Search 100,000+ live jobs across India

Free to search · AI fit score against your CV · tailor your résumé in one click

H

Senior Security Engineer - Customer Engineering

Harness · State of Karnataka, India

5–12 yrs experiencePosted 3w ago

Job description

Harness is the AI Software Delivery Platform company, led by technologist and entrepreneur Jyoti Bansal (founder of AppDynamics, acquired by Cisco for $3.7B). Harness has raised approximately $570M in funding and is valued at $5.5B, backed by leading investors including Goldman Sachs, Menlo Ventures, IVP, Unusual Ventures, Citi Ventures, and more. As AI accelerates code creation, the real bottleneck has shifted to everything after the code – testing, deployments, application security, reliability, compliance, and cost optimization. Harness brings AI and automation to this “outer loop,” helping teams ship software faster while maintaining security and governance throughout the entire software delivery lifecycle. Powered by Harness AI and the Software Delivery Knowledge Graph, the Harness Platform applies deep context and intelligent automation across the software delivery lifecycle with governance and policy-driven controls embedded throughout the platform. Over the past year, Harness powered over 185M deployments, 82M builds, 18T flag evaluations, 8M security scans, 9.1B optimized tests, 3T protected API calls, and helped manage $2.8B in cloud spend — enabling customers like United Airlines, Morningstar, and Choice Hotels to accelerate releases by up to 75%, reduce cloud costs by up to 60%, and achieve 10x DevOps efficiency. With a global team across 26 offices and 27 countries, Harness is shaping the future of AI software delivery — and we’re looking for exceptional talent to help us move even faster. The Role We're looking for a Senior Security Engineer to sit at the intersection of our Security Research Engineering team and our customers worldwide. This is a deeply technical, hands-on, detection-focused role for someone who understands how attacks against APIs and AI systems actually work — and can prove, in real customer traffic, whether a detection is firing correctly. This is a high-impact role. The value customers realize from the entire platform depends on the outcomes this team produces: whether our detections fire correctly, whether the threats that matter get surfaced, and whether customers trust what we tell them. You'll be the technical authority who validates the detections our researchers build (ModSecurity/WAF rules, API security signatures, AI security detections, OWASP Top 10 / API Top 10 / LLM Top 10 coverage), separates true positives from noise, hunts across global customer environments for business logic abuse and fraud, and closes the loop back to Research and Product to sharpen detection efficacy. You'll bring a deep understanding of the security landscape — the threat models, attacker techniques, and rapidly evolving AI security frontier — and you'll express that understanding through code: scripting, automating threat hunts, and using AI itself as a force multiplier in your investigations. Day to day, you'll work hand in hand with customers' own security teams to operationalize the Traceable by Harness Protection module and then stay engaged as an extended SOC and red team — continuously improving their security posture rather than handing off at go-live. What You'll Do • Operationalize the Protection module. Work directly with customers' security teams to stand up and tune the Traceable by Harness Protection module in their environment, from initial rollout through steady-state enforcement. • Be their extended SOC and red team. Engage continuously — not as a one-off deployment — acting as an extension of the customer's SOC to monitor and hunt, and as a red team to probe their defenses, steadily improving their overall security posture. • Evaluate detections built by Security Research Engineering. Review and pressure-test ModSecurity (ModSec) rulesets, API security detections, AI Security detections, and OWASP Top 10 / OWASP API Top 10 / OWASP LLM Top 10 coverage for accuracy, coverage gaps, and false-positive rates before and after they reach customers. • Validate true positives in production traffic. Partner directly with customer security teams to triage platform alerts, confirm genuine true positives, distinguish them from false positives and benign anomalies, and document the reasoning behind each verdict. • Automate the hunt. Build scripts, tooling, and automated workflows — increasingly AI-assisted — that scale threat hunting across many customers at once, rather than investigating one alert at a time by hand. • Run threat hunting engagements globally. Proactively hunt across the API traffic of Harness customers worldwide for business logic abuse (BOLA/BFLA, parameter tampering, workflow abuse), account takeover, credential stuffing, scraping, carding, and fraud patterns that signature-based detection alone won't catch. • Black-box test the platform and customer APIs. Attack detections and API endpoints the way a real adversary would — validating coverage, finding blind spots, and generating the adversarial traffic needed to confirm detections actually fire. • Own the detection feedback loop. Turn field findings into concrete, prioritized input for Security Research Engineering and Product — new rule ideas, tuning recommendations, catalog/detection integration gaps, and coverage improvements. • Reproduce and investigate incidents. Lead deep-dive investigations into anomalous API behavior, trace root cause (including upstream CDN/WAF/gateway layers), and produce clear RCA documentation and findings for both technical and executive audiences. • Weed out false positives and report on what matters (critical). Aggressively filter noise so customers aren't chasing false alarms, and deliver clear reports that surface genuine threat insights — helping customer teams focus their limited attention on the true incidents that actually require action. This signal-over-noise discipline is central to the value customers get from the platform. • Reduce customer noise at the source. Tu

More jobs at Harness

All Harness jobs (29)

IT jobs in State of Karnataka

All IT jobs in India (476)

Other IT jobs in India

All IT jobs in India (6,052)