Staff Security Research Engineer

2 days ago


Bengaluru India Harness Full time

Job Description Harness is a high-growth company that is disrupting the software delivery market. Our mission is to enable the 30 million software developers in the world to deliver code to their users reliably, efficiently, securely and quickly, increasing customers pace of innovation while improving the developer experience. We offer solutions for every step of the software delivery lifecycle to build, test, secure, deploy and manage reliability, feature flags and cloud costs. The Harness Software Delivery Platform includes modules for CI, CD, Cloud Cost Management, Feature Flags, Service Reliability Management, Security Testing Orchestration, Chaos Engineering, Software Engineering Insights and continues to expand at an incredibly fast pace. Harness is led by technologist and entrepreneur Jyoti Bansal, who founded AppDynamics and sold it to Cisco for $3.7B. We're backed with $425M in venture financing from top-tier VC and strategic firms, including J.P. Morgan, Capital One Ventures, Citi Ventures, ServiceNow, Splunk Ventures, Norwest Venture Partners, Adage Capital Partners, Balyasny Asset Management, Gaingels, Harmonic Growth Partners, Menlo Ventures, IVP, Unusual Ventures, GV (formerly Google Ventures), Alkeon Capital, Battery Ventures, Sorenson Capital, Thomvest Ventures and Silicon Valley Bank. Position Summary Harness is expanding into DevSecOps with the integration of Traceable, and we're hiring a Staff or Principal Security Research Engineer to help lead the charge. This is a rare opportunity to work with visionary leaders like Jyoti Bansal and help shape security across the modern software delivery lifecyclefrom code to cloud. You'll drive research into cutting-edge threats targeting APIs, CI/CD pipelines, and emerging technologies like LLMs. Your work will directly influence product direction, detection capabilities, and customer protection strategies. This is a hands-on, high-impact role where you'll collaborate across teams, interface with top-tier customers, and represent Harness at leading security conferences. If you're passionate about solving hard security problems at scale, this role puts you at the center of innovation in a fast-growing DevSecOps platform. About The Role - Conduct cutting-edge research on modern attack vectors across AppSec, CI/CD pipelines, runtime environments, and emerging technologies like LLMs - Develop and refine advanced exploit techniques to prevent attacks targeting software delivery, runtime from code to cloud - Collaborate with research, product and engineering to prototype and implement detection and mitigation strategies for emerging threats - Perform in-depth security assessments and penetration testing of web applications, APIs, build systems, and cloud-native environments - Engage with customers to understand their application landscape and provide expert guidance on integrating product capabilities with their security requirements - Support pre-sales, POCs, and post-sales engagements by troubleshooting and solving complex detection and protection challenges - Build internal tools to automate and enhance security research workflows. - Evangelize our research and platform through blogs, white papers, and talks at premier security conferences - Analyze global cybersecurity incidents to extract learnings and apply them across domains About You - Bachelor's or Master's degree in Computer Science. - 8+ years of work experience - Deep expertise with modern application stacks (microservices, containers, Kubernetes, cloud platforms like AWS/GCP) - Prior development experience and a fair understanding of programming languages and frameworks are a must - Proficient in at least one modern programming language (Python, Go, Java, JavaScript, etc.) - Demonstrated experience in penetration testing, vulnerability research, and exploitation of Web/API ecosystems - Strong foundation in computer science fundamentals, identity aware, network, application and runtime security - Strong experience with various pen testing tools like Burpsuite, ZAP, etc. - Strong applied knowledge of attacks in Web/API eco-system - Web attacks, API attacks, API abuse, API Fraud, ATO, etc. - Strong knowledge of modern application security threats and mitigation platforms like (WAFs, WAAP, RASP, etc.). - Working knowledge of IAST, DAST, and SAST - Experience in responsible disclosure of vulnerabilities and a track record of CVEs or similar - Proven track record of publishing high-quality research or presenting at top security conferences (e.g., Black Hat, DEF CON, RSAC, BSides) is a strong plus - Certifications such as CEH, OSCP, OSCE, or relevant security credentials - Strong analytical skills and the ability to conduct complex security research autonomously - Ability to work autonomously and drive complex security investigations from hypothesis to implementation Work Location This role will be out of our Bengaluru, India office on a Hybrid capacity. Harness In The News - Harness AI Tackles Software Development's Real Bottleneck - After Vibe Coding Comes Vibe Testing (Almost) - Startup Within a Startup: Empowering Intrapreneurs for Scalable Innovation - Jyoti Bansal (Harness) - Jyoti Bansal, Harness | theCUBEd Awards - Eight years after selling AppDynamics to Cisco, Jyoti Bansal is pursuing an unusual merger - Harness snags Split.io, as it goes all in on feature flags and experiments - Exclusive: Jyoti Bansal-led Harness has raised $150 million in debt financing All qualified applicants will receive consideration for employment without regard to race, color, religion, sex or national origin. Note on Fraudulent Recruiting/Offers We have become aware that there may be fraudulent recruiting attempts being made by people posing as representatives of Harness. These scams may involve fake job postings, unsolicited emails, or messages claiming to be from our recruiters or hiring managers. Please note, we do not ask for sensitive or financial information via chat, text, or social media, and any email communications will come from the domain @harness.io. Additionally, Harness will never ask for any payment, fee to be paid, or purchases to be made by a job applicant. All applicants are encouraged to apply directly to our open jobs via our website. Interviews are generally conducted via Zoom video conference unless the candidate requests other accommodations. If you believe that you have been the target of an interview/offer scam by someone posing as a representative of Harness, please do not provide any personal or financial information and contact us immediately at [Confidential Information]. You can also find additional information about this type of scam and report any fraudulent employment offers via the Federal Trade Commission's website (https://consumer.ftc.gov/articles/job-scams), or you can contact your local law enforcement agency.


