/L2 teams. - Replicate issues in test environments to diagnose and resolve.- Utilize SQL skills to extract data relevant to customer queries or issues.- Use REST...


  • bangalore, India Harness Full time

    The world runs on software. Yet delivering changes to software remains massively complicated, highly manual, and risk-prone. At Harness, our mission is to simplify the entire software delivery process so that software engineering teams can move fast and ship code effortlessly without the fear of breaking things. That's why we're bringing the industry’s...


  • bangalore, India RSA Security Full time

    Responsibilities• Work on any number of security and identity related areas and products• Build systems for detecting anomalous activities within the product• Develops and administers software engineering procedures and training for vulnerability scans and static code analysis• Analyse vulnerability report of various SCA and SAST scan tools like,...


  • bangalore, India Synopsys Inc Full time

    At Synopsys, we pride ourselves for building products and delivering services that help our customers keep their applications safe and secure. Our people do this so well, we have been named the AppSec leader for seven years in a row by Gartner.We are looking for an experienced staff software engineer who will join forces with the development team for our...


  • bangalore, India RSA Security Full time

    RSA - Application Security Engineer Location: Remote India RSA offers mission-driven security solutions that provide organizations with a unified approach to managing digital risk that hinges on integrated visibility, automated insights and coordinated actions. RSA solutions are designed to effectively detect and respond to advanced attacks;...


  • bangalore, India Trellix Full time

    About the Role: Collaborate with development teams to integrate security practices into the Software Development Life Cycle (SDLC). Provide guidance and assistance in implementing secure coding practices and principles. Conduct security code reviews and provide feedback to development teams. Utilize SAST tools to analyze source code...


  • bangalore, India EdgeVerve Full time

    Edgeverve is a subsidiary of Infosys Ltd, specializing in Products. You will get an opportunity to work with a motivated team of individuals that cater to critical areas of security like product security, Cloud security, Mobile security and Enterprise security. You will be overseeing effective vulnerability assessment, penetration testing of products...


  • Bangalore, Karnataka, India THOUGHTSPOT INDIA PRIVATE LIMITED Full time

    Responsibilities: Define and execute the security posture for ThoughtSpot services running across multiple cloud and hybrid environments.Provide technical leadership, mentor team members, and lead initiatives across the R/D org across geographies.Experiment and drive technology decisions across multi-cloud environments - AWS, GCP, and private cloud.Architect...


  • Bangalore, India THOUGHTSPOT INDIA PRIVATE LIMITED Full time

    Responsibilities: Define and execute the security posture for ThoughtSpot services running across multiple cloud and hybrid environments. Provide technical leadership, mentor team members, and lead initiatives across the R/D org across geographies. Experiment and drive technology decisions across multi-cloud environments - AWS, GCP, and private cloud....


  • Bangalore, India Harness.io Full time

    Harness is a high-growth startup that is disrupting the software delivery market. Our mission is to enable the 30 million software developers in the world to deliver code to their users reliably, efficiently, securely and quickly, increasing customers' pace of innovation while improving the developer experience. We offer solutions for every step of the...


  • bangalore, India Harness.io Full time

    Harness is a high-growth startup that is disrupting the software delivery market. Our mission is to enable the 30 million software developers in the world to deliver code to their users reliably, efficiently, securely and quickly, increasing customers' pace of innovation while improving the developer experience. We offer solutions for every step of the...


  • Bangalore, Karnataka, India Harness.io Full time

    Harness is a high-growth startup that is disrupting the software delivery market. Our mission is to enable the 30 million software developers in the world to deliver code to their users reliably, efficiently, securely and quickly, increasing customers' pace of innovation while improving the developer experience. We offer solutions for every step of the...