Senior Product Security Engineer
2 weeks ago
Job Description Harness is a high-growth company that is disrupting the software delivery market. Our mission is to enable the 30 million software developers in the world to deliver code to their users reliably, efficiently, securely and quickly, increasing customers pace of innovation while improving the developer experience. We offer solutions for every step of the software delivery lifecycle to build, test, secure, deploy and manage reliability, feature flags and cloud costs. The Harness Software Delivery Platform includes modules for CI, CD, Cloud Cost Management, Feature Flags, Service Reliability Management, Security Testing Orchestration, Chaos Engineering, Software Engineering Insights and continues to expand at an incredibly fast pace. Harness is led by technologist and entrepreneur Jyoti Bansal, who founded AppDynamics and sold it to Cisco for $3.7B. We're backed with $425M in venture financing from top-tier VC and strategic firms, including J.P. Morgan, Capital One Ventures, Citi Ventures, ServiceNow, Splunk Ventures, Norwest Venture Partners, Adage Capital Partners, Balyasny Asset Management, Gaingels, Harmonic Growth Partners, Menlo Ventures, IVP, Unusual Ventures, GV (formerly Google Ventures), Alkeon Capital, Battery Ventures, Sorenson Capital, Thomvest Ventures and Silicon Valley Bank. Overview The Senior Product Security Engineer will lead efforts to secure the Harness software by embedding security into every stage of the development lifecycle. This role involves vulnerability management, internal adoption of cutting-edge security solutions, and enabling teams to shift left on security while safeguarding the software supply chain. Key Responsibilities - Lead identification, triage, and remediation of vulnerabilities across the Harness platform and modules, partnering with engineering teams to establish SLAs and track progress. - Collaborate with engineers to perform threat modeling for new and existing features, identifying risks early and providing actionable recommendations. - Promote and implement Harness STO and SCS modules internally to demonstrate security best practices and drive adoption. - Develop and integrate security controls and checks into CI/CD workflows to detect issues before deployment. - Establish robust processes for software supply chain security, including dependency management and artifact integrity verification using SLSA. - Stay updated on emerging threats targeting software supply chains and adjust strategies proactively. - Plan and execute periodic penetration tests to uncover vulnerabilities and validate security controls, working with internal teams and external testers. - Leverage expertise in security scanners and tools (e.g., SAST, DAST, IAST, SCA) to ensure consistent testing and reporting. - Evaluate and recommend security tools to align with organizational needs and improve testing coverage. - Partner with engineering, platform, and DevOps teams to foster a security-first mindset through training and enablement. - Support compliance initiatives by aligning product security practices with regulatory standards and maintaining audit documentation. - Participate in design and architecture reviews to identify and mitigate potential security weaknesses early in the development lifecycle. - Enhance automation for vulnerability management and reporting to improve visibility and response time. - Collaborate with incident response teams to investigate and remediate product-related security incidents. Qualifications - Proven 4 to 6 years of experience in product security, vulnerability management, and secure software development lifecycle practices. - Hands-on expertise with security tools such as OWASP ZAP, Burp Suite, Prisma Cloud, Semgrep, or equivalent. - Strong understanding of CI/CD processes, tools (e.g., Jenkins, GitHub Actions, Harness), and shift-left security approaches. - Knowledge of secure coding practices, threat modeling methodologies, and supply chain security principles. - Familiarity with different types of security testing SAST, DAST, IaC, SCA) and proficiency in evaluating scanning tools. - Experience scripting or coding in Python, Go, or Node.js for automation and security tooling. - Strong collaboration skills with engineering and DevOps teams to embed security practices effectively. - Passion for fostering a security-first culture through enablement, training, and continuous improvement. - Excellent communication skills to convey technical security concepts to diverse stakeholders. - Working knowledge of cloud environments (AWS, GCP, or Azure) and securing containerized applications (Docker, Kubernetes). - Experience scripting or automating security workflows using Python, Go, or similar languages. - Familiarity with modern IaC and cloud security scanning tools (e.g., Checkov, Prisma, Trivy). Harness In The News - Harness AI Tackles Software Development's Real Bottleneck - After Vibe Coding Comes Vibe Testing (Almost) - Startup Within a Startup: Empowering Intrapreneurs for Scalable Innovation - Jyoti Bansal (Harness) - Jyoti Bansal, Harness | theCUBEd Awards - Eight years after selling AppDynamics to Cisco, Jyoti Bansal is pursuing an unusual merger - Harness snags Split.io, as it goes all in on feature flags and experiments - Exclusive: Jyoti Bansal-led Harness has raised $150 million in debt financing All qualified applicants will receive consideration for employment without regard to race, color, religion, sex or national origin. Note on Fraudulent Recruiting/Offers We have become aware that there may be fraudulent recruiting attempts being made by people posing as representatives of Harness. These scams may involve fake job postings, unsolicited emails, or messages claiming to be from our recruiters or hiring managers. Please note, we do not ask for sensitive or financial information via chat, text, or social media, and any email communications will come from the domain @harness.io. Additionally, Harness will never ask for any payment, fee to be paid, or purchases to be made by a job applicant. All applicants are encouraged to apply directly to our open jobs via our website. Interviews are generally conducted via Zoom video conference unless the candidate requests other accommodations. If you believe that you have been the target of an interview/offer scam by someone posing as a representative of Harness, please do not provide any personal or financial information and contact us immediately at [Confidential Information]. You can also find additional information about this type of scam and report any fraudulent employment offers via the Federal Trade Commission's website (https://consumer.ftc.gov/articles/job-scams), or you can contact your local law enforcement agency.
