Security Research Engineer
5 days ago
Job Description Harness is a high-growth company that is disrupting the software delivery market. Our mission is to enable the 30 million software developers in the world to deliver code to their users reliably, efficiently, securely and quickly, increasing customers pace of innovation while improving the developer experience. We offer solutions for every step of the software delivery lifecycle to build, test, secure, deploy and manage reliability, feature flags and cloud costs. The Harness Software Delivery Platform includes modules for CI, CD, Cloud Cost Management, Feature Flags, Service Reliability Management, Security Testing Orchestration, Chaos Engineering, Software Engineering Insights and continues to expand at an incredibly fast pace. Harness is led by technologist and entrepreneur Jyoti Bansal, who founded AppDynamics and sold it to Cisco for $3.7B. We're backed with $425M in venture financing from top-tier VC and strategic firms, including J.P. Morgan, Capital One Ventures, Citi Ventures, ServiceNow, Splunk Ventures, Norwest Venture Partners, Adage Capital Partners, Balyasny Asset Management, Gaingels, Harmonic Growth Partners, Menlo Ventures, IVP, Unusual Ventures, GV (formerly Google Ventures), Alkeon Capital, Battery Ventures, Sorenson Capital, Thomvest Ventures and Silicon Valley Bank. Key Responsibilities - Contribute to research on modern attack vectors across source code, dependencies, build systems, and CI/CD pipelines. - Assist in developing scanning and detection techniques for SAST, SCA, and DAST to identify security flaws early in the development process. - Perform hands-on assessments of web applications, APIs, and build pipelines under guidance to uncover design flaws, misconfigurations, and dependency risks. - Study software supply chain threats and contribute to identifying and mitigating risks across open-source ecosystems. - Perform hands-on assessments of code, applications, APIs, and build pipelines under guidance to uncover design flaws, misconfigurations, and security risks. - Help build and test prototype tools that automate vulnerability detection and developer workflow integration. - Collaborate with research, product, and engineering teams to validate findings and implement security improvements in developer environments. - Stay current with new vulnerabilities, frameworks, and DevSecOps practices to identify emerging threats relevant to modern software delivery. - Document findings and share insights through internal reports, knowledge bases, or external blog drafts. Required Skills & Experience - Bachelor's degree in Computer Science, Cybersecurity, or a related field (or equivalent practical experience). - 1 - 4 years of experience application security or security research - Foundational understanding of Shift-Left Security concepts such as SAST, SCA, and DAST. - Understanding of CI/CD pipelines, build systems, and developer workflows. - Interest in AI and LLM models, and curiosity about how they impact software security (e.g., insecure code generation, data leakage, dependency risks). - Familiarity with dependency management ecosystems (npm, PyPI, Maven, Go modules) and basic knowledge of software supply chain risks. - Passion for research, security, and continuous learning, with a never-give-up attitude. - Knowledge of OWASP Top 10, API Top 10, LLM Top 10, CI/CD Top 10. - Strong analytical mindset with curiosity for exploring how attackers exploit weaknesses in code and pipelines. - Proficiency in Java and Python for prototyping and automating rule validation workflows. - Excellent communication, documentation, and cross-functional collaboration skills. Nice to Have - Contributions to open-source security projects, especially those related to the OWASP Top 10 or OWASP API Top 10. - Experience developing custom WAF/WAAP rule engines, threat classifiers, or signal correlation pipelines. - Background in API security, runtime protection, or detection engineering at scale. - Authored publications, technical blogs, or delivered conference talks. Harness In The News - Harness AI Tackles Software Development's Real Bottleneck - After Vibe Coding Comes Vibe Testing (Almost) - Startup Within a Startup: Empowering Intrapreneurs for Scalable Innovation - Jyoti Bansal (Harness) - Jyoti Bansal, Harness | theCUBEd Awards - Eight years after selling AppDynamics to Cisco, Jyoti Bansal is pursuing an unusual merger - Harness snags Split.io, as it goes all in on feature flags and experiments - Exclusive: Jyoti Bansal-led Harness has raised $150 million in debt financing All qualified applicants will receive consideration for employment without regard to race, color, religion, sex or national origin. Note on Fraudulent Recruiting/Offers We have become aware that there may be fraudulent recruiting attempts being made by people posing as representatives of Harness. These scams may involve fake job postings, unsolicited emails, or messages claiming to be from our recruiters or hiring managers. Please note, we do not ask for sensitive or financial information via chat, text, or social media, and any email communications will come from the domain @harness.io. Additionally, Harness will never ask for any payment, fee to be paid, or purchases to be made by a job applicant. All applicants are encouraged to apply directly to our open jobs via our website. Interviews are generally conducted via Zoom video conference unless the candidate requests other accommodations. If you believe that you have been the target of an interview/offer scam by someone posing as a representative of Harness, please do not provide any personal or financial information and contact us immediately at [Confidential Information]. You can also find additional information about this type of scam and report any fraudulent employment offers via the Federal Trade Commission's website (https://consumer.ftc.gov/articles/job-scams), or you can contact your local law enforcement agency.
