Senior Security Engineer - Customer Engineering
Bengaluru, India · Full-time
- Posted 1mo ago
- From Harness’s careers page
- Location
- Bengaluru, India
- Type
- Full-time
- Level
- Senior
- Experience
- 4+ years
- Department
- Information Technology
Opens the listing on harness.io
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.
About the role
The Role
We're looking for a Senior Security Engineer to sit at the intersection of our Security Research Engineering team and our customers worldwide. This is a deeply technical, hands-on, detection-focused role for someone who understands how attacks against APIs and AI systems actually work — and can prove, in real customer traffic, whether a detection is firing correctly.
What You'll Do
- Operationalize the Protection module. Work directly with customers' security teams to stand up and tune the Traceable by Harness Protection module in their environment, from initial rollout through steady-state enforcement.
- Be their extended SOC and red team. Engage continuously — not as a one-off deployment — acting as an extension of the customer's SOC to monitor and hunt, and as a red team to probe their defenses, steadily improving their overall security posture.
- Evaluate detections built by Security Research Engineering. Review and pressure-test ModSecurity (ModSec) rulesets, API security detections, AI Security detections, and OWASP Top 10 / OWASP API Top 10 / OWASP LLM Top 10 coverage for accuracy, coverage gaps, and false-positive rates before and after they reach customers.
- Validate true positives in production traffic. Partner directly with customer security teams to triage platform alerts, confirm genuine true positives, distinguish them from false positives and benign anomalies, and document the reasoning behind each verdict.
- Automate the hunt. Build scripts, tooling, and automated workflows — increasingly AI-assisted — that scale threat hunting across many customers at once, rather than investigating one alert at a time by hand.
- Run threat hunting engagements globally. Proactively hunt across the API traffic of Harness customers worldwide for business logic abuse (BOLA/BFLA, parameter tampering, workflow abuse), account takeover, credential stuffing, scraping, carding, and fraud patterns that signature-based detection alone won't catch.
- Black-box test the platform and customer APIs. Attack detections and API endpoints the way a real adversary would — validating coverage, finding blind spots, and generating the adversarial traffic needed to confirm detections actually fire.
- Own the detection feedback loop. Turn field findings into concrete, prioritized input for Security Research Engineering and Product — new rule ideas, tuning recommendations, catalog/detection integration gaps, and coverage improvements.
- Reproduce and investigate incidents. Lead deep-dive investigations into anomalous API behavior, trace root cause (including upstream CDN/WAF/gateway layers), and produce clear RCA documentation and findings for both technical and executive audiences.
- Weed out false positives and report on what matters (critical). Aggressively filter noise so customers aren't chasing false alarms, and deliver clear reports that surface genuine threat insights — helping customer teams focus their limited attention on the true incidents that actually require action. This signal-over-noise discipline is central to the value customers get from the platform.
- Reduce customer noise at the source. Tune detections to each customer's API catalog, business context, and legitimate integration patterns so false positives are suppressed before they ever reach an analyst.
- Be a trusted technical advisor. Translate detection logic and threat findings into language customer security leaders can act on, and help them mature their API and AI security posture.
What You Bring
- 4–6 years in security engineering, detection engineering, threat hunting, penetration testing, incident response, or a closely related discipline.
- A deep, current understanding of the security landscape — threat models, attacker techniques, and how attacks against APIs and AI systems actually play out.
- Ability to code and automate. You write your own tooling to scale threat hunting — this is not a point-and-click role.
- Ability to use AI for threat hunting. You actively leverage LLMs and AI-assisted workflows to accelerate investigation, triage, and hunt automation.
- Black-box penetration testing ability — you can attack an API or a detection with no prior knowledge and reason about what an adversary would do.
- Comfort working directly with enterprise customers globally — you can lead a technical conversation, defend a verdict, and write findings that stand up to scrutiny.
Skills they ask for
Pick one to see other roles that ask for it.
About Harness
An AI platform for software deliveryHarness provides an autonomous software delivery platform that uses AI to manage pipelines, assess risk, and govern software releases.
See all 27 roles at HarnessMore roles at Harness
See all 27- Senior Customer ArchitectUnited States · Senior · RemoteCustomer Service · Senior · RemoteUnited States13h
- Staff/Senior Software Engineer - Cloud Platform EngineeringUnited States · Senior · RemoteSoftware Development · Senior · RemoteUnited States2d
- Customer Experience Engineer I/IIUnited States · Entry Level · RemoteEntry Level · RemoteUnited States2d
- AppSec Sales Engineer - EastUnited States · Senior · RemoteSales · Senior · RemoteUnited States3d
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.