Application Security Engineer
United States · Remote
- Posted 1mo ago
- From Glean’s careers page
- Location
- United States
- Work mode
- Remote
- Experience
- 8+ years
- Department
- Information Technology
Opens the listing on job-boards.greenhouse.io
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.
About the role
About the Role:
Glean is looking for an experienced Application Security Engineer with a primary focus on ensuring that our entire technology stack is free of software vulnerabilities (CVEs). This role is responsible for securing our base OS images, ensuring all open-source software (OSS) dependencies are scanned and patched, and integrating cutting-edge security tools into our CI/CD pipeline. The ideal candidate will drive the adoption of solutions like Google’s Assured Open Source Software (OSS) and explore alternative approaches to enhance software security. This role will lead the vulnerability management charter at Glean, identifying, evaluating, and implementing new security technologies and processes to proactively protect our infrastructure.
You will:
- Own the vulnerability management lifecycle across Glean’s technology stack, from discovery and prioritization through remediation, reporting, and measurement.
- Harden base OS images and secure open-source dependencies, package managers, and the broader software supply chain.
- Integrate SAST, DAST, dependency scanning, and automated security validation into CI/CD pipelines.
- Evaluate, adopt, and develop security solutions and tooling, including Google’s Assured OSS and comparable approaches.
- Define secure-coding practices and drive engineering adoption through guidance, training, and mentorship.
About you:
- BA/BS in Computer Science, Cybersecurity, or a related field (or equivalent industry experience).
- 8+ years of experience in application security and vulnerability management.
- Deep understanding of software security vulnerabilities, including CVEs, OWASP Top 10, and supply chain risks.
- Experience with SAST, DAST, dependency scanning, and vulnerability management tools (e.g., Snyk, GitHub Dependabot, Trivy, Clair, Burp Suite, OWASP ZAP).
- Hands-on experience with cloud-native security across AWS, GCP, including containers, Kubernetes, and microservices.
- Ability to lead cross-functional initiatives and drive security adoption across engineering teams.
- Proactive, pragmatic, and collaborative, with strong problem-solving skills and the ability to balance security with performance and usability.
Skills they ask for
Pick one to see other roles that ask for it.
About Glean
Enterprise AI search and agentsGlean provides enterprise AI search, assistants, and agents that help employees find and use company information.
See all 111 roles at GleanMore roles at Glean
See all 111- Revenue AccountantBengaluru · Entry Level · HybridFinance and Accounting · Entry Level · HybridBengaluru, India2d
- Senior Data Engineer - Internal Data Platform & AnalyticsBengaluru · Senior · HybridData and Analytics · Senior · HybridBengaluru, India3d
- Software Engineer, Tech Lead, Admin ConsoleMountain View · Senior · HybridEngineering · Senior · HybridMountain View, United States3d
- Software Engineer, Tech Lead, Admin ConsoleSan Francisco · Senior · HybridEngineering · Senior · HybridSan Francisco, United States3d
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.