Supply Chain Security Engineer

Bangalore, India

Posted 16d ago

Job Location

Bangalore, India

Tech Stack

Remote Work Policy

On-site

Categories

Applied AI Engineer

About the job

Glean is seeking a Supply Chain Security Engineer to ensure the security of our technology stack by eliminating software vulnerabilities (CVEs). This role involves securing base OS images, scanning and patching open-source software (OSS) dependencies, and integrating advanced security tools into our CI/CD pipeline. You will be instrumental in building and executing our software supply chain security strategy, enhancing vulnerability scoring, and reducing the overall vulnerability footprint across various programming ecosystems and base layers. The position also includes creating hardened images, leading initiatives like SBOM generation and automated fix pipelines, and developing policy-driven controls for build provenance and trust verification. Additionally, you will manage secure software supply chain guidelines and documentation, and contribute to achieving FEDRAMP readiness for vulnerability management.

Responsibilities

  • Implement and improve the vulnerability management lifecycle to eliminate known vulnerabilities/CVEs across the tech stack.
  • Continuously scan, monitor, and patch OSS dependencies to mitigate supply chain risks and enforce best practices for dependency management.
  • Build and execute the software supply chain security strategy to enable secure-by-default open-source artifact deployment.
  • Improve the supply chain vulnerability scoring mechanism by considering environmental controls and reachability factors.
  • Research methods to reduce the supply chain vulnerability footprint across Python, Java, GO, npm ecosystems, and base layers.
  • Create hardened OS images for use across multiple deployment stacks.
  • Lead and contribute to Software Supply Chain Security initiatives, including SBOM generation/consumption, vulnerability prioritization, automated fix pipelines, build provenance, artifact signing, and trusted release workflows.
  • Design automation and policy-driven controls to verify build origins, provenance, and trustworthiness before deployment.
  • Develop and manage secure software supply chain usage guidelines and documentation.
  • Contribute to achieving FEDRAMP readiness concerning vulnerability management.

Requirements

  • BA/BS in Computer Science, Cybersecurity, or related field, or equivalent industry experience.
  • 3+ years of experience in application security and vulnerability management.
  • Deep understanding of software security vulnerabilities (CVEs, OWASP Top 10, supply chain risks).
  • Deep understanding of security design principles (authentication, authorization, RBAC, database security).
  • Strong understanding of software supply chain components, management, threats, and vulnerabilities.
  • Familiarity with package managers (npm, pip, Maven, Go modules) and securing open-source dependencies.
  • Coding experience in languages such as Go, Python, Java, or C++ for developing security tooling.
  • Hands-on experience with cloud-native security best practices on AWS, GCP, or Azure.
  • Experience with FEDRAMP audit cycles for vulnerability management.
  • Knowledge of container security, Kubernetes security, and securing microservices architectures.
  • Ability to lead cross-functional initiatives and drive security adoption within engineering teams.

Get new AI jobs in your inbox

A weekly digest of the newest AI engineering roles.

© 2026 AI Job Board. All rights reserved.