Application Security Engineer
Glean
Bangalore, IndiaPosted 3 months ago
Skill Required
EngineeringSecurity EngineerApplication DevelopersecurityPenetration Testingrelated fieldOWASPMicroservicesCybersecurityBurp SuiteKubernetesServiceNowEmbedded CTestNGPythondesignGitC++AzureCI/CDCloudJavaAPIsAWSGCPGenerative AIGo
Key highlights
- Hybrid role (3 days/week in Bangalore office)
- 3+ years of application security and vulnerability management experience required
- Eligible for variable compensation, equity, and benefits
- Focus on securing OSS dependencies and CI/CD pipeline integration
Role overview
Glean is the Work AI platform that helps enterprises work smarter with AI, offering intelligent Search, an AI Assistant, and scalable AI agents on a secure, open platform. The company is seeking an Application Security Engineer to ensure its technology stack is free of software vulnerabilities (CVEs), with a focus on securing base OS images, scanning and patching open-source software (OSS) dependencies, and integrating advanced security tools into the CI/CD pipeline. The role involves driving the adoption of solutions like Google’s Assured Open Source Software (OSS) and enhancing software security through collaboration with engineering teams.
Responsibilities
- Implement and improve the vulnerability management lifecycle, ensuring the entire tech stack is free from known vulnerabilities/CVEs.
- Continuously scan, monitor, and patch OSS dependencies to mitigate supply chain risks and enforce best practices for dependency management.
- Work closely with engineering teams to integrate state-of-the-art SAST, DAST, and dependency scanning tools into the CI/CD pipeline to detect and remediate vulnerabilities early.
- Define and maintain best practices for secure coding to ensure all code developed by Glean engineers is free from vulnerabilities.
- Ensure secure posture in SDLC by securing designs, conducting secure code reviews and penetration testing the features.
- Develop automated security validation tests to enforce vulnerability-free deployments across the stack.
- Lead the adoption and, if necessary, develop custom security solutions to manage and mitigate security risks at scale.
- Provide security guidance, training, and mentorship to engineering teams to foster a security-first culture at Glean.
Requirements
- BA/BS in Computer Science, Cybersecurity, or a related field (or equivalent industry experience).
- 3+ years of experience in application security and vulnerability management.
- Deep understanding of software security vulnerabilities, including CVEs, OWASP Top 10, and supply chain risks.
- Deep understanding security design principles including but not limited to authentication, authorisation, RBAC, database security.
- Experience with SAST, DAST, dependency scanning, and vulnerability management tools (e.g., Snyk, GitHub Dependabot, Trivy, Clair, Burp Suite, OWASP ZAP).
- Strong familiarity with package managers (npm, pip, Maven, Go modules) and securing open-source dependencies.
- Coding experience in languages such as Go, Python, Java, or C++ to develop security test cases and tooling.
- Hands-on experience with cloud-native security best practices across AWS, GCP, or Azure.
- Knowledge of container security, Kubernetes security, and securing microservices architectures.
- Ability to lead cross-functional initiatives and drive security adoption within engineering teams.
- A strong proactive approach to security, identifying risks before they become problems.
- Excellent problem-solving skills and the ability to balance security with performance and usability.
- Experience working in fast-paced, highly collaborative environments where security is a shared responsibility.
Nice to have
- Passion for open-source security and keeping up with the latest trends in software vulnerability management.
Benefits
- Compensation offered will be determined by factors such as location, level, job-related knowledge, skills, and experience. Certain roles may be eligible for variable compensation, equity, and benefits.
Additional details
- This role is hybrid (3 days a week in our Bangalore office).
- We are a diverse bunch of people and we want to continue to attract and retain a diverse range of people into our organization. We're committed to an inclusive and diverse company. We do not discriminate based on gender, ethnicity, sexual orientation, religion, civil or family status, age, disability, or race.
- At Glean, AI fluency is core to how we work and we're committed to ensuring every new hire feels confident integrating AI into their everyday work. As part of the interview process, you'll complete a brief AI-focused exercise or discussion so we can understand how you think about, design, and use AI to drive impact in your role. Feel free to reference any tools, platforms, or workflows you use today — prior Glean experience isn't required.
- Depending on your location, the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), or other privacy laws may regulate the way we manage the data of job applicants. Our full notice outlining how data will be processed as part of the application procedure for applicable locations is available in our Privacy Policy. By submitting your application, you are agreeing to our use and processing of your data as required. US applicants and their applications are subject to arbitration of disputes as outlined in our Applicant Arbitration Agreement.
- By clicking “Submit Application,” I confirm that I have read the Global Data Privacy Notice and the Applicant Arbitration Agreement, and I agree to the terms.