drjobs Senior Product Security Engineer

Senior Product Security Engineer

Employer Active

1 Vacancy
drjobs

Job Alert

You will be updated with latest job alerts via email
Valid email field required
Send jobs
Send me jobs like this
drjobs

Job Alert

You will be updated with latest job alerts via email

Valid email field required
Send jobs
Job Location drjobs

Bengaluru - India

Monthly Salary drjobs

Not Disclosed

drjobs

Salary Not Disclosed

Vacancy

1 Vacancy

Job Description

Harness is a highgrowth company that is disrupting the software delivery market. Our mission is to enable the 30 million software developers in the world to deliver code to their users reliably efficiently securely and quickly increasing customers pace of innovation while improving the developer experience. We offer solutions for every step of the software delivery lifecycle to build test secure deploy and manage reliability feature flags and cloud costs. The Harness Software Delivery Platform includes modules for CI CD Cloud Cost Management Feature Flags Service Reliability Management Security Testing Orchestration Chaos Engineering Software Engineering Insights and continues to expand at an incredibly fast pace.
Harness is led by technologist and entrepreneur Jyoti Bansal who founded AppDynamics and sold it to Cisco for $3.7B. Were backed with $425M in venture financing from toptier VC and strategic firms including J.P. Morgan Capital One Ventures Citi Ventures ServiceNow Splunk Ventures Norwest Venture Partners Adage Capital Partners Balyasny Asset Management Gaingels Harmonic Growth Partners Menlo Ventures IVP Unusual Ventures GV (formerly Google Ventures) Alkeon Capital Battery Ventures Sorenson Capital Thomvest Ventures and Silicon Valley Bank.

Overview:

The Senior Product Security Engineer will lead efforts to secure the Harness software by embedding security into every stage of the development lifecycle. This role involves vulnerability management internal adoption of cuttingedge security solutions and enabling teams to shift left on security while safeguarding the software supply chain.

Key Responsibilities

  • Lead identification triage and remediation of vulnerabilities across the Harness platform and modules partnering with engineering teams to establish SLAs and track progress.
  • Collaborate with engineers to perform threat modeling for new and existing features identifying risks early and providing actionable recommendations.
  • Promote and implement Harness STO and SCS modules internally to demonstrate security best practices and drive adoption.
  • Develop and integrate security controls and checks into CI/CD workflows to detect issues before deployment.
  • Establish robust processes for software supply chain security including dependency management and artifact integrity verification using SLSA
  • Stay updated on emerging threats targeting software supply chains and adjust strategies proactively.
  • Plan and execute periodic penetration tests to uncover vulnerabilities and validate security controls working with internal teams and external testers.
  • Leverage expertise in security scanners and tools (e.g. SAST DAST IAST SCA) to ensure consistent testing and reporting.
  • Evaluate and recommend security tools to align with organizational needs and improve testing coverage.
  • Partner with engineering platform and DevOps teams to foster a securityfirst mindset through training and enablement.
  • Support compliance initiatives by aligning product security practices with regulatory standards and maintaining audit documentation.

Qualifications

  • Proven experience in product security vulnerability management and secure software development lifecycle practices.
  • Handson expertise with security tools such as OWASP ZAP Burp Suite Checkmarx SonarQube or equivalent.
  • Strong understanding of CI/CD processes tools (e.g. Jenkins GitHub Actions Harness) and shiftleft security approaches.
  • Knowledge of secure coding practices threat modeling methodologies and supply chain security principles.
  • Familiarity with different types of security testing SAST DAST IaC SCA) and proficiency in evaluating scanning tools.
  • Strong collaboration skills with engineering and DevOps teams to embed security practices effectively.
  • Passion for fostering a securityfirst culture through enablement training and continuous improvement.
  • Excellent communication skills to convey technical security concepts to diverse stakeholders.

Harness in the news:

All qualified applicants will receive consideration for employment without regard to race color religion sex or national origin.

Note on Fraudulent Recruiting/Offers

We have become aware that there may be fraudulent recruiting attempts being made by people posing as representatives of Harness. These scams may involve fake job postings unsolicited emails or messages claiming to be from our recruiters or hiring managers.

Please note we do not ask for sensitive or financial information via chat text or social media and any email communications will come from the domain @harness. Additionally Harness will never ask for any payment fee to be paid or purchases to be made by a job applicant. All applicants are encouraged to apply directly to our open jobs via our website. Interviews are generally conducted via Zoom video conference unless the candidate requests other accommodations.

If you believe that you have been the target of an interview/offer scam by someone posing as a representative of Harness please do not provide any personal or financial information and contact us immediately at. You can also find additional information about this type of scam and report any fraudulent employment offers via the Federal Trade Commissions website or you can contact your local law enforcement agency.


Required Experience:

Senior IC

Employment Type

Full Time

About Company

Report This Job
Disclaimer: Drjobpro.com is only a platform that connects job seekers and employers. Applicants are advised to conduct their own independent research into the credentials of the prospective employer.We always make certain that our clients do not endorse any request for money payments, thus we advise against sharing any personal or bank-related information with any third party. If you suspect fraud or malpractice, please contact us via contact us page.