Why This Role Stands Out
As an Application Security Engineer at Glean, you'll join a rapidly growing, award-winning AI company and play a vital role in safeguarding their innovative Work AI platform. This remote position offers significant opportunities for skill development and impact within a dynamic team, so we encourage you to apply.
Quick Overview
Job Description
About the Role:
Glean is looking for an experienced Application Security Engineer with a primary focus on ensuring that our entire technology stack is free of software vulnerabilities (CVEs). This role is responsible for securing our base OS images, ensuring all open-source software (OSS) dependencies are scanned and patched, and integrating cutting-edge security tools into our CI/CD pipeline. The ideal candidate will drive the adoption of solutions like Google’s Assured Open Source Software (OSS) and explore alternative approaches to enhance software security. This role will lead the vulnerability management charter at Glean, identifying, evaluating, and implementing new security technologies and processes to proactively protect our infrastructure.
You will:
- Own the vulnerability management lifecycle across Glean’s technology stack, from discovery and prioritization through remediation, reporting, and measurement.
-
Harden base OS images and secure open-source dependencies, package managers, and the broader software supply chain.
-
Integrate SAST, DAST, dependency scanning, and automated security validation into CI/CD pipelines.
-
Evaluate, adopt, and develop security solutions and tooling, including Google’s Assured OSS and comparable approaches.
-
Define secure-coding practices and drive engineering adoption through guidance, training, and mentorship.
About you:
- BA/BS in Computer Science, Cybersecurity, or a related field (or equivalent industry experience).
- 8+ years of experience in application security and vulnerability management.
- Deep understanding of software security vulnerabilities, including CVEs, OWASP Top 10, and supply chain risks.
- Experience with SAST, DAST, dependency scanning, and vulnerability management tools (e.g., Snyk, GitHub Dependabot, Trivy, Clair, Burp Suite, OWASP ZAP).
- Hands-on experience with cloud-native security across AWS, GCP, including containers, Kubernetes, and microservices.
- Ability to lead cross-functional initiatives and drive security adoption across engineering teams.
- Proactive, pragmatic, and collaborative, with strong problem-solving skills and the ability to balance security with performance and usability.
Location:
- This role is remote
Compensation & Benefits:
The standard base salary range for this position is $185,000 - $260,000 annually. Compensation offered will be determined by factors such as location, level, job-related knowledge, skills, and experience. Certain roles may be eligible for variable compensation, equity, and benefits.
By clicking “Submit Application,” I confirm that I have read the Global Data Privacy Notice and the Applicant Arbitration Agreement, and I agree to the terms.
Similar jobs
- SP
Infrastructure Security Engineer (Bare Metal & Platform)
NewAuto ApplySpaceXAI
Palo Alto🇺🇸Hybrid6 hours agoOpenStackPCI DSSSAML+19Technology - TC
Engineering, Cybersecurity, Application Security Engineer, Vice President
NewAuto ApplyTPG Careers Page
Fort Worth🇺🇸Hybrid11 hours agoGCPAWSOAuth+16Technology - PG
Senior Game Application Security Analyst
NewAuto ApplyPlayStation Global
United States🇺🇸Remote9 hours agoSQLSnowflakeTableau+3Technology - AR
Member of Security Staff, IT Engineer
NewAuto ApplyArena
SF Bay Area🇺🇸On-site9 hours agoGCPAWSMFA+11Technology - LA
Senior Manager, Security
NewAuto ApplyLaunchDarkly
Remote - US West🇺🇸Remote14 hours agoAWSSOC 2Mental Health+1 - FL
Senior IT & Security Operations Engineer
NewAuto ApplyFloatme
San Antonio🇺🇸Hybrid15 hours agoAWSSOC 2SSO+10Technology - HU
Principal macOS Security Researcher
NewAuto ApplyHuntress
United States🇺🇸Hybrid13 hours agoRubySwiftData Privacy+3 - DE
Staff Security Engineer
NewAuto ApplyDelinea
U.S. Remote🇺🇸Remote11 hours agoDockerAWSAzure+7Technology - CA
GRC Engineer
NewAuto ApplyCape
Hybrid🇺🇸Hybrid10 hours agoGCPAWSSOC 2+8Engineering - FS
Senior Engineer - Penetration Testing
NewAuto ApplyFinite State
United States or Canada🇺🇸Hybrid14 hours ago5GAWSEmbedded Systems+16Technology - CO
Senior Security Engineer, Networking
NewAuto ApplyCoreWeave
Livingston🇺🇸Hybrid13 hours agoGCPSpringAWS+7Technology - CO
Senior Security Engineer, Vulnerability Management
NewAuto ApplyCoreWeave
Livingston🇺🇸Hybrid15 hours agoRustSpringCompliance+6Technology