Harness

Staff Product Security Engineer

Harness$180K — $200K *
US-AnywhereRemote in United States
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • BS in Computer Science or related degree.
  • 5+ years of relevant industry experience focused on security.
  • Experience with DevSecOps and secure SDLC practices.
  • Knowledge of security frameworks: OWASP, SANS, NIST, CIS.
  • Ability to articulate software supply chain risks.
  • Familiarity with cloud environments like K8s, AWS, GCP, or Azure.
  • Proficiency in Java or similar object-oriented programming languages.

Responsibilities

  • Design and develop product security APIs and tools for stakeholders.
  • Conduct threat modeling and secure design reviews for application services.
  • Perform penetration tests and adversarial simulations on the platform and APIs.
  • Lead manual and automated code reviews for vulnerabilities and weaknesses.
  • Implement security tools into CI/CD pipelines.
  • Consult with developers on security standards and architecture.
  • Assess risks and propose solutions for product security features.
  • Collaborate with cross-functional teams to ensure security in software releases.

Benefits

  • Opportunity to influence engineering culture and security posture.
  • Significant autonomy in decision-making and program definition.
  • Participation in complex cross-team initiatives.
  • Access to collaboration with global engineering teams.
  • Engagement in cutting-edge security practices and technologies.
Full Job Description
About the Role

Product Security is responsible for ensuring the continuous security of Harness customer-facing products and internal tools. The team is focused on proactively discovering security weaknesses, driving and advising risk remediation, building a paved road for developers to adopt secure development practices, and developing partnerships with engineering and product teams to accelerate the release of software with security by design.

The Staff Product Security Engineer is a senior individual contributor who sets the technical direction for Harness's product security posture. You will define programs, lead complex cross-team initiatives, and make foundational decisions that protect our platform and customers at scale. You operate with significant autonomy, are expected to influence engineering culture, and are the go-to authority on security architecture and strategy.

What You Will Do
  • Design and develop product security APIs, tools, and utilities for internal and external stakeholders.
  • Conduct threat modeling and secure design reviews for application backend services and business integrations.
  • Perform advanced penetration tests and adversarial attack simulations against Harness modules, APIs, and codebase using industry-standard frameworks.
  • Lead manual and automated code review efforts to discover vulnerabilities, weaknesses, and anti-patterns in the Harness platform.
  • Implement and operate security tooling including SAST, DAST, and SCA, and integrate these into CI/CD pipelines.
  • Consult and advise developers and Product Managers on security standards, vulnerability remediation, and security architecture.
  • Assess risks and trade-offs, and propose solutions for product security features such as authentication and authorization.
  • Participate in the creation, review, and implementation of technical security standards across global engineering teams.
  • Use the Harness platform to integrate security processes like vulnerability management into the SDLC.
  • Collaborate cross-functionally with Engineering and Product to accelerate the release of software with security by design.
About You
  • BS in Computer Science or a related degree.
  • 5+ years of relevant industry experience with a strong security focus.
  • Solid experience with DevSecOps practices and secure SDLC methodologies.
  • Good working knowledge of cyber security frameworks including OWASP, SANS, NIST, and CIS.
  • Ability to describe software supply chain risks and Secure SDLC best practices.
  • Experience with public or private cloud environments such as K8s, AWS, GCP, or Azure.
  • Professional knowledge of enterprise applications, API development, and modern software delivery processes.
  • Previous experience in a cloud-native environment.
  • Proficiency in Java or a comparable language and object-oriented programming methodology.
  • Hands-on experience with security testing tools and vulnerability management workflows.


Pay transparency

$180,000-$200,000 USD

Harness in the news:
  • Accelerating Our Mission to Bring AI to Everything After Code
  • Goldman Sachs leads investment in software delivery startup Harness at $5.5 billion valuation
  • How Harness runs 16 "startups within a startup" at scale | Jyoti Bansal
  • Harness Research Shows AI Visibility Crisis Fueling Security Nightmare
  • Harness has been named to the Inc. Power Partner list for software delivery success

About Harness

Harness is a continuous delivery platform that helps businesses automate their software delivery processes. The platform offers a range of tools and services to help developers build, test, and deploy software more quickly and efficiently. Harness uses AI and machine learning to optimize the software delivery process, and provides analytics and insights to help teams identify and resolve issues more quickly. The company was founded in 2016 and is headquartered in Santa Clara, California.
Learn more about Harness
Size
500 employees
Industry
Founded
2015

Similar Jobs

More Jobs at Harness

More Information Technology Jobs

Find similar Staff Product Security Engineer jobs: