채용

Security Research Engineer - Shift Left Security
Bengaluru, Karnataka, India
·
On-site
·
Full-time
·
1mo ago
Benefits & Perks
•Professional development budget
•Comprehensive health, dental, and vision insurance
•Competitive salary and equity package
•Parental leave
•Team events and activities
•Learning
•Healthcare
•Equity
•Parental Leave
Required Skills
React
Node.js
TypeScript
Harness is led by technologist and entrepreneur Jyoti Bansal, founder of App Dynamics (acquired by Cisco for $3.7B). The company has raised ~$240M in Series E venture funding, is valued at $5.5B, and backed by top investors including Goldman Sachs, Menlo Ventures, IVP, Google Ventures, J.P. Morgan, Capital One Ventures, Citi Ventures, Service Now, Splunk Ventures and more. Harness is building the industry’s leading AI-powered software delivery platform, enabling teams worldwide to build, test, and deliver software faster, safer, and more reliably. Writing code is only 30–40% of the engineering lifecycle — the rest involves testing, deployments, security, compliance, and optimization. Harness brings AI and automation to this outer loop, turning complex, time-consuming workflows into streamlined processes at massive global scale.
The platform includes industry leading products in CI/CD, Feature Flags, Cloud Cost Management, Service Reliability, Chaos Engineering, Software Engineering Insights, Internal Developer Experience, and API discovery, observability, governance, and runtime protection. Over the past year, Harness powered 128M deployments, 81M builds, 1.2T API calls protected, and $1.9B in cloud spend optimized, helping customers like United Airlines and Choice Hotels accelerate releases by up to 75% and achieve 10x DevOps efficiency. With employees in over 25 countries, Harness is shaping the future of AI-driven software delivery — and we’re looking for exceptional talent to help us move even faster.
Key Responsibilities
-
Contribute to research on modern attack vectors across source code, dependencies, build systems, and CI/CD pipelines.
-
Assist in developing scanning and detection techniques for SAST, SCA, and DAST to identify security flaws early in the development process.
-
Perform hands-on assessments of web applications, APIs, and build pipelines under guidance to uncover design flaws, misconfigurations, and dependency risks.
-
Study software supply chain threats and contribute to identifying and mitigating risks across open-source ecosystems.
-
Perform hands-on assessments of code, applications, APIs, and build pipelines under guidance to uncover design flaws, misconfigurations, and security risks.
-
Help build and test prototype tools that automate vulnerability detection and developer workflow integration.
-
Collaborate with research, product, and engineering teams to validate findings and implement security improvements in developer environments.
-
Stay current with new vulnerabilities, frameworks, and Dev Sec Ops practices to identify emerging threats relevant to modern software delivery.
-
Document findings and share insights through internal reports, knowledge bases, or external blog drafts.
Required Skills & Experience
-
Bachelor’s degree in Computer Science, Cybersecurity, or a related field (or equivalent practical experience).
-
1 - 4 years of experience application security or security research
-
Foundational understanding of Shift-Left Security concepts such as SAST, SCA, and DAST.
-
Understanding of CI/CD pipelines, build systems, and developer workflows.
-
Interest in AI and LLM models, and curiosity about how they impact software security (e.g., insecure code generation, data leakage, dependency risks).
-
Familiarity with dependency management ecosystems (npm, PyPI, Maven, Go modules) and basic knowledge of software supply chain risks.
-
Passion for research, security, and continuous learning, with a never-give-up attitude.
-
Knowledge of OWASP Top 10, API Top 10, LLM Top 10, CI/CD Top 10.
-
Strong analytical mindset with curiosity for exploring how attackers exploit weaknesses in code and pipelines.
-
Proficiency in Java and Python for prototyping and automating rule validation workflows.
-
Excellent communication, documentation, and cross-functional collaboration skills.
Nice to Have
-
Contributions to open-source security projects, especially those related to the OWASP Top 10 or OWASP API Top 10.
-
Experience developing custom WAF/WAAP rule engines, threat classifiers, or signal correlation pipelines.
-
Background in API security, runtime protection, or detection engineering at scale.
-
Authored publications, technical blogs, or delivered conference talks.
Harness in the news:
-
Accelerating Our Mission to Bring AI to Everything After Code
-
Goldman Sachs leads investment in software delivery startup Harness at $5.5 billion valuation
-
How Harness runs 16 “startups within a startup” at scale | Jyoti Bansal
-
Harness Research Shows AI Visibility Crisis Fueling Security Nightmare
-
Harness has been named to the Inc. Power Partner list for software delivery success
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex or national origin.
Note on Fraudulent Recruiting/Offers
We have become aware that there may be fraudulent recruiting attempts being made by people posing as representatives of Harness. These scams may involve fake job postings, unsolicited emails, or messages claiming to be from our recruiters or hiring managers.
Please note, we do not ask for sensitive or financial information via chat, text, or social media, and any email communications will come from the domain @harness.io. Additionally, Harness will never ask for any payment, fee to be paid, or purchases to be made by a job applicant. All applicants are encouraged to apply directly to our open jobs via our website. Interviews are generally conducted via Zoom video conference unless the candidate requests other accommodations.
If you believe that you have been the target of an interview/offer scam by someone posing as a representative of Harness, please do not provide any personal or financial information and contact us immediately at security@harness.io. You can also find additional information about this type of scam and report any fraudulent employment offers via the Federal Trade Commission’s website (https://consumer.ftc.gov/articles/job-scams)), or you can contact your local law enforcement agency.
Contact & Location
Total Views
0
Apply Clicks
0
Mock Applicants
0
Scraps
0
Similar Jobs

