Product Security Engineer

Harness
Bengaluru
Workplace: OnsiteFull timeFunction: CybersecuritySkills: ["Collaboration","Communication"]

Own day-to-day product security operations for the Harness platform, triaging customer security escalations and managing vulnerabilities from triage through remediation. Lead SAST/SCA and cloud/container scanning using tools like Semgrep, Snyk, and Prisma Cloud, and embed security controls into CI/CD pipelines (Harness, GitHub Actions, and similar) to catch issues before release. Drive internal adoption of security modules, support advisories, supply-chain practices, and pen tests.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Harness
Harness
12 hours ago

Product Security Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 9 hours agoStatus: Live

Job Summary

Own day-to-day product security operations for the Harness platform, triaging customer security escalations and managing vulnerabilities from triage through remediation. Lead SAST/SCA and cloud/container scanning using tools like Semgrep, Snyk, and Prisma Cloud, and embed security controls into CI/CD pipelines (Harness, GitHub Actions, and similar) to catch issues before release. Drive internal adoption of security modules, support advisories, supply-chain practices, and pen tests.
Location: Bengaluru
Workplace: Onsite
Employment Type: Full time
Job Function: Cybersecurity

Key Responsibilities

  • •Own daily product-security operations, triage customer security escalations, investigate alerts, and drive vulnerability management to closure with clear owners, SLAs, and status.
  • •Lead identification, triage, and remediation of vulnerabilities across the Harness platform and modules in partnership with engineering.
  • •Operate and improve SAST/SCA and cloud/container scanning using Semgrep, Snyk, Prisma Cloud (and equivalents), including tuning rules and reducing noise.
  • •Integrate security controls into CI/CD pipelines (Harness, GitHub Actions, or similar) so scans, gates, and supply-chain checks run during delivery.
  • •Promote internal adoption of Harness STO and SCS, support release security advisories, and help establish software supply-chain practices (dependency management, artifact integrity, SLSA-oriented controls).

Key Requirements

  • •Proven experience in product security, vulnerability management, and secure SDLC practices.
  • •Hands-on expertise with tools such as OWASP ZAP, Burp Suite, Snyk, Prisma Cloud, and Semgrep (or equivalents).
  • •Strong understanding of CI/CD and shift-left security approaches, including tools like Jenkins, GitHub Actions, and Harness.
  • •Knowledge of secure coding, threat modeling, and software supply-chain security principles.
  • •Working knowledge of OWASP Top 10 and the ability to map it to real product issues and security findings.
Skills:CollaborationCommunication
Languages:En
Tech Stack:SemgrepSnykPrisma CloudOWASP ZAPBurp SuiteGitHub ActionsJenkinsHarnessCI/CDOWASP Top 10AWSGCPAzureDockerKubernetesPythonGoSASTSCADAST

Company Brief

Harness
Provides a continuous delivery and software delivery platform that automates deployment, feature releases, rollbacks, and cloud cost optimization using machine learning to help engineering teams deliver changes quickly and safely.
Industry: Developer Tools
Company Size: Enterprise (1,001+ employees)
Growth: Scaleup
Valuation: Unicorn (USD 1B+)
Funding: Series D
Headquarters: San Francisco, United States
Founded: 2016
WebsiteLinkedIn