The ITSPmagazine Podcast

Coding Is a Fraction of the Work. Harness Secures Everything After It. | A Brand Briefing at Black Hat USA 2026 with Rahul Sood, General Manager, Application Security at Harness | Hosted by Sean Martin

Episode Summary

AI is writing more code than ever, and almost none of the new constraint sits in the writing. Recorded on site at Black Hat USA 2026, this conversation looks at what happens to security, policy, and release velocity in the 70 to 80 percent of the life cycle that comes after the code exists.

Episode Notes

Rahul Sood has run the application security business at Harness for almost a year. He describes application security as one of the core pillars of the company, part of a vision of building a DevSecOps platform. A year ago Harness publicly announced that security accounted for a quarter of its revenue. Sood says the figure is now considerably higher.

The company did not start there. Founder Jyoti Bansal thought about Harness for a decade before founding it, Sood says, after seeing the problem inside one of the largest banks. Harness launched as a DevOps platform, then merged with an API security company Bansal had also funded. The result is a platform that treats security as part of the developer workflow rather than a bolt-on, and covers it from code all the way to runtime.

What changes when security lives inside the developer workflow? Developers stop leaving their own tools to chase findings. Harness aggregates results across scanners, deduplicates them, and puts remediation, assignment, and exemption requests in one place. Security teams get the other half of the picture through a policy engine that shows which policies fire on every build, which ones break a build, and where a developer asked for an exception, with a full audit trail behind it.

Where is the bottleneck now that AI writes the code? It moved downstream. Sood says nearly every development team is generating more code with AI, while the volume actually reaching users has not risen at the same rate. By his estimate coding is 20 to 30 percent of the software development life cycle, and the remaining 70 to 80 percent happens after the code is written.

That includes agents. Harness has extended the platform to support the Agent DLC, with native capabilities for AI evaluation and prompt testing alongside security coverage for agents from code to runtime. Sood points to two differences. The span from code to runtime covers agents while they are built and while they run, and skill scanning and prompt scanning were added to the same scanner already looking for code vulnerabilities rather than shipped as another tool to buy.

The operational payoff shows up in release cadence. Sood describes a tier one US bank that maintained 150 separate policies and convened a team to confirm each one had been met before it could launch its banking app. Automating that review removed the meeting, and the bank now runs multiple launches within weeks. With 80 to 90 percent of software now assembled from third-party packages, libraries, and open source components, the same policy engine can block any build that pulls in a package which is end of life or malicious.

This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing

GUEST

Rahul Sood, General Manager, Application Security at Harness
On LinkedIn: https://www.linkedin.com/in/rssoods/

RESOURCES

Black Hat USA 2026 event coverage from ITSPmagazine: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas
Harness: https://www.harness.io/
Harness customer case studies: https://www.harness.io/customers
Securing the Agent DLC, by Rahul Sood: https://www.harness.io/blog/securing-the-agent-dlc
Harness AI Security: https://www.harness.io/products/ai-security
Harness Application Security Testing: https://www.harness.io/products/application-security-testing

Are you interested in telling your story?
▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full
▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight
▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight
▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings

KEYWORDS

rahul sood, harness, sean martin, brand briefing, brand story, brand marketing, marketing podcast, black hat usa 2026, application security, devsecops, agent dlc, ai security, api security, policy engine, software supply chain, open source risk, prompt scanning, skill scanning, code to runtime, developer experience, release velocity

Episode Transcription

Coding Is a Fraction of the Work. Harness Secures Everything After It. | A Brand Briefing at Black Hat USA 2026 with Rahul Sood, General Manager, Application Security at Harness | Hosted by Sean Martin


 

[00:00:00] Sean Martin:

Roll. Here we are. The Harness booth. It's pretty impressive, my friend. Yeah. And I have to thank you for the, uh, the cushion floor. Not every booth has the cushion floor. It's nice to be standing on there.


 

[00:00:24] Rahul Sood:

We take care of our people.


 

[00:00:25] Sean Martin:

Yeah, that's good. That's good. And your customers actually think as well. We're gonna get into, um, let's start off with a few words about your role at Harness. Maybe what led you to the role, and then we'll talk about what the company's up to.


 

[00:00:41] Rahul Sood:

Um. So I've been in this role now for almost a year. Okay. I run our application security business, um, and, you know, application security is one of the core pillars for Harness, um, as part of a vision of building a DevSecOps platform. Um, just to give you a sense, a year ago we publicly announced that security was a quarter of our revenue. And I can only say it's now much higher. Right.


