AI is being run everywhere, by humans and agents. Harmonic Security governs all of it. The AI Governance and Control (AIGC) platform understands user / agent intent and data context in real time, giving security teams visibility and control across every tool and workflow so companies can move faster with AI while minimizing risk. We operate in one of the fastest-moving spaces in tech: the emerging intersection of AI and cybersecurity. It's a market still being defined, and we're among the first to build natively for it - protecting sensitive data in real time, at the endpoint, with minimal friction for the teams using it. Enterprises get full visibility and control. Their people get to innovate without guardrails slowing them down. Named to the Rising in Cyber 2026 list, Harmonic is gaining serious recognition and serious traction. We're led by deep cybersecurity expertise and backed by investors who know the space: N47, Ten Eleven Ventures, and In-Q-Tel. As AI adoption inside the enterprise accelerates, the ability to safely observe, control, and enforce policy in real time isn't a nice-to-have. It's mission-critical infrastructure. That's what we build. HOW WE WORK: AI-FIRST BY DESIGN Harmonic exists to help enterprises adopt AI safely and at scale. We hold ourselves to that same standard. Everyone here actively leverages AI tools to perform their best work — from deep research and writing to building robust processes and automating complex workflows. We expect every new hire to bring a genuine curiosity for AI and a commitment to using it to work smarter, faster, and with greater creativity. For some, this involves tinkering and remaining open to emerging tools; for others, it means architecting entirely new systems with AI at the core. We will be transparent about expectations for every role and provide the tools and support needed for you to thrive. ABOUT THE TEAM We sell security to some of the most demanding enterprise security teams in the world, and we've held ourselves to that bar from day one. Our engineers have already built a platform architecture we're genuinely proud of - strong foundations across authentication, data isolation, and secrets handling - but it's been built by generalist engineers who split their time across security and everything else on the roadmap. It's good precisely because good engineers cared about it, not because it had a specialist behind it. Now we want to bring in someone whose full-time focus is security architecture, to take that foundation and push it further than a generalist team has the bandwidth to. This isn't an audit or compliance function, and it's not a rescue mission. It's an engineering one, building on top of something solid rather than starting from zero. ABOUT THE ROLE We're looking for a Senior Product Security Engineer to become the authority on our platform's security architecture - and to write the code that embodies it. You'll inherit a platform where the fundamentals of authentication and authorization, secrets and key management, encryption, and multi-tenant data isolation are already in decent shape, and your job is to sharpen, harden, and evolve them with the depth a dedicated specialist brings that a generalist team can't. Once you set a standard, the rest of engineering builds to it - that's a formal mandate, not a suggestion. You'll spend the majority of your time writing production code, not producing reports on someone else's. This is deliberately not a role for someone who wants to sit on a security team finding holes in what other people have already shipped. We want someone who'd rather build the fix into the architecture in the first place - hands-on, opinionated, and accountable for the outcome. WHAT YOU'LL DO - Take formal ownership of Harmonic's platform security architecture - authentication and authorization, secrets and key management, encryption at rest and in transit, and multi-tenant data isolation - and evolve it beyond what a generalist engineering team has had the focus to do - Write production code that directly hardens and extends these patterns in our core platform, not just documentation describing them - Set security engineering standards for the wider engineering team, and have the mandate to enforce them - this isn't advisory - Manage your own backlog of platform security improvements, prioritized independently of the product roadmap - Run threat modeling and architecture reviews on major new systems and integrations before they ship, so security is designed in rather than retrofitted - Partner directly with engineering leads to embed the right patterns at design time, and support them in meeting the standards you set - Keep our own security posture ahead of what our most demanding enterprise customers and their security teams expect from us - Stay current on the threat landscape relevant to AI agent security, sensitive data handling, and multi-tenant SaaS platforms WHAT YOU BRING - 6+ years of hands-on software engineering experience, with deep specialization in security architecture rather than general backend development - Proven track record designing and personally implementing platform-level security controls in production - OAuth/OIDC/SAML, encryption, secrets and key management, multi-tenant isolation - Strong grounding in threat modeling and secure-by-design principles, applied to real architectural decisions rather than theoretical frameworks - Comfort setting technical standards that other engineers are expected to follow, with the communication skill to bring people along rather than dictate from a distance - Experience with cloud security fundamentals (AWS, GCP, or Azure) - IAM, network security, container and Kubernetes security - A track record of shipping secure, reliable, production-grade code, not just reviewing or auditing someone else's YOU MIGHT BE A FIT IF YOU - Have built or hardened platform-level security in