Application Security Engineer
$185k - $260k • Remote • United States, Remote
Posted 16d ago
Remote Work Policy
Fully remote
Categories
Applied AI Engineer
About the job
Glean is seeking an experienced Application Security Engineer to ensure the security of its technology stack by eliminating software vulnerabilities. This role will be responsible for securing base OS images, scanning and patching open-source software (OSS) dependencies, and integrating advanced security tools into the CI/CD pipeline. The ideal candidate will lead Glean's vulnerability management efforts, driving the adoption of solutions like Google's Assured Open Source Software (OSS) and exploring new technologies and processes to proactively protect the infrastructure.
Responsibilities
- Own the vulnerability management lifecycle, including discovery, prioritization, remediation, reporting, and measurement.
- Harden base OS images and secure open-source dependencies, package managers, and the software supply chain.
- Integrate SAST, DAST, dependency scanning, and automated security validation into CI/CD pipelines.
- Evaluate, adopt, and develop security solutions and tooling, such as Google's Assured OSS.
- Define secure-coding practices and promote engineering adoption through guidance, training, and mentorship.
Requirements
- BA/BS in Computer Science, Cybersecurity, or a related field, or equivalent industry experience.
- 8+ years of experience in application security and vulnerability management.
- Deep understanding of software security vulnerabilities, including CVEs and OWASP Top 10.
- Experience with vulnerability management tools and processes.
- Familiarity with cloud security best practices.
- Experience with CI/CD pipeline security integration.
- Knowledge of secure coding principles and practices.