{"id":1215030,"url":"https://alion.io/job/harness-product-security-engineer","title":"Product Security Engineer","company":{"id":7218,"name":"Harness","domain":"harness.io","url":"https://alion.io/company/harness","size_band":"1001-5000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Greenhouse","truth_index":{"grade":"A","score":94,"open_postings":45,"ghost_share":0,"stale_share":0.044,"repost_share":0,"time_to_fill_p50_days":144,"computed_at":"2026-09-29T05:45:00Z"}},"role":"Security","role_family":"Security","seniority":null,"employment_type":null,"work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Bengaluru, India"],"countries":["IN"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":25000,"max_usd":67000,"period":"year","method":"role_country_seniority_unknown","sample_n":34},"experience_years_min":null,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AppDynamics","optional":false},{"name":"AWS","optional":false},{"name":"Azure","optional":false},{"name":"Burp Suite","optional":false},{"name":"CI/CD","optional":false},{"name":"Copilot","optional":false},{"name":"Cursor","optional":false},{"name":"Docker","optional":false},{"name":"Function Calling","optional":false},{"name":"GCP","optional":false},{"name":"GitHub Actions","optional":false},{"name":"Jenkins","optional":false},{"name":"Knowledge Graph","optional":false},{"name":"Kubernetes","optional":false},{"name":"LLM","optional":false},{"name":"OWASP","optional":false},{"name":"OWASP Top 10","optional":false},{"name":"OWASP ZAP","optional":false},{"name":"Prisma Cloud","optional":false},{"name":"Python","optional":false},{"name":"Semgrep","optional":false},{"name":"Shift-Left","optional":false},{"name":"Shift-Left Security","optional":false},{"name":"SLSA","optional":false},{"name":"Snyk","optional":false},{"name":"Threat Modeling","optional":false},{"name":"Tool Use","optional":false}],"status":"live","first_seen_at":"2026-09-25T07:02:45Z","employer_posted_date":"2026-09-28","last_verified_at":"2026-09-29T20:57:14Z","board_verified":true,"closed_at":null,"days_open":4,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":4},"description":"Harness is the AI Software Delivery Platform company, led by technologist and entrepreneur Jyoti Bansal (founder of AppDynamics, acquired by Cisco for $3.7B). Harness has raised approximately $570M in funding and is valued at $5.5B, backed by leading investors including Goldman Sachs, Menlo Ventures, IVP, Unusual Ventures, Citi Ventures, and more. As AI accelerates code creation, the real bottleneck has shifted to everything after the code - testing, deployments, application security, reliability, compliance, and cost optimization. Harness brings AI and automation to this “outer loop,” helping teams ship software faster while maintaining security and governance throughout the entire software delivery lifecycle.\nPowered by Harness AI and the Software Delivery Knowledge Graph, the Harness Platform applies deep context and intelligent automation across the software delivery lifecycle with governance and policy-driven controls embedded throughout the platform. \nOver the past year, Harness powered over 185M deployments, 82M builds, 18T flag evaluations, 8M security scans, 9.1B optimized tests, 3T protected API calls, and helped manage $2.8B in cloud spend - enabling customers like United Airlines, Morningstar, and Choice Hotels to accelerate releases by up to 75%, reduce cloud costs by up to 60%, and achieve 10x DevOps efficiency. \nWith a global team across 26 offices and 27 countries, Harness is shaping the future of AI software delivery - and we’re looking for exceptional talent to help us move even faster.\nProduct Security Engineer\nOverview:\nThe Product Security Engineer helps keep Harness software secure across the development lifecycle, with a strong focus on the day-to-day work that keeps product security moving: customer security escalations, incoming security alerts, and vulnerability management from triage through remediation.\nThis role partners with engineering to find, prioritize, and fix vulnerabilities; run and tune scanners such as Semgrep, Snyk, and Prisma Cloud; and fold security checks into CI/CD so issues are caught before they ship. It also drives internal adoption of Harness security modules (STO, SCS, and related platform capabilities) so we use our own product the way customers should, and so shift-left and software supply-chain practices stick across teams.\nKey Responsibilities\nOwn daily product-security operations, triage customer security escalations, investigate security alerts, and drive vulnerability management to closure with clear owners, SLAs, and status.\nLead identification, triage, and remediation of vulnerabilities across the Harness platform and modules, partnering with engineering to track progress and unblock fixes.\nOperate and improve SAST/SCA and cloud/container scanning with tools such as Semgrep, Snyk, and Prisma Cloud (and equivalents), including tuning rules, reducing noise, and keeping reporting consistent.\nIntegrate security controls into CI/CD (Harness, GitHub Actions, or similar) so scans, gates, and supply-chain checks run as part of the pipeline, not as an afterthought.\nPromote and implement Harness STO and SCS internally: define adoption strategy, land the workflows on real pipelines, and use internal usage as the reference for customer-facing best practice.\nSupport release security advisories by helping produce and review customer-facing vulnerability summaries for product and platform releases.