 

[00:01:09] Sean Martin:

No announcements today.


 

[00:01:10] Rahul Sood:

Not yet.


 

[00:01:11] Sean Martin:

No. Pull out, no announcements. But you did get


 

[00:01:15] Rahul Sood:

Yeah, but we an


 

[00:01:16] Sean Martin:

award,


 

[00:01:16] Rahul Sood:

which is really


 

[00:01:16] Sean Martin:

cool. What is


 

[00:01:17] Rahul Sood:

this? We got a leader award.


 

[00:01:19] Sean Martin:

Okay.


 

[00:01:19] Rahul Sood:

This is for the best and the most accurate, uh, detection for API threats.


 

[00:01:27] Sean Martin:

Okay.


 

[00:01:27] Rahul Sood:

And the reason that's very important is if you've been tracking what's happened in the last few days, we've, OpenAI and Hugging Face and, you know, Anthropic. As I said, agents are gonna be agents. There are agents now running in the wire, right? So as companies, you have to protect not just the agents you build, but you have to protect yourself from the agents in the wire. And that's what this award shows, that we are the best at it.


 

[00:01:54] Sean Martin:

Nice. Congratulations on that.


 

[00:01:55] Rahul Sood:

Thank you. No, we are very excited about


 

[00:01:57] Sean Martin:

it. It's a good looking award too. Nice color. It


 

[00:02:00] Rahul Sood:

matches, it matches the Harness blue.


 

[00:02:01] Sean Martin:

Purposeful or not, but


 

[00:02:02] Rahul Sood:

yes,


 

[00:02:02] Sean Martin:

take it.


 

[00:02:03] Rahul Sood:

Yes.


 

[00:02:03] Sean Martin:

Alright. So tell me a little bit about the company. So rooted in DevOps, which is important, right? Bring in products to, to market and to life in an organization. Uh, switch to DevSecOps. So kind of paint that picture for me.


 

[00:02:21] Rahul Sood:

So, um, our founder is Jyoti Bansal. As Jyoti likes to say, he thought about this company 10 years before he founded it. He saw this problem at one of the largest banks and uh, you know, he realized that one of the biggest challenges that, um, most organizations have as they start developing software is how do you ship your software quickly and securely? So that was his motivation of starting Harness as a DevOps platform. As the company gained momentum and we started serving some of the largest companies, he realized security was a really critical part of it. And that's when he brought in security and, you know, just coincidentally he had funded another security company. Okay. Focused on API security. So he merged the two companies to build, uh, you know, a DevSecOps platform. And, uh, what is truly unique about us is security is not a bolt-on. It is really part of the developer workflow and native in the. And the other thing which is unique about us is we view security all the way from code to runtime. And that is special because, you know, most names that you've heard of are either focused on the code or the build time. Or focus on the runtime.


 

[00:03:43] Sean Martin:

Yeah.


 

[00:03:43] Rahul Sood:

We bring the two together into a unified view.


 

[00:03:46] Sean Martin:

So talk to me about the, the developer experience first off, um, because I know there's, you can educate and. Can you give them examples? Kind of talk about how they work within the Harness environment and how you help them actually deliver the security killer.


 

[00:04:06] Rahul Sood:

So the problem with security for the longest time has been, you know, security is seen as a toil in the developer, right? It is something that blocks them from launching, moving fast. It also requires them to then go and chase lots of different things and move from their preferred tool to a security tool and, you know, understand the new context, and that's always somewhat irritating and slows things down. With Harness security is part of the developer workflow. We give you all of the context of security vulnerabilities right there. We aggregate them across all your different scanners. We do dedupe them so you're not seeing duplicates, and then we really help you manage the workflow of remediating those, right? So a lot of companies, you know, some of the largest banks are able to automate hundreds of policies, which were manual earlier and make it now part of the tool.


 

[00:05:06] Sean Martin:

Alright, so tell me about the, the experience that developer has as their work and actually deliver and shape their code.


 

[00:05:13] Rahul Sood:

So security and developers have always had friction and that friction is partly caused by the fact that they live in two different tools. Security teams live in scanning and security tools and developers live in, you know, IDEs and, uh, you know, and they're sort of managing pipelines and buildings, uh, uh, you know, pipelines and, and artifacts. So bringing these two things together is one of the things that we did really well. So as a developer, you get all the vulnerability findings with all of the context, with the prioritization, all as part of a single tool. Right. And you can then run the entire workflow of assigning different vulnerabilities to the different team members. If you need an exemption, you can ask for an exemption. And all of that is there both for the developer and the, and the security professional. And that's one of the things that, um, really is driving, you know, our momentum. Because we are able to bring security and developers on the same page.


