Product Security Engineer

Harness

Bengaluru

Sur place

INR 3 500 000 - 6 000 000

Plein temps

14 jours+
Générateur de candidature

Une candidature conçue pour ce poste — un CV et une lettre de motivation personnalisés qui correspondent à l’offre.

Passez les filtres ATS

Résumé du poste

Harness is the AI Software Delivery Platform company, led by technologist Jyoti Bansal. Harness has built its platform to apply deep context and intelligent automation across the software delivery lifecycle with governance and policy-driven controls.

As a Product Security Engineer, you will own daily product-security operations, triage escalations, and drive vulnerability management while integrating scanners into CI/CD.

Qualifications

  • Proven experience in product security and secure SDLC.
  • Hands-on expertise with OWASP ZAP, Burp Suite, Snyk, Prisma Cloud, Semgrep.
  • Strong understanding of CI/CD processes and shift-left security.
  • Knowledge of secure coding practices and threat modeling.
  • Familiarity with AI security concerns in SDLC and LLM apps.

Responsabilités

  • Own daily product-security operations and triage escalations.
  • Lead triage and remediation of vulnerabilities with engineering.
  • Tune SAST/SCA and cloud/container scanners and reduce noise.
  • Integrate security controls into CI/CD pipelines.
  • Promote internal adoption of Harness STO and SCS security modules.
  • Support release security advisories with customer-facing summaries.
  • Establish software supply-chain practices and stay current on threats.
  • Plan periodic penetration tests and validate security controls.
  • Evaluate tools to close coverage gaps and automate reporting.
  • Collaborate with incident response and audit readiness.

Connaissances

Product security
Vulnerability management
Secure SDLC
CI/CD security
SAST/SCA tools
Semgrep
Snyk
Prisma Cloud
OWASP Top 10
Collaboration with Eng/DevOps

Outils

OWASP ZAP
Burp Suite
Snyk
Prisma Cloud
Semgrep
Jenkins
GitHub Actions
Harness

Description du poste

Job Description:

Harness is the AI Software Delivery Platform company, led by technologist and entrepreneur Jyoti Bansal (founder of AppDynamics, acquired by Cisco for $3.7B). Harness has raised approximately $570M in funding and is valued at $5.5B, backed by leading investors including Goldman Sachs, Menlo Ventures, IVP, Unusual Ventures, Citi Ventures, and more. As AI accelerates code creation, the real bottleneck has shifted to everything after the code - testing, deployments, application security, reliability, compliance, and cost optimization. Harness brings AI and automation to this "outer loop," helping teams ship software faster while maintaining security and governance throughout the entire software delivery lifecycle.

Powered by Harness AI and the Software Delivery Knowledge Graph, the Harness Platform applies deep context and intelligent automation across the software delivery lifecycle with governance and policy-driven controls embedded throughout the platform.

Over the past year, Harness powered over 185M deployments, 82M builds, 18T flag evaluations, 8M security scans, 9.1B optimized tests, 3T protected API calls, and helped manage $2.8B in cloud spend - enabling customers like United Airlines, Morningstar, and Choice Hotels to accelerate releases by up to 75%, reduce cloud costs by up to 60%, and achieve 10x DevOps efficiency.

With a global team across 26 offices and 27 countries, Harness is shaping the future of AI software delivery - and we're looking for exceptional talent to help us move even faster.

Product Security Engineer
Overview

The Product Security Engineer helps keep Harness software secure across the development lifecycle, with a strong focus on the day-to-day work that keeps product security moving: customer security escalations, incoming security alerts, and vulnerability management from triage through remediation.

This role partners with engineering to find, prioritize, and fix vulnerabilities; run and tune scanners such as Semgrep, Snyk, and Prisma Cloud; and fold security checks into CI/CD so issues are caught before they ship. It also drives internal adoption of Harness security modules (STO, SCS, and related platform capabilities) so we use our own product the way customers should, and so shift-left and software supply-chain practices stick across teams.

