801,878open jobs
51,353companies
126,239added this week
Browse all
Location
In office (Bengaluru)

Confirmed on the employer's own hiring board on Sep 26, 2026. First seen by Alion on Sep 25, 2026. Harness scores A on the Alion truth index.

Overview
Company
Impact
Profile match
Harness is a unified, end-to-end AI software delivery platform to manage the SDLC using purpose-built AI agents.

Harness is the AI Software Delivery Platform company, led by technologist and entrepreneur Jyoti Bansal (founder of AppDynamics, acquired by Cisco for $3.7B). Harness has raised approximately $570M in funding and is valued at $5.5B, backed by leading investors including Goldman Sachs, Menlo Ventures, IVP, Unusual Ventures, Citi Ventures, and more. As AI accelerates code creation, the real bottleneck has shifted to everything after the code - testing, deployments, application security, reliability, compliance, and cost optimization. Harness brings AI and automation to this “outer loop,” helping teams ship software faster while maintaining security and governance throughout the entire software delivery lifecycle.

Powered by Harness AI and the Software Delivery Knowledge Graph, the Harness Platform applies deep context and intelligent automation across the software delivery lifecycle with governance and policy-driven controls embedded throughout the platform. 

Over the past year, Harness powered over 185M deployments, 82M builds, 18T flag evaluations, 8M security scans, 9.1B optimized tests, 3T protected API calls, and helped manage $2.8B in cloud spend - enabling customers like United Airlines, Morningstar, and Choice Hotels to accelerate releases by up to 75%, reduce cloud costs by up to 60%, and achieve 10x DevOps efficiency. 

With a global team across 26 offices and 27 countries, Harness is shaping the future of AI software delivery - and we’re looking for exceptional talent to help us move even faster.

Product Security Engineer

Overview:

The Product Security Engineer helps keep Harness software secure across the development lifecycle, with a strong focus on the day-to-day work that keeps product security moving: customer security escalations, incoming security alerts, and vulnerability management from triage through remediation.

This role partners with engineering to find, prioritize, and fix vulnerabilities; run and tune scanners such as Semgrep, Snyk, and Prisma Cloud; and fold security checks into CI/CD so issues are caught before they ship. It also drives internal adoption of Harness security modules (STO, SCS, and related platform capabilities) so we use our own product the way customers should, and so shift-left and software supply-chain practices stick across teams.

Key Responsibilities

  • Own daily product-security operations, triage customer security escalations, investigate security alerts, and drive vulnerability management to closure with clear owners, SLAs, and status.
  • Lead identification, triage, and remediation of vulnerabilities across the Harness platform and modules, partnering with engineering to track progress and unblock fixes.
  • Operate and improve SAST/SCA and cloud/container scanning with tools such as Semgrep, Snyk, and Prisma Cloud (and equivalents), including tuning rules, reducing noise, and keeping reporting consistent.
  • Integrate security controls into CI/CD (Harness, GitHub Actions, or similar) so scans, gates, and supply-chain checks run as part of the pipeline, not as an afterthought.
  • Promote and implement Harness STO and SCS internally: define adoption strategy, land the workflows on real pipelines, and use internal usage as the reference for customer-facing best practice.
  • Support release security advisories by helping produce and review customer-facing vulnerability summaries for product and platform releases.
  • Establish and maintain software supply-chain practices (dependency management, artifact integrity, SLSA-oriented controls) and stay current on emerging supply-chain threats.
  • Plan and support periodic penetration tests with internal teams and external testers; use findings to validate and strengthen controls.
  • Evaluate and recommend security tools to close coverage gaps; automate vulnerability management and reporting so response time and visibility stay high.
  • Partner with incident response on product-related security incidents; support compliance work with audit-ready evidence.
  • Apply the OWASP Top 10 (and API/LLM-adjacent variants where they apply) when triaging findings, reviewing designs, and advising teams on what actually matters versus scanner noise.
  • Enable engineering, platform, and DevOps teams through practical training so security is treated as part of delivery, not a separate queue.