  • Security Researcher

    3 weeks ago


    india, IN Altered Security Full time

    We are looking for top Security Researchers (Remote) with demonstrable expertise to join our team of experts!Altered Security is an information security startup with focus on edtech, hands-on learning and focused security assessments. It has offices in India and Singapore.We are experts in information security training, cyber ranges, online labs and security...


  • Bengaluru, India Zscaler Full time

    Company Description With more than 10 years of experience developing, operating, and scaling the cloud, Zscaler serves thousands of enterprise customers around the world, including 450 of the Forbes Global 2000 organizations. In addition to protecting customers from damaging threats, such as ransomware and data exfiltration, it helps them slash costs,...


  • Bengaluru, Karnataka, India Palo Alto Networks Full time ₹ 20,00,000 - ₹ 25,00,000 per year

    Senior Staff Security Researcher (Prisma Cloud) Company Description Our Mission At Palo Alto Networks everything starts and ends with our mission: Being the cybersecurity partner of choice, protecting our digital way of life. Our vision is a world where each day is safer and more secure than the one before. We are a company built on the...

  • Security Engineer

    3 weeks ago


    india Altered Security Full time

    We are looking for Security Engineers with following qualities to join our team at Altered Security:- Passionate about information security. - Ability to solve challenges. - Interest in new attack vectors and creating challenges. - Demonstrated experience in Windows and Active Directory security. - If you hold CRTP certification, it is a plus.Who should...

  • Security Researcher

    3 weeks ago


    Bengaluru, Karnataka, India, Karnataka Vehere Full time

    Job Summary:We are seeking a seasoned Security Researcher with deep expertise in malware analysis, reverse engineering, and cloud threat research. The ideal candidate will have extensive hands-on experience analyzing advanced malware, uncovering TTPs (Techniques, Tactics, and Procedures) used by threat actors, and aligning their findings with the MITRE...

  • Security Researcher

    4 hours ago


    Mohali, India SquareX Full time

    Job Description Mode: In-Person/Office - Mohali (India) CTC: 12 to 25 LPA (Based on experience and skills) About SquareX SquareX is a leading cybersecurity company that focuses on providing robust protection to users while ensuring their productivity remains unhampered. Our mission is to secure the internet for everyone, making our services invaluable to...

  • Security Engineer

    3 weeks ago


    india Altered Security Full time

    We are looking forSecurity Engineerswith following qualities to join our team at Altered Security:Passionate about information security. Ability to solve challenges. Interest in new attack vectors and creating challenges. Demonstrated experience in Windows and Active Directory security. If you hold CRTP certification, it is a plus.Who should apply:Very good...

  • Staff Engineer

    1 week ago


    Bengaluru, Karnataka, India Rubrik Security Cloud Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    Staff Engineer, Rubrik Security AppsBangalore, IndiaAbout Team:The Rubrik Security Apps team helps customers secure their data on the cloud, SaaS and on-prem. Data is growing at an ever growing pace and so are the risks with cyber attacks targeted towards cloud data. We make it easy for businesses to protect, search, analyze all of their data simply and...


  • Bengaluru, India Vehere Full time

    Job Description Job Summary: We are seeking a seasoned Security Researcher with deep expertise in malware analysis, reverse engineering, and cloud threat research. The ideal candidate will have extensive hands-on experience analyzing advanced malware, uncovering TTPs (Techniques, Tactics, and Procedures) used by threat actors, and aligning their findings...


  • Mohali, India TAC Security Full time

    Job Description Job Summary: TAC Security is looking for a passionate and motivated Cyber Security Intern to join our team in Mohali. The intern will assist in identifying security vulnerabilities, conducting research on emerging threats, and supporting ongoing cybersecurity projects. This internship offers hands-on experience in a global cybersecurity...