-
Security Researcher
4 weeks ago
india, IN Altered Security Full timeWe are looking for top Security Researchers (Remote) with demonstrable expertise to join our team of experts!Altered Security is an information security startup with focus on edtech, hands-on learning and focused security assessments. It has offices in India and Singapore.We are experts in information security training, cyber ranges, online labs and security...
-
Security Engineer
4 weeks ago
india Altered Security Full timeWe are looking for Security Engineers with following qualities to join our team at Altered Security:- Passionate about information security. - Ability to solve challenges. - Interest in new attack vectors and creating challenges. - Demonstrated experience in Windows and Active Directory security. - If you hold CRTP certification, it is a plus.Who should...
-
Security Engineer
4 weeks ago
india Altered Security Full timeWe are looking forSecurity Engineerswith following qualities to join our team at Altered Security:Passionate about information security. Ability to solve challenges. Interest in new attack vectors and creating challenges. Demonstrated experience in Windows and Active Directory security. If you hold CRTP certification, it is a plus.Who should apply:Very good...
-
Security Researcher
4 weeks ago
Bengaluru, Karnataka, India, Karnataka Vehere Full timeJob Summary:We are seeking a seasoned Security Researcher with deep expertise in malware analysis, reverse engineering, and cloud threat research. The ideal candidate will have extensive hands-on experience analyzing advanced malware, uncovering TTPs (Techniques, Tactics, and Procedures) used by threat actors, and aligning their findings with the MITRE...
-
Security Researcher
5 days ago
Mohali, India SquareX Full timeJob Description Mode: In-Person/Office - Mohali (India) CTC: 12 to 25 LPA (Based on experience and skills) About SquareX SquareX is a leading cybersecurity company that focuses on providing robust protection to users while ensuring their productivity remains unhampered. Our mission is to secure the internet for everyone, making our services invaluable to...
-
Intern- Security Engineer
5 days ago
Mohali, India TAC Security Full timeJob Description Job Summary: TAC Security is looking for a passionate and motivated Cyber Security Intern to join our team in Mohali. The intern will assist in identifying security vulnerabilities, conducting research on emerging threats, and supporting ongoing cybersecurity projects. This internship offers hands-on experience in a global cybersecurity...
-
Staff Security Research Engineer
6 days ago
Bengaluru, India Harness Full timeJob Description Harness is a high-growth company that is disrupting the software delivery market. Our mission is to enable the 30 million software developers in the world to deliver code to their users reliably, efficiently, securely and quickly, increasing customers pace of innovation while improving the developer experience. We offer solutions for every...
-
Associate Security Researcher
4 weeks ago
Bengaluru, India Calix Full timeJob Description Calix is hiring Security Researcher to join their Threat Intelligence team in Bangalore. The successful candidates will lead efforts in identifying, analyzing, and mitigating network threats. Develop and implement advanced threat detection and prevention strategies. Additionally, they will enhance threat detection capabilities through various...
-
Security Engineer
4 weeks ago
Delhi, India, India TAC Security Full timeJob descriptionAs a Security Engineer - VAPT, you will be responsible for conducting comprehensive security assessments, identifying vulnerabilities, and implementing effective remediation strategies. Leveraging your expertise in penetration testing and ethical hacking, you will play a key role in enhancing the security posture of our clients' systems and...
-
Clinical Research Systems Engineer
3 weeks ago
Bengaluru, India MS CLINICAL RESEARCH Full timePosition: Software Engineer/ IT Support Engineer – Clinical ResearchDepartment: IT / Research TechnologyLocation: Indiranagar, BangaloreEmployment Type: Full-time/ ConsultantExperience: 2-4 yearsJob SummaryWe are looking for a Software Engineer to support our clinical research systems and data operations. The role involves managing secure networks,...