\nEstablish and maintain software supply-chain practices (dependency management, artifact integrity, SLSA-oriented controls) and stay current on emerging supply-chain threats.\nPlan and support periodic penetration tests with internal teams and external testers; use findings to validate and strengthen controls.\nEvaluate and recommend security tools to close coverage gaps; automate vulnerability management and reporting so response time and visibility stay high.\nPartner with incident response on product-related security incidents; support compliance work with audit-ready evidence.\nApply the OWASP Top 10 (and API/LLM-adjacent variants where they apply) when triaging findings, reviewing designs, and advising teams on what actually matters versus scanner noise.\nEnable engineering, platform, and DevOps teams through practical training so security is treated as part of delivery, not a separate queue.\nQualifications\nProven experience in product security, vulnerability management, and secure software development lifecycle practices.\nHands-on expertise with security tools such as OWASP ZAP, Burp Suite, Snyk, Prisma Cloud, Semgrep, or equivalent.\nStrong understanding of CI/CD processes, tools (e.g., Jenkins, GitHub Actions, Harness), and shift-left security approaches.\nKnowledge of secure coding practices, threat modeling methodologies, and supply chain security principles.\nWorking knowledge of the OWASP Top 10 and how to map it to real product issues (injection, broken access control, SSRF, insecure design, etc.), not only the list by name.\nFamiliarity with AI security concerns in both the SDLC (AI-generated code, Copilot/Cursor-style tools) and the product (LLM apps, agents): prompt injection, sensitive-data exposure, insecure plugin/tool use, and basic OWASP LLM Top 10 awareness.\nFamiliarity with different types of security testing (SAST, DAST, IaC, SCA) and proficiency in evaluating scanning tools.\nStrong collaboration skills with engineering and DevOps teams to embed security practices effectively.\nPassion for fostering a security-first culture through enablement, training, and continuous improvement.\nExcellent communication skills to convey technical security concepts to diverse stakeholders.\nWorking knowledge of cloud environments (AWS, GCP, or Azure) and securing containerized applications (Docker, Kubernetes).\nExperience scripting or automating security workflows using Python, Go, or similar languages.\nHarness in the news:\nAccelerating Our Mission to Bring AI to Everything After Code\nGoldman Sachs leads investment in software delivery startup Harness at $5.5 billion valuation\nHow Harness runs 16 “startups within a startup” at scale | Jyoti Bansal\nHarness Research Shows AI Visibility Crisis Fueling Security Nightmare\nHarness has been named to the Inc. Power Partner list for software delivery success\nAll qualified applicants will receive consideration for employment without regard to race, color, religion, sex or national origin.\nAt Harness, we care about your privacy and are committed to protecting your personal data. For additional information on this topic, you can visit our privacy Portal: https://harness-privacy.relyance.ai/\nNote on Fraudulent Recruiting/Offers\nWe have become aware that there may be fraudulent recruiting attempts being made by people posing as representatives of Harness. These scams may involve fake job postings, unsolicited emails, or messages claiming to be from our recruiters or hiring managers. \nPlease note, we do not ask for sensitive or financial information via chat, text, or social media, and any email communications will come from the domain @harness.io. Additionally, Harness will never ask for any payment, fee to be paid, or purchases to be made by a job applicant. All applicants are encouraged to apply directly to our open jobs via our website. Interviews are generally conducted via Zoom video conference unless the candidate requests other accommodations.\nIf you believe that you have been the target of an interview/offer scam by someone posing as a representative of Harness, please do not provide any personal or financial information and contact us immediately at . You can also find additional information about this type of scam and report any fraudulent employment offers via the Federal Trade Commission’s website (https://consumer.ftc.gov/articles/job-scams), or you can contact your local law enforcement agency.","description_format":"text","description_chars":7843,"description_truncated":false,"requirements":{"experience_years_min":null,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Artificial Intelligence","Sales & Marketing","Software","Code Intelligence"],"lifecycle":[{"event":"open","at":"2026-09-25T07:53:15Z"},{"event":"close","at":"2026-09-28T07:06:12Z"},{"event":"reopen","at":"2026-09-28T11:23:59Z"}],"liveness":{"score":99,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.993,"p_room":1,"age_days":3,"expected_fill_days":144,"reasons":["conf:3","urgency","velocity","win:early"],"computed_at":"2026-09-29T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/harness-product-security-engineer","json_url":"https://alion.io/job/harness-product-security-engineer.json","meta":{"generated_at":"2026-09-30T03:10:24Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"search","counted_by":"address","units_charged":0,"used_today":0,"day_limit":null,"remaining_today":null,"minute_limit":null,"resets_at":"2026-10-01T00:00:00Z"}}}