Director Software Engineering - AppSec Platform
harnessinc · Bengaluru, Karnataka, India
Experience: 15-20 years
Harness is the AI Software Delivery Platform company, led by technologist and entrepreneur Jyoti Bansal (founder of AppDynamics, acquired by Cisco for
.7B). Harness has raised approximately $570M in funding and is valued at $5.5B, backed by leading investors including Goldman Sachs, Menlo Ventures, IVP, Unusual Ventures, Citi Ventures, and more. As AI accelerates code creation, the real bottleneck has shifted to everything after the code – testing, deployments, application security, reliability, compliance, and cost optimization. Harness brings AI and automation to this “outer loop,” helping teams ship software faster while maintaining security and governance throughout the entire software delivery lifecycle.Powered by Harness AI and the Software Delivery Knowledge Graph, the Harness Platform applies deep context and intelligent automation across the software delivery lifecycle with governance and policy-driven controls embedded throughout the platform.
Over the past year, Harness powered over 185M deployments, 82M builds, 18T flag evaluations, 8M security scans, 9.1B optimized tests, 3T protected API calls, and helped manage
Careeroza — One-stop Zone for Aspirants
Study material, Careeroza mentorship, tech jobs, and career guidance on careeroza.com.
Public study materials
- Django (Django)
- What is Django · basic
- Installing Django · basic
- Features of Django · basic
- MVT Architecture · basic
- Django vs Flask · basic
- Creating Project & Creating App · basic
- Django Project Structure · basic
- URL Routing · basic
- Views · basic
- Templates · basic
- Static & Media Files · medium
- Models · medium
- ORM (Object Relational Mapping) · medium
- Model Relationships · medium
- Migrations · medium
- Django Admin · medium
- Forms · medium
- Authentication · medium
- Authorization · medium
- Middleware · medium
- Signals · medium
- Class Based Views Deep Dive · advance
- Generic Views · advance
- File Handling · advance
- Django REST Framework (DRF) · advance
- Advanced ORM · advance
- Caching · advance
- Asynchronous Django · advance
- Background Tasks · advance
- Interview Questions · interview-questions
- Python (Python)
- Python Fundamentals · basic
- Control Flow · basic
- Strings · basic
- Collections / Data Structures · basic
- Functions · basic
- Modules and Packages · basic
- File Handling · basic
- Exception Handling · basic
- Object-Oriented Programming (OOP · medium
- Advanced Python Concepts · advance
- Functional Programming · advance
- Multithreading & Multiprocessing · advance
- Async Programming · advance
- System Architecture (System Architecture)
- Fundamentals of System Architecture · basic
- Distributed System Basics · basic
- System Reliability Concepts · basic
- Scaling Concepts · basic
- Networking Basics · basic
- Web Communication · basic
- API Communication · basic
- Proxy & Delivery Systems · basic
- Web Architecture Basics · basic
- Rendering Architectures · basic
- Frontend Advanced Concepts · basic
- Message Queue Basics · medium
- What is Load Balancer · medium
- Load Balancing Algorithms · medium
- API Design Basics · medium
- API Protection · medium
- Authentication Basics · medium
- Security Tokens · medium
- Security Threats · medium
- Encryption & Security · medium
- SQL Database Basics · medium
- SQL Scaling Concepts · medium
- NoSQL Databases · medium
- Database Optimization · medium
- Replication Strategies · medium
- Caching Basics · medium
- Cache Storage Systems · medium
- Cache Strategies · medium
- Event-Driven Systems · advance
- Queue Reliability · advance
- Microservices Basics · advance
- Microservice Communication · advance
- Distributed Transactions · advance
- DevOps Basics · advance
- Automation Tools · advance
- Deployment Strategies · advance
- Monitoring Basics · advance
- Monitoring Tools · advance
- Distributed System Concepts · advance
- Distributed Algorithms · advance
- Express.js — Web APIs & middleware (expressjs)
- Application setup · basic
- Routing deep dive · basic
- 1. MVC / Layered Architecture · medium
- Validation · medium
- File uploads · medium
- Sessions & auth (stateful) · medium
- Passport & strategies · medium
- Templating & SSR · medium
- WebSockets & SSE · medium
- Security middleware · advance
