Back to all positions

Member of Technical Staff (MTS)

Remote (US) or Hybrid (SF Bay Area)
Full-time
$120,000–$200,000 + equity

About Us

Harden is the enterprise security and governance platform for AI-built apps. Every AI-generated application ships with the same gaps — hardcoded secrets, missing auth, uncontrolled egress, no audit trail. Harden closes them automatically: build-time SAST and SCA scanning with auto-remediation, a one-page approval report that gates CI/CD, and runtime enforcement that covers egress controls, prompt-injection defense, AI cost caps, and tamper-evident audit logs — all deployed inside the customer's own cloud. We're a venture-backed startup based in the SF Bay Area. The founding team combines AI/ML research leadership at Google DeepMind and Amazon with product leadership at Verkada and AWS. Enterprise customers are already in production and we're bringing on exceptional engineers to build the infrastructure that makes enterprise AI adoption safe and scalable.

About the Role

Build production-grade security services for Harden's BYOC runtime. You'll implement row-level security, policy engines, and SBOM pipelines that protect enterprise deployments. This role is a blend of backend engineering and security, where you'll own the systems that make AI-generated code safe for production — from container isolation and zero-trust networking to audit logging and compliance automation.

What You'll Do

  • Build production security services for Harden's BYOC runtime
  • Implement row-level security, ABAC, and policy engines
  • Develop SBOM generation and dependency scanning pipelines
  • Write robust APIs for control plane and customer dashboards
  • Own SLOs for latency, throughput, and availability
  • Partner on observability and incident response
  • Contribute to security hardening: container isolation, zero-trust networking

What We're Looking For

  • 3+ years building backend services at production scale
  • Experience with security concepts: RBAC/ABAC, encryption, mTLS
  • Strong database skills: PostgreSQL, Redis, query optimization
  • API design: REST, GraphQL, OpenAPI
  • Cloud experience: AWS (VPC, IAM, ECS/EKS), GCP, or Azure
  • Linux/containers: Docker, Kubernetes, networking

Nice to Have

  • Background in security or compliance (SOC2, HIPAA)
  • Authorization systems: OIDC, Open Policy Agent
  • Observability tools: OpenTelemetry, Datadog
  • Security open source contributions

Apply for this Position

1
Personal Info
2
Experience
3
Documents
4
Review