Full-Time
Updated on 9/4/2026
CI/CD platform with cloud cost management
$110k - $145k/yr
San Francisco, CA, USA
Hybrid
Hybrid in the Bay Area; qualified candidates may work remotely within the United States.
See people who can refer or advise you
Harness provides a platform for automated software delivery and cloud cost management. It focuses on CI/CD, helping teams integrate code, deploy to production, run tests, and monitor applications through automated pipelines. It also offers a Cloud Cost Management tool that detects and stops cost anomalies in real time to optimize cloud spending. The self-managed Enterprise edition can be installed on a customer’s Kubernetes cluster. What sets Harness apart is its combination of intelligent automation across the software delivery lifecycle with real-time cloud cost control, plus an enterprise-grade, flexible deployment model. Its goal is to help organizations deliver software faster and more reliably while keeping cloud costs under control.
Company Size
1,001-5,000
Company Stage
Series E
Total Funding
$805M
Headquarters
San Francisco, California
Founded
2017
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Competitive salary and early-stage stock options
Comprehensive healthcare benefits
Flexible Spending Account (FSA)
Flexible work schedule
Employee Assistance Program (EAP)
Paid Time Off & Parental Leave
Monthly, quarterly, & annual social and team building events
TGIF-Off program
Remote office stipend
Monthly internet reimbursement
Monthly Food & Beverage Reimbursement Program
Harness RT Agents automate resilience risk detection in CD pipelines. 1h ago DevOps Tl;dr. Harness launches agentic resilience testing that passively scans CD pipelines and Kubernetes workloads to identify risks, then generates and runs chaos experiments without manual setup. Key points. * Passive detection analyzes deployment configs and pipeline history without instrumenting or touching production * Agents automatically generate chaos experiments and load tests tailored to detected risks
Harness has launched Agent-Ready Code Repository and AI Code Review, tools designed for teams using AI coding agents. The platform addresses the challenge of managing high volumes of AI-generated code that traditional systems struggle to handle. The new repository can process thousands of pull requests and commits simultaneously whilst maintaining search and file history performance. It includes permission controls specifically for AI agents, allowing developers to define what agents can access, merge, or deploy. The AI Code Review feature groups code changes by risk level and provides one-click remediation for identified issues. Teams can set mandatory checks that must pass before code can be merged. Harness reports its engineering teams saved over 10,000 hours of manual review time monthly whilst testing the tools internally. The repository includes 50 GB of free storage and supports one-click migration from GitHub, GitLab, Bitbucket, and Azure DevOps.
Can AI agents automate security at machine speed? Aug 20, 2026 Harness recently launched a Zero-Day Agent that monitors threat intelligence feeds around the clock to identify and fix newly disclosed vulnerabilities instantly. This development signifies a critical pivot in the arms race between cyber defense teams and threat actors who utilize automated exploit generators. In the current 2026 landscape, the traditional model of manually triaging security alerts is insufficient, as the window between the publication of a CVE entry and the first active attack has effectively vanished. Organizations are now forced to adopt autonomous agents that navigate complex codebases and apply patches at the same speed at which threats propagate. These agents utilize advanced reasoning to determine the specific relevance of a vulnerability to a unique environment, eliminating the noise that typically plagues security operations. By automating identification and remediation cycles, enterprises reduce risk exposure while allowing staff to focus on strategic threat hunting. The technical architecture: beyond simple automation. The technical foundation of these agents involves deep integration with the software development lifecycle, specifically within the automated testing pipelines. Unlike legacy scanners that only flag issues, modern security agents understand the semantic structure of code, allowing them to propose changes that fix vulnerabilities without altering the intended functionality. When a new vulnerability is announced, the agent automatically clones the environment in a secure sandbox and begins iterating through fixes, validating each one against existing unit and integration tests. This process ensures that any code changes are safe to deploy and will not result in service disruptions. Furthermore, these agents generate detailed reports that explain the logic behind each fix, providing transparency for human reviewers who need to audit the changes. This shift toward intelligent, self-correcting systems represents a major milestone where