Skip to main content
Glean

Application Security Engineer

RemoteUnited States only
Published
Role
Fullstack
Experience
Mid
Employment
Full-time
$185k–$260k/yr
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

Glean is looking for an experienced Application Security Engineer with a primary focus on ensuring that our entire technology stack is free of software vulnerabilities (CVEs). This role is responsible for securing our base OS images, ensuring all open-source software (OSS) dependencies are scanned and patched, and integrating cutting-edge security tools into our CI/CD pipeline.

Core skills

SAST/DAST/dependency scanning/vulnerability management tools

Required skills

Snyk/GitHub Dependabot/Trivy/Clair/Burp Suite/OWASP ZAPAWS/GCP/containers/Kubernetes/microservices

What you'll do

  • Own the vulnerability management lifecycle across Glean’s technology stack, from discovery and prioritization through remediation, reporting, and measurement.
  • Harden base OS images and secure open-source dependencies, package managers, and the broader software supply chain.
  • Integrate SAST, DAST, dependency scanning, and automated security validation into CI/CD pipelines.
  • Evaluate, adopt, and develop security solutions and tooling, including Google’s Assured OSS and comparable approaches.
  • Define secure-coding practices and drive engineering adoption through guidance, training, and mentorship.

What they require

  • BA/BS in Computer Science, Cybersecurity, or a related field (or equivalent industry experience).
  • 8+ years of experience in application security and vulnerability management.
  • Deep understanding of software security vulnerabilities, including CVEs, OWASP Top 10, and supply chain risks.
  • Experience with SAST, DAST, dependency scanning, and vulnerability management tools (e.g., Snyk, GitHub Dependabot, Trivy, Clair, Burp Suite, OWASP ZAP).
  • Hands-on experience with cloud-native security across AWS, GCP, including containers, Kubernetes, and microservices.
  • Ability to lead cross-functional initiatives and drive security adoption across engineering teams.
  • Proactive, pragmatic, and collaborative, with strong problem-solving skills and the ability to balance security with performance and usability.

Benefits

  • Competitive compensation
  • Medical, Vision, and Dental coverage
  • Generous time-off policy
  • Opportunity to contribute to your 401k plan
  • Home office improvement stipend
  • Annual education and wellness stipends
  • Regular events
  • Healthy lunches daily
TechnologyEnterprise
$185k–$260k/yr