Staff Security Research Engineer

Harness

Mountain View, CA, US / Onsite/Remote
  • Job Type: Full-Time
  • Function: IT
  • Post Date: 06/09/2025
  • Website: harness.io
  • Company Address: 55 Stockton St, Floor 8, San Francisco, California 94108, US

About Harness

Harness is a rapidly growing startup that is disrupting the software delivery market. We are building an intelligent software delivery platform that enables engineers to deliver software faster, with higher quality, and with less effort.

Job Description

Harness is a high-growth company that is disrupting the software delivery market. Our mission is to enable the 30 million software developers in the world to deliver code to their users reliably, efficiently, securely and quickly, increasing customers’ pace of innovation while improving the developer experience. We offer solutions for every step of the software delivery lifecycle to build, test, secure, deploy and manage reliability, feature flags and cloud costs. The Harness Software Delivery Platform includes modules for CI, CD, Cloud Cost Management, Feature Flags, Service Reliability Management, Security Testing Orchestration, Chaos Engineering, Software Engineering Insights and continues to expand at an incredibly fast pace.
 
Harness is led by technologist and entrepreneur Jyoti Bansal, who founded AppDynamics and sold it to Cisco for $3.7B. We’re backed with $425M in venture financing from top-tier VC and strategic firms, including J.P. Morgan, Capital One Ventures, Citi Ventures, ServiceNow, Splunk Ventures, Norwest Venture Partners, Adage Capital Partners, Balyasny Asset Management, Gaingels, Harmonic Growth Partners, Menlo Ventures, IVP, Unusual Ventures, GV (formerly Google Ventures), Alkeon Capital, Battery Ventures, Sorenson Capital, Thomvest Ventures and Silicon Valley Bank.


Position Summary


Harness is expanding into DevSecOps with the integration of Traceable, and we're hiring a Staff or Principal Security Research Engineer to help lead the charge. This is a rare opportunity to work with visionary leaders like Jyoti Bansal and help shape security across the modern software delivery lifecycle—from code to cloud.

You'll drive research into cutting-edge threats targeting APIs, CI/CD pipelines, and emerging technologies like LLMs. Your work will directly influence product direction, detection capabilities, and customer protection strategies. This is a hands-on, high-impact role where you’ll collaborate across teams, interface with top-tier customers, and represent Harness at leading security conferences.

If you're passionate about solving hard security problems at scale, this role puts you at the center of innovation in a fast-growing DevSecOps platform.


About The Role

  • Conduct cutting-edge research on modern attack vectors across AppSec, CI/CD pipelines, runtime environments, and emerging technologies like LLMs
  • Develop and refine advanced exploit techniques to prevent attacks targeting software delivery, runtime from code to cloud
  • Collaborate with research, product and engineering to prototype and implement detection and mitigation strategies for emerging threats
  • Perform in-depth security assessments and penetration testing of web applications, APIs, build systems, and cloud-native environments
  • Engage with customers to understand their application landscape and provide expert guidance on integrating product capabilities with their security requirements
  • Support pre-sales, POCs, and post-sales engagements by troubleshooting and solving complex detection and protection challenges
  • Build internal tools to automate and enhance security research workflows.
  • Evangelize our research and platform through blogs, white papers, and talks at premier security conferences
  • Analyze global cybersecurity incidents to extract learnings and apply them across domains


About You

  • Bachelor's or Master's degree in Computer Science.
  • 8-10+ years of work experience
  • Deep expertise with modern application stacks (microservices, containers, Kubernetes, cloud platforms like AWS/GCP)
  • Prior development experience and a fair understanding of programming languages and frameworks are a must
  • Proficient in at least one modern programming language (Python, Go, Java, JavaScript, etc.)
  • Demonstrated experience in penetration testing, vulnerability research, and exploitation of Web/API ecosystems
  • Strong foundation in computer science fundamentals, identity aware, network, application and runtime security
  • Strong experience with various pen testing tools like Burpsuite, ZAP, etc.
  • Strong applied knowledge of attacks in Web/API eco-system - Web attacks, API attacks, API abuse, API Fraud, ATO, etc.
  • Strong knowledge of modern application security threats and mitigation platforms like (WAFs, WAAP, RASP, etc.).
  • Working knowledge of IAST, DAST, and SAST
  • Experience in responsible disclosure of vulnerabilities and a track record of CVEs or similar
  • Proven track record of publishing high-quality research or presenting at top security conferences (e.g., Black Hat, DEF CON, RSAC, BSides) is a strong plus
  • Certifications such as CEH, OSCP, OSCE, or relevant security credentials
  • Strong analytical skills and the ability to conduct complex security research autonomously
  • Ability to work autonomously and drive complex security investigations from hypothesis to implementation


Work Location


This role will be out of our Mountain View office on a Hybrid capacity.


What You Will Have at Harness

  • Competitive salary
  • Comprehensive healthcare benefits
  • Flexible Spending Account (FSA)
  • Employee Assistance Program (EAP)
  • Flexible Time Off and Parental Leave
  • Quarterly Harness TGIF-Off / 4 days
  • Monthly, quarterly, and annual social and team-building events
  • Recharge & Reset Program
  • Monthly internet reimbursement
  • Commuter benefits


The anticipated base salary range for this position is $180,000 - $235,000 annually. Salary is determined by a combination of factors including location, level, relevant experience, and skills. The range displayed on each job posting reflects the minimum and maximum target for new hire salaries for the position across all US locations.  The compensation package for this position may also include equity, and benefits. More details about our company benefits can be found at the following link: https://www.harness.io/company/careers.

A valid authorization to work in the U.S. is required

 

Pay transparency

$180,000 - $235,000 USD

Harness in the news:

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex or national origin.

Note on Fraudulent Recruiting/Offers

We have become aware that there may be fraudulent recruiting attempts being made by people posing as representatives of Harness. These scams may involve fake job postings, unsolicited emails, or messages claiming to be from our recruiters or hiring managers. 

Please note, we do not ask for sensitive or financial information via chat, text, or social media, and any email communications will come from the domain @harness.io. Additionally, Harness will never ask for any payment, fee to be paid, or purchases to be made by a job applicant. All applicants are encouraged to apply directly to our open jobs via our website. Interviews are generally conducted via Zoom video conference unless the candidate requests other accommodations.

If you believe that you have been the target of an interview/offer scam by someone posing as a representative of Harness, please do not provide any personal or financial information and contact us immediately at security@harness.io. You can also find additional information about this type of scam and report any fraudulent employment offers via the Federal Trade Commission’s website (https://consumer.ftc.gov/articles/job-scams), or you can contact your local law enforcement agency.

Related Jobs

Enterprise Account Executive - Chicago

Harness - Chicago, IL, US

Enterprise Account Executive - Federal/Civilian (DC)

Harness - Washington, DC, US

Staff Software Engineer - AI Assistant

Harness - Bangalore, IN

Senior Software Engineer - CCM

Harness - Bangalore, IN

Senior Software Engineer - AI

Harness - Bangalore, IN
Disclaimer: Local Candidates Only
This company does NOT accept candidates from outside recruiting firms. Agency contacts are not welcome.