Qualifications

  • Proven experience in product security, vulnerability management, and secure software development lifecycle practices.
  • Hands-on expertise with security tools such as OWASP ZAP, Burp Suite, Snyk, Prisma Cloud, Semgrep, or equivalent.
  • Strong understanding of CI/CD processes, tools (e.g., Jenkins, GitHub Actions, Harness), and shift-left security approaches.
  • Knowledge of secure coding practices, threat modeling methodologies, and supply chain security principles.
  • Working knowledge of the OWASP Top 10 and how to map it to real product issues (injection, broken access control, SSRF, insecure design, etc.), not only the list by name.
  • Familiarity with AI security concerns in both the SDLC (AI-generated code, Copilot/Cursor-style tools) and the product (LLM apps, agents): prompt injection, sensitive-data exposure, insecure plugin/tool use, and basic OWASP LLM Top 10 awareness.
  • Familiarity with different types of security testing (SAST, DAST, IaC, SCA) and proficiency in evaluating scanning tools.
  • Strong collaboration skills with engineering and DevOps teams to embed security practices effectively.
  • Passion for fostering a security-first culture through enablement, training, and continuous improvement.
  • Excellent communication skills to convey technical security concepts to diverse stakeholders.
  • Working knowledge of cloud environments (AWS, GCP, or Azure) and securing containerized applications (Docker, Kubernetes).
  • Experience scripting or automating security workflows using Python, Go, or similar languages.

Harness in the news:

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex or national origin.

At Harness, we care about your privacy and are committed to protecting your personal data. For additional information on this topic, you can visit our privacy Portal: https://harness-privacy.relyance.ai/

Note on Fraudulent Recruiting/Offers

We have become aware that there may be fraudulent recruiting attempts being made by people posing as representatives of Harness. These scams may involve fake job postings, unsolicited emails, or messages claiming to be from our recruiters or hiring managers. 

Please note, we do not ask for sensitive or financial information via chat, text, or social media, and any email communications will come from the domain @harness.io. Additionally, Harness will never ask for any payment, fee to be paid, or purchases to be made by a job applicant. All applicants are encouraged to apply directly to our open jobs via our website. Interviews are generally conducted via Zoom video conference unless the candidate requests other accommodations.