- Reverse proxies & trust · advance
- Performance · advance
- API design & versioning · advance
- Testing with Supertest · advance
- GraphQL & tRPC (overview) · advance
- Deployment checklist · advance
- Middlewares · basic
- Request & Response · basic
- System Designing (System Designing)
- Day-1 : What is system Designing ? · basic
- Day-2 : Vertical vs. Horizontal Scaling · basic
- Day-3:How to do vertical scaling ? · basic
- Day4:How to do horizaontal scaling ? · basic
- Day:5TCP vs UDP · basic
- Day6:IP & DNS · basic
- Day7:Client-Server Model · basic
- Day8:HTTP & HTTPS · basic
- Databases (SQL vs NoSQL) · medium
- Caching · medium
- Day9:Latency & Throughput · basic
- Load Balancing · medium
- Indexes & Query Optimization · medium
- CDN · medium
- Proxies · medium
- Message Queues · medium
- Horizontal vs Vertical Scaling · medium
- Database Replication · advance
- Database Sharding · advance
- Consistent Hashing · advance
- CAP Theorem · advance
- Rate Limiting · advance
- Service Discovery · advance
- Event-Driven Architecture · advance
- API Gateway · advance
- Distributed Consensus · expert
- Microservices · expert
- Observability · expert
- Idempotency · expert
- PACELC Theorem · expert
- Two-Phase Commit · expert
- Back-of-Envelope Estimation · expert
- Designing for Failure · expert
- SQL (SQL)
- SQL Fundamentals · basic
- Database Operations · basic
- Table Operations · basic
- CRUD Operations · basic
- Filtering & Operators · basic
- SQL Functions · basic
- GROUPING Data · basic
- Joins · medium
- Constraints · basic
- Subqueries · medium
- Set Operators · medium
- Views · medium
- Indexes · medium
- Normalization · advance
- Transactions · advance
- Stored Procedures & Functions · advance
- Triggers · advance
- Advanced SQL · advance
- Query Optimization · advance
- Database Design · advance
- SQL Security · advance
- Backup & Recovery · advance
- Questions · interview questions
- JavaScript (JavaScript)
- JS Introduction · basic
- Variables & Data Types · basic
- Operators · basic
- Control Flow · basic
- Functions · basic
- Scope & Execution · basic
- Closures · basic
- Objects · basic
- Arrays · basic
- Strings · basic
- DOM Manipulation · basic
- Browser APIs · medium
- Asynchronous JavaScript · medium
- Fetch & APIs · medium
- ES6+ Features · medium
- OOP in JavaScript · medium
- Prototype & Inheritance · advance
- Advanced Functions · advance
- Memory Management · advance
- Error Handling · advance
- Modules · advance
- Advanced Async Concepts · advance
- Functional Programming · advance
- JavaScript Internals · advance
- Performance Optimization · advance
- Angular (Angular)
- Angular Fundamentals · basic
- Project Structure · basic
- Components & Templates · basic
- Data Binding · basic
- Directives · basic
- Pipes · basic
- Component Communication · basic
- Lifecycle Hooks · basic
- Routing Basics · basic
- Routing · basic
- API Calls · basic
- Forms · medium
- Routing · medium
- Services & Dependency Injection · medium
- RxJS & Observables · medium
- Authentication & Security · medium
- Component Interaction · medium
- State Management Basics · medium
- Error Handiling · medium
- Perfomance Basic · medium
- Real World Features · medium
- Advanced Angular Architecture · advance
- Change Detection · advance
- Advanced RxJS · advance
- State Management · advance
- Dynamic Rendering · advance
- Perfomance Optimization · advance
- Modern Angular · advance
- STAR (Situation, Task, Action, and Result) (Situation Based Questions)
- Node.js — Server-side JavaScript (nodejs)
- Getting started · basic
- JavaScript on the server · basic
- CommonJS modules · basic
- ES modules (ESM) · basic
- npm & package management · basic
- Asynchronous JavaScript in Node · basic
- The event loop · basic
- Essential core utilities · basic
- process & configuration · basic
- File system basics · basic
- HTTP & HTTPS servers · medium
- Streams · medium
- Events & EventEmitter · medium
- Advanced filesystem · medium
- crypto · medium
- Compression & encoding · medium
- Child processes · medium
- net, dgram & DNS · medium
- readline, timers & scheduling · medium
- Testing & diagnostics (intro) · medium
- Worker threads · advance
- cluster & multi-process scaling · advance
- Performance & tuning · advance
- Debugging & observability · advance
- Security hardening · advance
