Product Security Engineer

Harness.io

Bengaluru

On-site

INR 2,400,000 - 4,200,000

Full time

13 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Harness.io seeks a Product Security Engineer to safeguard our software across the development lifecycle. You’ll handle customer escalations, alerts, and vulnerability management end-to-end, partnering with engineering to fix issues and strengthen controls.

You will tune scanners, embed security in CI/CD, and champion secure supply-chain practices, while enabling teams through practical training and adoption of our security modules.

Qualifications

  • Proven experience in product security and vulnerability management.
  • Hands-on with security tools like ZAP, Burp, Snyk, Prisma Cloud, Semgrep.
  • Strong understanding of CI/CD and shift-left security approaches.
  • Knowledge of secure coding practices, threat modeling, and supply chain security.
  • Familiarity with OWASP Top 10 and LLM/AI security concerns is a plus.
  • Excellent collaboration with engineering and DevOps to embed security.
  • Willingness to enable teams and train others on secure delivery.

Responsibilities

  • Own daily product-security operations, triage escalations, and drive vulnerability management.
  • Lead identification, triage, and remediation of vulnerabilities across Harness platform.
  • Operate and improve SAST/SCA and cloud/container scanning with major tools.
  • Integrate security controls into CI/CD pipelines and gate checks.
  • Promote internal adoption of security modules and secure supply-chain practices.
  • Support release advisories with customer-facing vulnerability summaries.
  • Plan penetration tests and validate improvements from findings.
  • Evaluate security tools and automate vulnerability reporting.

Skills

Product security
Vulnerability management
CI/CD security
Threat modeling
Secure coding
Scripting (Python/Go)
Collaboration with engineering

Tools

OWASP ZAP
Burp Suite
Snyk
Prisma Cloud
Semgrep
Jenkins
GitHub Actions
Harness

Job description

Job Summary

The Product Security Engineer helps keep Harness software secure across the development lifecycle, with a strong focus on the day-to-day work that keeps product security moving: customer security escalations, incoming security alerts, and vulnerability management from triage through remediation.

This role partners with engineering to find, prioritize, and fix vulnerabilities; run and tune scanners such as Semgrep, Snyk, and Prisma Cloud; and fold security checks into CI/CD so issues are caught before they ship. It also drives internal adoption of Harness security modules (STO, SCS, and related platform capabilities) so we use our own product the way customers should, and so shift-left and software supply-chain practices stick across teams.

Responsibilities
  • Own daily product-security operations, triage customer security escalations, investigate security alerts, and drive vulnerability management to closure with clear owners, SLAs, and status.
  • Lead identification, triage, and remediation of vulnerabilities across the Harness platform and modules, partnering with engineering to track progress and unblock fixes.
  • Operate and improve SAST/SCA and cloud/container scanning with tools such as Semgrep, Snyk, and Prisma Cloud (and equivalents), including tuning rules, reducing noise, and keeping reporting consistent.
  • Integrate security controls into CI/CD (Harness, GitHub Actions, or similar) so scans, gates, and supply-chain checks run as part of the pipeline, not as an afterthought.
  • Promote and implement Harness STO and SCS internally: define adoption strategy, land the workflows on real pipelines, and use internal usage as the reference for customer-facing best practice.
  • Support release security advisories by helping produce and review customer-facing vulnerability summaries for product and platform releases.
  • Establish and maintain software supply-chain practices (dependency management, artifact integrity, SLSA-oriented controls) and stay current on emerging supply-chain threats.
  • Plan and support periodic penetration tests with internal teams and external testers; use findings to validate and strengthen controls.
  • Evaluate and recommend security tools to close coverage gaps; automate vulnerability management and reporting so response time and visibility stay high.
  • Partner with incident response on product-related security incidents; support compliance work with audit-ready evidence.
  • Apply the OWASP Top 10 (and API/LLM-adjacent variants where they apply) when triaging findings, reviewing designs, and advising teams on what actually matters versus scanner noise.
  • Enable engineering, platform, and DevOps teams through practical training so security is treated as part of delivery, not a separate queue.
Qualifications
  • Proven experience in product security, vulnerability management, and secure software development lifecycle practices.
  • Hands‑on expertise with security tools such as OWASP ZAP, Burp Suite, Snyk, Prisma Cloud, Semgrep, or equivalent.
  • Strong understanding of CI/CD processes, tools (e.g., Jenkins, GitHub Actions, Harness), and shift-left security approaches.
  • Knowledge of secure coding practices, threat modeling methodologies, and supply chain security principles.
  • Working knowledge of the OWASP Top 10 and how to map it to real product issues (injection, broken access control, SSRF, insecure design, etc.), not only the list by name.
  • Familiarity with AI security concerns in both the SDLC (AI-generated code, Copilot/Cursor-style tools) and the product (LLM apps, agents): prompt injection, sensitive-data exposure, insecure plugin/tool use, and basic OWASP LLM Top 10 awareness.
  • Familiarity with different types of security testing (SAST, DAST, IaC, SCA) and proficiency in evaluating scanning tools.
  • Strong collaboration skills with engineering and DevOps teams to embed security practices effectively.
  • Passion for fostering a security‑first culture through enablement, training, and continuous improvement.
  • Excellent communication skills to convey technical security concepts to diverse stakeholders.
  • Working knowledge of cloud environments (AWS, GCP, or Azure) and securing containerized applications (Docker, Kubernetes).
  • Experience scripting or automating security workflows using Python, Go, or similar languages.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Product Security Engineer
Product Security Engineer

Harness • Bengaluru

On-site
INR 3,500,000 - 6,000,000
Product Security Engineer
Product Security Engineer

Armory • Bengaluru

On-site
INR 1,800,000 - 2,400,000
Product Security Engineer
Product Security Engineer

Split Software • Bengaluru

On-site
INR 3,000,000 - 6,000,000
Senior Product Security Engineer
Senior Product Security Engineer

Pocket FM Corp. • Bengaluru

On-site
INR 2,000,000 - 3,200,000
Product Security Engineer (Devsec Ops)
Product Security Engineer (Devsec Ops)

Lenskart • Gurugram District

On-site
INR 1,500,000 - 2,300,000
Product Security Engineer
Product Security Engineer

HBK - Hottinger Brüel & Kjær • Chennai District

On-site
INR 1,200,000 - 1,800,000
Security Engineer - Cloud & Infrastructure Security
Security Engineer - Cloud & Infrastructure Security

Armory • India

On-site
INR 1,500,000 - 2,500,000
Security Engineer - Cloud & Infrastructure Security
Security Engineer - Cloud & Infrastructure Security

Split Software • India

On-site
INR 1,800,000 - 3,000,000
Senior Product Security Engineer
Senior Product Security Engineer

Dun & Bradstreet • Hyderabad

On-site
INR 4,000,000 - 7,000,000
Senior Security Engineer - Customer Engineering
Senior Security Engineer - Customer Engineering

Split Software • Bengaluru

On-site
INR 13,397,000 - 18,182,000