 

[00:06:14] Sean Martin:

So what's the experience for the security team then? Because do they have visibility into the whole picture and actually when they get that exception request, know what, what it means.


 

[00:06:24] Rahul Sood:

So the, you know, the biggest challenge for security teams is they come up with all of these policies and requirements and. Wow. But then they have no way of knowing which of these are being met because most of them are, some of them are manual. Some of them may be in one tool, other, another tool. With us, all of them get consolidated, and you can really bake it as part of our policy engine so you know exactly what is happening with every build that is happening in your company. Which policies are being triggered? Which policies are breaking your build? Where did the developer need an exception? And all of that is really part of one environment with full audit trails.


 

[00:07:04] Sean Martin:

And I'm gonna guess not just security, right? The policy can be many things.


 

[00:07:10] Rahul Sood:

Yeah. So the policies, yeah, that's absolutely right. The policy can be security, it can be compliance,


 

[00:07:16] Sean Martin:

right?


 

[00:07:16] Rahul Sood:

Uh, you know, it can, uh, it can even be, uh, I'm trying to think if there's something which is, uh, different than security and compliance. Well,


 

[00:07:25] Sean Martin:

just general quality of assurance,


 

[00:07:27] Rahul Sood:

right? It could be code reviews, it could be quality, it could be lots of different things, and all of them are treated the same way.


 

[00:07:33] Sean Martin:

Okay. Very cool. So obviously developers are being asked to do more faster. Where do they turn to do that? AI perhaps. Um, so what does that world look like, um, for them? Working with you.


 

[00:07:53] Rahul Sood:

So, um, clearly, you know, almost every development team right now in the world is using AI. The amount of code that they're generating is, is definitely increasing. The problem however, is the, the amount of code that is being delivered out to the, to the customer or the user is actually not increasing that much. The reason for that is the bottleneck in the system has just shifted. Okay. Earlier the bottleneck was the code you could write. That is no longer the bottleneck. Now the bottleneck is all this code that is being written. How do you make sure it is secure? How do you test for it? How do you deploy it? And you know, how do you do that with all of the governance and compliance that you need? That's the problem Harness is really trying to solve. So we like to call ourselves, we are AI for everything after the code has been written, because the entire SDLC, coding is only 20 to 30% of it. 70 to 80% of the software development life cycle happens after the code is written.


 

[00:08:52] Sean Martin:

So you, you've been, uh, innovating, I think here at Black Hat or just recently you launched some new things. So tell me a little bit about that.


 

[00:09:00] Rahul Sood:

So, um, you know, the nature of software constantly evolves, right? You know, at one time it was monocode, then became, you know, microservices based. And what's happened in the last six to nine to 12 months is a lot of the applications that are written are AI applications or agents.


 

[00:09:17] Sean Martin:

Okay,


 

[00:09:18] Rahul Sood:

we have now extended the Harness platform to support Agent DLC. Okay. So if you're writing agents, um, you know, now the platform provides you native capabilities, uh, things like, you know, how do you do AI eval? How do you evaluate your, the agents so that, uh, you know, you know that they will reason the right way, um, or how do you test for them so that you know the prompts are the right prompts before you roll them out. And as part of that, we rolled out a full, you know, security experience. So how do you make sure your agents are secure from code to runtime? Now, you know, at Black Hat, every security company's talking about that


 

[00:10:00] Sean Martin:

of course, but you're different.


 

[00:10:04] Rahul Sood:

You got it. Right. So there are two things that are unique about us. I think one is this, uh, the approach of code to runtime. So what that means is we secure your agents while they're being developed, you know, the industry likes to use the word shift left for that. Right? And we secure your code when they're, uh, operating and running. That's the industry likes to call it shield, right?


 

[00:10:28] Sean Martin:

Does it matter where,


 

[00:10:30] Rahul Sood:

uh, it doesn't matter where you run it, we will still, you know, protect it. So we bring these two things together. The other thing which is unique is everyone that is talking about agent security has a new tool. They have a new widget that they're asking you to buy. We have fundamentally believed that platforms should be able to support multiple use cases. So we've just extended our existing platform to support agents. Okay? So I'll give you an example of that,


 

[00:10:55] Sean Martin:

please.