security is no longer a separate phase but a built-in feature. Integrating these agents into the continuous delivery process has changed how engineering teams prioritize their daily tasks and projects. In 2026, developers no longer spend a significant portion of their week chasing security technical debt or manually updating libraries to satisfy compliance. Instead, the autonomous agents handle the bulk of routine maintenance and patching, only escalating issues to humans when a complex architectural decision or a significant breaking change is detected. This collaborative model between human and machine intelligence allows for a resilient infrastructure that can withstand the pressure of constant scanning by malicious bots. Moreover, the ability of these systems to coordinate with cloud-native security groups ensures a multi-layered defense strategy. By automatically adjusting access controls and network configurations, the agents provide a dynamic security perimeter that adapts in real-time, ensuring that sensitive data remains protected regardless of the initial attack vector. Risk management and strategic deployment: the road ahead. Risk management remains a central concern for any organization deploying autonomous agents with the authority to modify production code. While the speed of these systems is a clear advantage, the possibility of an agent making an incorrect decision necessitates robust guardrails. Advanced platforms now incorporate a policy-based approach where administrators define the boundaries of autonomous action based on the criticality of the system. For instance, an agent might be allowed to automatically patch a low-risk web application but only suggest changes for a core transactional database. This tiered approach ensures that the benefits of machine-speed response are realized where they are most needed, while maintaining human control over the most sensitive assets. Additionally, the use of diverse AI models for cross-validation helps to minimize the risk of a single model making a flawed recommendation. This achieves a higher level of reliability than was ever possible with manual processes. Beyond simple patching, these agents are now being utilized to predict and prevent future vulnerabilities by analyzing patterns in successful attacks across the industry. By participating in decentralized intelligence networks, agents share anonymized data about new exploitation techniques and defensive strategies in real-time. This collective intelligence allows an agent in one part of the world to proactively harden local systems based on an attack observed elsewhere, often before the specific vulnerability is even publicly disclosed. This move toward predictive defense is essential in an era where generative AI is used by adversaries to create novel malware at scale. The agents simulate potential attack paths through a network and recommend structural changes to the architecture to eliminate entire classes of vulnerabilities. This proactive stance raises the cost for attackers, as they are no longer targeting static systems but dynamic environments that learn from every interaction. The implementation of autonomous security agents demonstrated that organizations could finally close the gap between vulnerability discovery and remediation. To achieve this, leaders prioritized the integration of security agents into existing observability stacks, ensuring the AI had access to high-quality telemetry data. Successful strategies focused on a gradual rollout, starting with non-critical internal applications to build confidence in the agentic decision-making process. Security teams also invested in training for their human analysts, shifting their focus from manual triage to high-level policy definition and agent oversight. By treating the security agent as a force multiplier, companies optimized their response times and reduced the burden of repetitive maintenance tasks. Ultimately, the move toward machine-speed security required a cultural shift that embraced automation as a foundational requirement. Early adopters secured a competitive advantage by ensuring data remained protected.
Harness has launched a suite of AI-powered security agents designed to accelerate vulnerability response at machine speed. The platform includes AI SAST scanning, automated triage and remediation agents, a Zero-Day Agent, and virtual patching capabilities. The tools address a growing challenge: attackers using frontier AI models can exploit vulnerabilities within six hours of disclosure, whilst the average fix still takes over 50 days. Project Glasswing partners have surfaced roughly 10 times more vulnerabilities using LLM-based scanning. The Zero-Day Agent monitors for newly disclosed threats continuously, identifies affected pipelines, and generates validated fixes within minutes. Virtual patching deploys protective measures immediately whilst permanent fixes are developed. The capabilities are available now as part of the Harness platform. The company previously merged with Traceable in early 2025.