If you believe that you have been the target of an interview/offer scam by someone posing as a representative of Harness, please do not provide any personal or financial information and contact us immediately at  [email protected]. You can also find additional information about this type of scam and report any fraudulent employment offers via the Federal Trade Commission’s website (https://consumer.ftc.gov/articles/job-scams), or you can contact your local law enforcement agency.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
801,878 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
Bengaluru
≈ $35k – $78k per year (Estimated) • In office • 8+ years exp • Bengaluru
DevOps
Platform Engineering
Cybersecurity
SIEM
Apply
≈ $28k – $63k per year (Estimated) • In office • 7+ years exp • Bachelor's Degree • Hyderabad
AI/ML
Red Teaming
Management
Gmail
Apply
≈ $34k – $87k per year (Estimated) • In office • Full-Time • 5+ years exp • Bengaluru
DevOps
GitLab
IAM
Cybersecurity
Qualys Cloud Platform
EPSS
KEV
PKI
DLP
Apply
≈ $34k – $76k per year (Estimated) • In office • 5+ years exp • Bachelor's Degree • Bengaluru
Python
Java
C#
C++
AI/ML
AI Agents
Red Teaming
LLM Guardrails
DevOps
Terraform
Ansible
GCP
CloudFormation
Azure
CI/CD
Jenkins
AWS
GitHub
Linux
Cybersecurity
HashiCorp Vault
ISO 27001
OWASP Top 10
Threat Modeling
SBOM
Delinea
OWASP
Cryptography
Vault
Apply
≈ $34k – $76k per year (Estimated) • In office • 5+ years exp • Bachelor's Degree • Bengaluru
Python
DevOps
Linux
Windows
Cybersecurity
ISO 27001
NIST CSF
SOC 2
Apply
Cloud Engineer 1 day ago
In office • Full-Time • Bachelor's Degree • Kuala Lumpur
Python
PowerShell
AI/ML
Machine Learning
DevOps
Terraform
GCP
CloudFormation
Azure
AWS
Apply
≈ $34k – $82k per year (Estimated) • In office • Bengaluru
Python
TypeScript
SQL
AI/ML
Function Calling
Speech Recognition
LLM
RAG
Text-to-Speech
LLM Guardrails
DevOps
GCP
AWS
Apply
Data Scientist 1 day ago
$85k – $125k per year • Equity • In office • Full-Time • 2+ years exp • Bachelor's Degree • Milpitas • Ann Arbor
Python
SQL
AI/ML
Machine Learning
Apply
Remote (India) • Full-Time • Noida
Python
Java
PowerShell
Bash
Java
Apache Tomcat
DevOps
Splunk
Ansible
OpenShift
Azure DevOps
GitHub Actions
VMWare
Dynatrace
Prometheus
Azure
CI/CD
Windows Server
Jenkins
Git
Docker
Kubernetes
Apache HTTP Server
Grafana
Platform Engineering
Configuration Management
Self-Healing
AppDynamics
GitHub
Linux
Windows
DNS
Apply
Security Engineer 1 day ago
≈ $52k – $118k per year (Estimated) • In office • Full-Time • 5+ years exp • Barcelona
Python
PowerShell
DevOps
Splunk
Azure
AWS
Cybersecurity
SIEM
DLP
Apply
≈ $32k – $77k per year (Estimated) • Remote (India) • 3+ years exp
Python
AI/ML
Knowledge Graph
DevOps
Terraform
GCP
AWS
Kubernetes
AppDynamics
IAM
Cybersecurity
ISO 27001
PCI DSS
SOC 2
Apply
≈ $42k – $95k per year (Estimated) • In office • 4+ years exp • Bengaluru
Python
AI/ML
AI Agents
LLM
Knowledge Graph
Red Teaming
Frontend
GraphQL
DevOps
Rest API
gRPC
Cloudflare
AppDynamics
Akamai
Cybersecurity
Burp Suite
OWASP ZAP
ModSecurity
OWASP Top 10
OWASP
QA
Postman
Apply
≈ $56k – $139k per year (Estimated) • In office • 15+ years exp • Bachelor's Degree • Bengaluru
AI/ML
AI Agents
Knowledge Graph
DevOps
Platform Engineering
AppDynamics
Apply
$150k – $164k per year • Remote (United States) • 8+ years exp
AI/ML
Knowledge Graph
DevOps
GCP
Azure
CI/CD
AWS
Kubernetes
AppDynamics
Cybersecurity
ISO 27001
PCI DSS
SOC 2
HIPAA
NIST 800-53
FedRAMP
SLSA
DLP
Apply
Payroll Specialist 1 day ago
≈ $19k – $54k per year (Estimated) • Hybrid • 3+ years exp • Bachelor's Degree • Bengaluru
AI/ML
Knowledge Graph
DevOps
AppDynamics
Analytics
Microsoft Excel
Management
Microsoft Office
Apply
≈ $23k – $56k per year (Estimated) • In office • Full-Time • 3+ years exp • Bengaluru
Python
Cybersecurity
CVE
Apply
$15k – $35k per year • In office • Full-Time • 3+ years exp • Bengaluru
Python
Cybersecurity
MITRE ATT&CK
Management
Telegram
Apply
AI SOC Lead 10 hours ago
$18k – $25k per year • In office • Full-Time • 6+ years exp • Bengaluru
Python
PowerShell
AI/ML
Anomaly Detection
Red Teaming
DevOps
Splunk
GCP
Azure
AWS
SLI/SLO/SLA
Cybersecurity
Microsoft Sentinel
ISO 27001
MITRE ATT&CK
NIST CSF
PCI DSS
SOC 2
Cyber Kill Chain
Diamond Model
IBM QRadar
Cortex XSOAR
SIEM
Apply
$26k – $52k per year • Equity 0–0.1% • In office • Full-Time • 3+ years exp • Bengaluru
Python
JavaScript
SQL
Node JS
Databases
DynamoDB
AI/ML
Cursor
LangChain
Claude Code
Embeddings
Prompt Engineering
RAG
OpenAI
Hugging Face
Machine Learning
DevOps
AWS
AWS Lambda
Amazon EC2
IAM
Amazon ECS
Apply
≈ $34k – $82k per year (Estimated) • In office • Bengaluru
Python
TypeScript
SQL
AI/ML
Function Calling
Speech Recognition
LLM
RAG
Text-to-Speech
LLM Guardrails
DevOps
GCP
AWS
Apply
See all jobs
This is one of many
801,878 more open roles from verified company boards, updated every day.