- Native addons & N-API · advance
- Architecture patterns · advance
- Graceful shutdown · advance
- 100 Questions · interview questions
- MongoDB — Documents & data modeling (MongoDB)
- Introduction · basic
- Shell, Compass & tools · basic
- Databases & collections · basic
- CRUD operations · basic
- Indexes deep dive · medium
- Explain plans & performance · medium
- Aggregation framework · medium
- Schema design patterns · medium
- Mongoose basics · medium
- Mongoose advanced · medium
- Drivers & connection · medium
- Operators for updates & arrays · medium
- Replication & read preferences · advance
- Write concern & read concern · advance
- Multi-document transactions · advance
- Change streams · advance
- Sharding (overview) · advance
- Atlas Search & full-text · advance
- GridFS & large files · advance
- Backup, restore & ops · advance
- AWS Crash Course (AWS)
- What is Cloud ? · basic
- What is AWS ? · basic
- If not cloud ? · basic
- Cloud Computing · basic
- AWS Pricing · basic
- AWS Shared Responsibility Model · basic
- AWS Management Console · basic
- AWS SDKs · basic
- AWS IAM · medium
- Users, Groups, Roles · medium
- Policies · medium
- AWS Organizations · medium
- AWS Cognito · medium
- AWS Directory Service · medium
- AWS KMS (Key Management Service) · medium
- AWS Secrets Manager · medium
- AWS Shield · medium
- AWS WAF · medium
- AWS Inspector · medium
- AWS GuardDuty · medium
- EC2 · advance
- Launching EC2 Instances · advance
- EBS Volumes · advance
- Security Groups · advance
- Key Pairs · advance
- Elastic IP · advance
- User Data Scripts · advance
- Auto Scaling · advance
- Load Balancers · advance
- ALB · advance
- NLB · advance
- Serverless Compute ,AWS Lambda, Lambda Layers · advance
- Event-Driven Architecture · advance
- ECS · advance
- EKS · advance
With a global team across 26 offices and 27 countries, Harness is shaping the future of AI software delivery — and we’re looking for exceptional talent to help us move even faster.
## Position Summary
Join Harness at a defining moment for application security — the moment AI stopped being a feature of the attack surface and became the attack surface itself. Harness is the leading AI-native software delivery platform, helping engineering teams build, test, secure, and deploy software faster and more safely. We're backed by $600M+ in funding, led by AppDynamics founder Jyoti Bansal, and recognized as a Leader in the Gartner Magic Quadrant™ for DevSecOps Platforms.
Our Web Application and API Protection (WAAP) team protects the APIs and applications that power some of the world's most demanding digital businesses — at a moment when API traffic, AI agent endpoints, and machine-to-machine communication are growing faster than any human security team can manually review. WAAP also owns Harness's AI Security capabilities, putting this team at the center of some of the most important emerging problems in the industry in AI era: discovering and inventorying AI usage across an enterprise, red-teaming AI systems and agents before attackers do, and building the AI firewall layer that governs how models and agents are allowed to act.
We're looking for a Director of Engineering to lead WAAP's next chapter — taking a product that already protects mission-critical, API-first traffic at scale for global customers and growing its footprint into AI Discovery, AI red-teaming, and AI firewall capabilities as enterprises figure out how to secure their own AI adoption. This is a hands-on, high-impact leadership role combining product ownership, architectural depth, and direct customer partnership, reporting into AppSec engineering leadership and working closely with a team that already has strong managers and senior ICs in place across every function.
## About the Role
As Director of Engineering for WAAP, you'll own the technical vision, roadmap, and execution for a product line defending live, high-value traffic for global customers — and help point the team toward where AI-era protection needs to go next, from AI/agent discovery to red-teaming to enforcement at the AI firewall layer. You'll split your time between technology leadership, product and roadmap ownership, and cross-functional collaboration — partnering closely with the AST and Software Supply Chain teams that make up Harness's broader AppSec portfolio.