Application Security Engineer
xAI · Palo Alto, CA; San Francisco, CA

SOC Support Specialist- Weekend Shift
Huntress · Remote US; United States of America

Staff Software Engineer, Platform Security
Discord · San Francisco Bay Area or Remote

Security Engineer, Product
Ramp · New York, NY (HQ)

Security Engineer
Contentful · New York City, New York, United States
About Split.io

Split.io
AcquiredBest known for creating and developing the Hitman and Kane and Lynch franchises.
201-500
Employees
Copenhagen
Headquarters
Reviews
3.6
2 reviews
Work Life Balance
3.0
Compensation
3.0
Culture
3.0
Career
3.0
Management
3.0
60%
Recommend to a Friend
Pros
Works properly on mobile app
Clear problem solutions
Good for deployment and release decoupling
Cons
Blacklisted by many firewalls
Breaks web browser access
Inconsistent experience between web and mobile
Interview Experience
36 interviews
Difficulty
3.2
/ 5
Duration
14-28 weeks
Offer Rate
33%
Experience
Positive 65%
Neutral 17%
Negative 18%
Interview Process
1
Phone Screen
2
Technical Interview
3
Hiring Manager
4
Team Fit
Common Questions
Technical skills
Past experience
Team collaboration
Problem solving
News & Buzz
AITAH lying about why we broke up with my gf?
**I am NOT OOP. OOP is u/Just_Chicken_373** **Originally posted to r/AITAH** **AITAH lying about why we broke up with my gf?** **Thank you to a longtime redditor for the suggestion!** **Trigger Warnings:** >!mentions bullying and infidelity, misogyny, slut shaming!< ---- [Original Post](
·
5w ago
·
1,679
·
615
The 20 most critically acclaimed games of the half-decade (2021-2025)
Got curious about the most acclaimed games of the last 5 years so here we are. This is going by Open Critic scores with Death Stranding 2 and Tekken 8 being the lowest scoring at 90 and Baldur's Gate 3 being the highest at 96. All games included have a minimum of 20 reviews and in case of tied scor
·
9w ago
·
5,515
·
1146
Europe if all the glaciers melted – new cities, canals, ports and borders [OC]
·
9w ago
·
1,891
·
453
600+ Steam Key Giveaway from Old Humble Bundles
***Final update*** *With 99% of the keys having been distributed* ***this giveaway is now officially over!*** ***Update: December 25, 23:50 GMT*** *HO-HO-hold it there! I was hoping to finish ticking off the list tonight and sped things up a little but Reddit decided to tell me to take a break from
·
11w ago
·
1,248
·
2799