Harness launches AI security tools for faster vulnerability remediation. Harness has introduced new application security capabilities, including AI SAST, agentic triage and remediation, a dedicated Zero-Day Agent, and virtual patching. Together, the capabilities help security teams detect vulnerabilities, prioritize critical risks, and deploy fixes faster without relying on slow, disconnected security processes. As frontier AI accelerates attackers' ability to exploit vulnerabilities, Harness aims to give defenders the automation and speed needed to keep pace. Frontier AI models are now on both sides of the equation. Attackers are using them to find and chain vulnerabilities faster than ever, going from disclosure to first exploit in as little as six hours, while the average vulnerability still takes over 50 days to fix. Machine Learning & Artificial Intelligence Defenders are gaining the same advantage, but unevenly: Harness's own testing found frontier models surfacing roughly 10 times more vulnerabilities than traditional scanners, a wave of visibility that just becomes a bigger backlog without a faster way to act on it. Harness's view is that this is the new baseline, and every enterprise needs to be ready. This means having the ability to scan, triage, and ship a fix at the same machine speed those models now operate at, rather than relying on a security process built for a slower era. "We're at a point where the same AI models helping our customers ship software faster are also what attackers are using to find and exploit vulnerabilities faster," said Jyoti Bansal, CEO and Co-Founder of Harness. "The only way to close that gap is to make security a first-class part of the delivery pipeline itself, so scanning, prioritization, remediation, and deployment all move together instead of getting stuck in handoffs between disconnected systems. That's the shift we built this launch around, and it's the same shift every enterprise is going to have to make to stay ahead." Launching agents across the vulnerability lifecycle. Today's announcement covers every stage a vulnerability moves through, from the moment it's found to the moment it's shielded in production, so no one slow step holds up the rest of the chain. Here's a look at what's shipping: Security Products & Services * AI SAST: A deterministic scanning engine paired with an AI layer that filters out noise, cutting false positives dramatically while catching issues, like missing authorization checks, that traditional tools miss entirely. * Claude Scan Orchestration: Teams that want to run their own Claude-based scanners can now do it natively inside their pipeline, with results feeding directly into the same triage and remediation workflow as everything else. * Triage Agent: Automatically sorts the flood of scanner findings down to what's actually exploitable, so teams can focus their time on real risk. * Remediation Agent: Writes and validates a fix for a prioritized finding and opens a pull request for a developer to review, pinpointing the exact vulnerable function so teams aren't wasting time on dependencies that were never actually reachable. * Zero-Day Agent: Monitors for newly disclosed zero-days around the clock, instantly identifies every affected system across a customer's environment, and has a validated fix ready for review, often within minutes of a threat going public. * Virtual Patching: Deploys a protective patch the moment a vulnerability is discovered during testing, no code changes required, shielding production immediately while the real fix is finished behind the scenes. "For customers, this means the distance between 'we found something' and 'it's fixed and deployed' shrinks from weeks to hours, without adding headcount or a new tool to manage," said Rahul Sood, GM of AppSec at Harness. "Every agent in this launch is built on the same reachability data, so teams aren't just moving faster, they're spending that speed on the vulnerabilities that actually matter instead of chasing noise." Business Operations Partnering with Anthropic's Claude. Harness's AI security capabilities, including AI SAST, the Zero-Day Agent, and the Triage and Remediation Agents, integrate Anthropic's Claude models among the large language models powering the platform. As part of today's launch, customers can also integrate findings from scanning their code with Claude directly into their Harness pipeline, bringing Claude-based scanning into the same triage and remediation workflow as everything else. "Claude reasons across a codebase the way a human researcher would, tracing how a vulnerability actually behaves in context," said [First Name Last Name], [Title], Cybersecurity, Anthropic. "Feeding those findings directly into Harness's pipeline means customers get the depth of an LLM-based scan without it becoming a separate process to manage on top of everything else." Extending Harness's AI security momentum. Harness has had sustained investment in AI-driven security since its merger with Traceable in early 2025. Today's announcement continues that trajectory, following the July 21 launch of Agent DLC, which brought governance and chain of custody to AI coding agents across the software delivery lifecycle. It's also the latest step alongside new integrations with Kong and Google, extending Harness's security and governance capabilities across a wider range of infrastructure and platform partners. Taken together, these efforts point to the same conclusion: as AI reshapes both software delivery and the threats against it, security has to be built into the platform itself. Harness plans to keep extending this work as the AI models on both sides of that equation keep getting more capable. Machine Learning & Artificial Intelligence