-
Senior Security Engineer
4 weeks ago
Mumbai, Maharashtra, India, Maharashtra TAC Security Full timeJob descriptionAs a Security Engineer - VAPT, you will be responsible for conducting comprehensive security assessments, identifying vulnerabilities, and implementing effective remediation strategies. Leveraging your expertise in penetration testing and ethical hacking, you will play a key role in enhancing the security posture of our clients' systems and...
-
Security Engineer
3 weeks ago
india Altered Security Full timeWe are looking for Security Engineers with following qualities to join our team at Altered Security:- Passionate about information security. - Ability to solve challenges. - Interest in new attack vectors and creating challenges. - Demonstrated experience in Windows and Active Directory security. - If you hold CRTP certification, it is a plus.Who should...
-
Security Engineer
4 weeks ago
india Altered Security Full timeWe are looking forSecurity Engineerswith following qualities to join our team at Altered Security:Passionate about information security. Ability to solve challenges. Interest in new attack vectors and creating challenges. Demonstrated experience in Windows and Active Directory security. If you hold CRTP certification, it is a plus.Who should apply:Very good...
-
Senior Product Designer
5 days ago
Bengaluru, Karnataka, India Oleria Security Full time ₹ 5,00,000 - ₹ 8,00,000 per yearAbout Oleria:Oleria provides adaptive and autonomous identity security solutions that help organizations accelerate at the pace of change, trusting that their data is protected. Oleria enables organizations to have comprehensive visibility into their access posture and autonomously identifies and mitigates access risks before they can be exploited. Founded...
-
Senior product security engineer
3 weeks ago
Bengaluru, India Slice Full timeAbout Usslice the way you bankslice’s purpose is to make the world better at using money and time, with a major focus on building the best consumer experience for your money. We’ve all felt how slow, confusing, and complicated banking can be. So, we’re reimagining it. We’re building every product from scratch to be fast, transparent, and feel good,...
-
Security Engineer
4 weeks ago
Delhi, India, India TAC Security Full timeJob descriptionAs a Security Engineer - VAPT, you will be responsible for conducting comprehensive security assessments, identifying vulnerabilities, and implementing effective remediation strategies. Leveraging your expertise in penetration testing and ethical hacking, you will play a key role in enhancing the security posture of our clients' systems and...
-
Senior Product Security Engineer
4 weeks ago
Bengaluru, Karnataka, India, Karnataka Pocket FM Full timeAbout Pocket FMPocket FM is the world’s largest audio entertainment platform, revolutionizing the way stories are told and consumed. We bring together storytelling, technology, and creativity to deliver an immersive and engaging experience through audio series, audiobooks, and podcasts. With over 150 million+ users, and billions of minutes streamed...
-
Sr Security Engineer
4 weeks ago
Bengaluru, India Ecolab Full timeJob Description Job Position Senior Security Engineer Product Security Location: Bangalore, Karnataka Experience: 68 Years Department: Information Security Employment Type: Full-Time Overview Ecolab's Information Security team is seeking a Senior Security Engineer with strong expertise in Product Security to lead and enhance secure software development...
-
Senior Product Security Engineer
1 week ago
Bengaluru, Karnataka, India slice Full time ₹ 12,00,000 - ₹ 36,00,000 per yearAbout Usslice the way you bankslice's purpose is to make the world better at using money and time, with a major focus on building the best consumer experience for your money. We've all felt how slow, confusing, and complicated banking can be. So, we're reimagining it. We're building every product from scratch to be fast, transparent, and feel good, because...
-
Senior product security engineer
1 week ago
Bengaluru, Karnataka, India Cloud Software Group Full time ₹ 12,00,000 - ₹ 36,00,000 per yearThe Senior product security engineer is responsible for leading and executing the Security Development Lifecycle (SDL) for Citrix On-Prem and Cloud products to ensure that our software meets the customer expectation of security robustness, as well as drive and execute SDL best practices and its integration with the CI/CD, Agile and Waterfall development...