## Key Responsibilities
• Define the AI-era WAAP vision — set strategy for runtime API protection, bot and abuse defense, and AI security as machine traffic and agentic workloads reshape what "web application protection" means.
• Shape the AI Security roadmap — identify where WAAP should invest next in AI Discovery (finding and inventorying AI/agent usage across an enterprise), AI red-teaming (proactively probing models and agents for weaknesses), and the AI firewall (governing and enforcing how models and agents are allowed to act) — a fast-moving space with significant room to define what good looks like.
• Own architecture and platform depth — provide hands-on technical leadership across API discovery, runtime traffic analysis, and detection efficacy, continuing the move toward a unified, efficient architecture across the broader AST/WAAP stack.
• Build and develop the team — hire, grow, and retain strong engineers and leaders, building on managers and senior ICs already in place across the org.
• Partner directly with customers — engage with enterprise customers on escalations, roadmap input, and adoption of new AI-era protection capabilities.
• Drive quality and enterprise readiness — own reliability, incident response, and production health across WAAP, closing execution gaps with rigor and discipline.
• Contribute to the AppSec portfolio strategy — collaborate across AST and Software Supply Chain Security to ensure WAAP's roadmap reinforces a coherent, best-in-class security platform.
• Represent Harness externally — engage with the security community, industry panels, and customers as a credible voice on API security and AI-era application defense.
## About You
You are a strong people leader with empathy and growth mindset. You lead with technical depth, not title. You've scaled distributed systems and engineering teams through hypergrowth, you learn fast in new domains, and you're drawn to the kind of ambiguity that comes with building in a space — AI security — that's still being invented. You think like a product engineer even in a leadership seat — close to the technical decisions, close to customers, and willing to get hands-on when it matters.
## Required Experience & Qualifications
• 15-20 years of backend or platform engineering experience; 8+ years leading high-performing engineering teams.
• Proven success building and scaling engineering orgs in fast-paced, high-growth environments.
• Hands-on architectural experience with high-throughput, distributed systems and scalable APIs.
• Strong interest in applying AI to security problems — discovery, detection, and response.
• Clear, confident communicator who can operate across engineers, executives, and customers.
• Organized, action-oriented leader who drives results while protecting team health.
• BS in Computer Science or equivalent practical experience.
• A builder's instinct for applying AI/agentic approaches to security workflows, not just security to AI products.
• Domain knowledge in application security, API security, WAAP/WAF, bot/abuse defense, or AI security is preferred
## Harness in the news:
• Accelerating Our Mission to Bring AI to Everything After Code
• Goldman Sachs leads investment in software delivery startup Harness at $5.5 billion valuation
• How Harness runs 16 “startups within a startup” at scale | Jyoti Bansal
• Harness Research Shows AI Visibility Crisis Fueling Security Nightmare
• Harness has been named to the Inc. Power Partner list for software delivery success
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex or national origin.
At Harness, we care about your privacy and are committed to protecting your personal data. For additional information on this topic, you can visit our privacy Portal: https://harness-privacy.relyance.ai/
Note on Fraudulent Recruiting/Offers
We have become aware that there may be fraudulent recruiting attempts being made by people posing as representatives of Harness. These scams may involve fake job postings, unsolicited emails, or messages claiming to be from our recruiters or hiring managers.
Please note, we do not ask for sensitive or financial information via chat, text, or social media, and any email communications will come from the domain @harness.io. Additionally, Harness will never ask for any payment, fee to be paid, or purchases to be made by a job applicant. All applicants are encouraged to apply directly to our open jobs via our website. Interviews are generally conducted via Zoom video conference unless the candidate requests other accommodations.
If you believe that you have been the target of an interview/offer scam by someone posing as a representative of Harness, please do not provide any personal or financial information and contact us immediately at security@harness.io . You can also find additional information about this type of scam and report any fraudulent employment offers via the Federal Trade Commission’s website ( https://consumer.ftc.gov/articles/job-scams) , or you can contact your local law enforcement agency.