Glean
Application Security Engineer
About this role
Glean seeks an Application Security Engineer to lead vulnerability management across their entire technology stack, focusing on eliminating CVEs through secure OS hardening, OSS dependency scanning, and CI/CD security tooling integration. You'll drive proactive vulnerability remediation and evaluate cutting-edge security solutions to protect their enterprise Work AI platform.
What you'll do
- Lead vulnerability management lifecycle and ensure the entire tech stack remains free from known CVEs
- Implement and maintain hardened, secure base OS images across infrastructure
- Continuously scan, monitor, and patch open-source software dependencies to mitigate supply chain risks
- Integrate SAST, DAST, and dependency scanning tools into CI/CD pipelines for early vulnerability detection
- Research and evaluate security solutions like Google's Assured Open Source Software for adoption
- Collaborate with engineering teams to establish and enforce security best practices for dependency management
What they're looking for
- Application security and vulnerability management
- SAST/DAST tool implementation and integration
- Open-source software supply chain security
- CI/CD pipeline security integration
- OS hardening and base image configuration
- Dependency scanning and software composition analysis
- Security policy development and enforcement
- Kubernetes and container security (implied by enterprise scale)
Opens the application — the Jobs AI extension fills it for you. Set up autofill
Opens the official application on the employer’s site. No login required.
Glean
Glean builds a Work AI platform that helps enterprises access and leverage their internal data intelligently. The company is hiring backend engineers, infrastructure specialists, fullstack engineers, and billing platform leads to develop scalable features, robust data infrastructure, consumption-based billing systems, and enterprise-grade storage and analytics capabilities.
- Website
- glean.com
Likely interview questions
- Walk us through your approach to establishing a comprehensive vulnerability management program from scratch.
- Describe your experience integrating security scanning tools into CI/CD pipelines and handling false positives.