 

[00:10:56] Rahul Sood:

You know, you scan your code for vulnerabilities, right? We just added skill scanning. And prompt scanning is part of that,


 

[00:11:06] Sean Martin:

okay?


 

[00:11:06] Rahul Sood:

So you understand, you know, where you have prompts and you know what your exposure is and what the risk is. It's the same tool that does scanning for code vulnerabilities that is now scanning for AI risks.


 

[00:11:17] Sean Martin:

So the ultimate goal is to get the product out there. I mean, that's the developers want their stuff out, the business wants, whether it's internal users or customers to have their code delivered. Secure. Yes. So what are some examples of customers where they're able to do that with a higher level of confidence or some other outcome that. It was not possible.


 

[00:11:42] Rahul Sood:

You know, I would say each one of Harness's thousand customers I've seen increase in velocity. And I'll give you, uh, one of the largest tier one US banks. Um, they had 150 different policies. Um, they had to bring an entire team together to review whether all of those 150 policies had been adhered to before they could do a launch of, let's say, even their, you know, banking app for


 

[00:12:09] Sean Martin:

your phone, right.


 

[00:12:10] Rahul Sood:

By automating all of that, they now don't need to, you know, bring all of these people together. They're able to do launches within weeks, multiple launches within weeks. And, you know, they're able to do that with the confidence that they're meeting all of their compliance requirements and policy requirements. So that's just one example. But, you know, um, if you go to the Harness website,


 

[00:12:31] Sean Martin:

a lot of case studies,


 

[00:12:32] Rahul Sood:

we just have tons of case studies because this is the core use case and this is the way we, we justify to our customers the investment in the Harness platform.


 

[00:12:42] Sean Martin:

So, so clearly they're, I'm gonna use the policy thing as an example and maybe expand on that a little bit more, 'cause policies, that's an internal view, sometimes it's an external. What are the policies you're running to adhere to a HIPAA or adhere to SOC, whatever. So visibility into what you did, proof that you did it. Um, tell me a little bit about that in terms of how. How you can offer it.


 

[00:13:07] Rahul Sood:

So, you know, um, I'll give you a very simple example right now, which is very, um, topical, right? Um, since the launch, uh, of, you know, uh, of, uh, Mythos and some of the frontier, um, models, one of the big risks is there'll be a lot of new vulnerabilities that we discovered in all the third party packages and open source, um, software, which is, which all of us use in a very, very, you know, big way. Um, so, you know, you can have a simple policy which says. Um, if the open source package or third party package that is part of this build is end of life or malicious, um, or, uh, you know, uh, does not meet some of your requirements, you just block the build, right? So no matter what the developer's doing, it'll not go into the, you know, into the pipeline if it does not meet that requirement. So that's a very simple example. Yeah. But, you know, very powerful example because. One of the big problems security teams have right now is how do you govern the packages that are being used? Because you know, 80%, 90% of the software is now third, third party packages, libraries, open source components you're using.


 

[00:14:20] Sean Martin:

Oh, so good to have this chat with you. I'm gonna give you a final word to, let's say, security team leaders, how they can connect with you, what they can expect. And they're working with the Harness team. Um,


 

[00:14:37] Rahul Sood:

you know, for security professionals, as I said, one of the biggest challenges is how do you really get developers, um, to, you know, to adopt the right practices, the right policies. And, you know, one of the things that Harness really offers is we are a friend, um, that really brings, uh, security and DevOps on the same page. So, you know, if you're a security professional and you're challenged with. Um. Uh, you know, how do you make sure your, uh, your security practices are really being, uh, adopted. That's one. Second are, uh, state of the art so that you are ready for, for the AI era. Uh, you know, those are two really good reasons for you to reach out.


 

[00:15:20] Sean Martin:

Appreciate it.


 

[00:15:21] Rahul Sood:

Thank


 

[00:15:21] Sean Martin:

you. Keep up the good.


 

[00:15:22] Rahul Sood:

Thank you so much


 

[00:15:23] Sean Martin:

and everybody listening, watching, connect with Rahul and the Harness team, harness.io.


 

[00:15:28] Rahul Sood:

That's right.


 

[00:15:28] Sean Martin:

And, uh, continue your own transition from DevOps to DevSecOps and have security and dev work together for, for a change. Alright, thanks everybody. Thank you.