Key Responsibilities
  • Own daily product-security operations, triage customer security escalations, investigate security alerts, and drive vulnerability management to closure with clear owners, SLAs, and status.
  • Lead identification, triage, and remediation of vulnerabilities across the Harness platform and modules, partnering with engineering to track progress and unblock fixes.
  • Operate and improve SAST/SCA and cloud/container scanning with tools such as Semgrep, Snyk, and Prisma Cloud (and equivalents), including tuning rules, reducing noise, and keeping reporting consistent.
  • Integrate security controls into CI/CD (Harness, GitHub Actions, or similar) so scans, gates, and supply-chain checks run as part of the pipeline, not as an afterthought.
  • Promote and implement Harness STO and SCS internally: define adoption strategy, land the workflows on real pipelines, and use internal usage as the reference for customer-facing best practice.
  • Support release security advisories by helping produce and review customer-facing vulnerability summaries for product and platform releases.
  • Establish and maintain software supply-chain practices (dependency management, artifact integrity, SLSA-oriented controls) and stay current on emerging supply-chain threats.
  • Plan and support periodic penetration tests with internal teams and external testers; use findings to validate and strengthen controls.
  • Evaluate and recommend security tools to close coverage gaps; automate vulnerability management and reporting so response time and visibility stay high.
  • Partner with incident response on product-related security incidents; support compliance work with audit-ready evidence.
  • Apply the OWASP Top 10 (and API/LLM-adjacent variants where they apply) when triaging findings, reviewing designs, and advising teams on what actually matters versus scanner noise.
  • Enable engineering, platform, and DevOps teams through practical training so security is treated as part of delivery, not a separate queue.
Qualifications
  • Proven experience in product security, vulnerability management, and secure software development lifecycle practices.
  • Hands-on expertise with security tools such as OWASP ZAP, Burp Suite, Snyk, Prisma Cloud, Semgrep, or equivalent.
  • Strong understanding of CI/CD processes, tools (e.g., Jenkins, GitHub Actions, Harness), and shift-left security approaches.
  • Knowledge of secure coding practices, threat modeling methodologies, and supply chain security principles.
  • Working knowledge of the OWASP Top 10 and how to map it to real product issues (injection, broken access control, SSRF, insecure design, etc.), not only the list by name.
  • Familiarity with AI security concerns in both the SDLC (AI-generated code, Copilot/Cursor-style tools) and the product (LLM apps, agents): prompt injection, sensitive-data exposure, insecure plugin/tool use, and basic OWASP LLM Top 10 awareness.
  • Familiarity with different types of security testing (SAST, DAST, IaC, SCA) and proficiency in evaluating scanning tools.
  • Strong collaboration skills with engineering and DevOps
Obtenez votre examen gratuit et confidentiel de votre CV.

ou faites glisser et déposez votre fichier ici.

Similar jobs

Postes similaires à comparer

Product Security Engineer
Product Security Engineer

Harness.io • Bengaluru

Sur place
INR 2 400 000 - 4 200 000
Product Security Engineer
Product Security Engineer

Split Software • Bengaluru

Sur place
INR 3 000 000 - 6 000 000
Product Security Engineer
Product Security Engineer

Armory • Bengaluru

Sur place
INR 1 800 000 - 2 400 000
Senior Security Engineer - Customer Engineering
Senior Security Engineer - Customer Engineering

Harness • Bengaluru

Sur place
INR 2 500 000 - 4 200 000
Security Engineer - Cloud & Infrastructure Security
Security Engineer - Cloud & Infrastructure Security

Armory • Inde

Sur place
INR 1 500 000 - 2 500 000
Security Engineer - Cloud & Infrastructure Security
Security Engineer - Cloud & Infrastructure Security

Split Software • Inde

Sur place
INR 1 800 000 - 3 000 000
Director Software Engineering - AST
Director Software Engineering - AST

Split Software • Bengaluru

Sur place
INR 900 000 - 1 500 000
Staff Security Research Engineer
Staff Security Research Engineer

Armory • Bengaluru

Sur place
INR 4 000 000 - 6 000 000
Senior Security Engineer - Customer Engineering
Senior Security Engineer - Customer Engineering

Armory • Bengaluru

Sur place
INR 4 000 000 - 6 500 000
Senior Security Engineer - Customer Engineering
Senior Security Engineer - Customer Engineering

Harness Inc • Inde

Sur place
INR 3 000 000 - 5 200 000