Security Engineer, Application Security
full-time
senior
Posted 1 year ago
About this role
About Glean:
Glean is the Work AI platform that helps everyone work smarter with AI. What began as the industry’s most advanced enterprise search has evolved into a full-scale Work AI ecosystem, powering intelligent Search, an AI Assistant, and scalable AI agents on one secure, open platform. With over 100 enterprise SaaS connectors, flexible LLM choice, and robust APIs, Glean gives organizations the infrastructure to govern, scale, and customize AI across their entire business - without vendor lock-in or costly implementation cycles.
At its core, Glean is redefining how enterprises find, use, and act on knowledge. Its Enterprise Graph and Personal Knowledge Graph map the relationships between people, content, and activity, delivering deeply personalized, context-aware responses for every employee. This foundation powers Glean’s agentic capabilities - AI agents that automate real work across teams by accessing the industry’s broadest range of data: enterprise and world, structured and unstructured, historical and real-time. The result: measurable business impact through faster onboarding, hours of productivity gained each week, and smarter, safer decisions at every level.
Recognized by Fast Company as one of the World’s Most Innovative Companies (Top 10, 2025), by CNBC’s Disruptor 50, Bloomberg’s AI Startups to Watch (2026), Forbes AI 50, and Gartner’s Tech Innovators in Agentic AI, Glean continues to accelerate its global impact. With customers across 50+ industries and 1,000+ employees in more than 25 countries, we’re helping the world’s largest organizations make every employee AI-fluent, and turning the superintelligent enterprise from concept into reality.
If you’re excited to shape how the world works, you’ll help build systems used daily across Microsoft Teams, Zoom, ServiceNow, Zendesk, GitHub, and many more - deeply embedded where people get things done. You’ll ship agentic capabilities on an open, extensible stack, with the craft and care required for enterprise trust, as we bring Work AI to every employee, in every company.
About the Role:
Glean is looking for an experienced Application Security Engineer with a primary focus on ensuring that our entire technology stack is free of software vulnerabilities (CVEs). This role is responsible for securing our base OS images, ensuring all open-source software (OSS) dependencies are scanned and patched, and integrating cutting-edge security tools into our CI/CD pipeline. The ideal candidate will drive the adoption of solutions like Google’s Assured Open Source Software (OSS) and explore alternative approaches to enhance software security. This role will lead the vulnerability management charter at Glean, identifying, evaluating, and implementing new security technologies and processes to proactively protect our infrastructure.
You will:
Own and lead the vulnerability management lifecycle, ensuring our entire tech stack is free from known CVEs.
Implement and manage secure base OS images, ensuring all underlying systems remain hardened against security threats.
Continuously scan, monitor, and patch OSS dependencies to mitigate supply chain risks and enforce best practices for dependency management.
Research and evaluate trusted open-source security solutions like Google’s Assured Open Source Software and recommend their adoption where applicable.
Work closely with engineering teams to integrate state-of-the-art SAST, DAST, and dependency scanning tools into the CI/CD pipeline to detect and remediate vulnerabilities early.
Define and maintain best practices for secure coding to ensure all code developed by Glean engineers is free from vulnerabilities.
Develop automated security validation tests to enforce vulnerability-free deployments across the stack.
Lead the adoption and, if necessary, develop custom security solutions to manage and mitigate security risks at scale.
Provide security guidance, training, and mentorship to engineering teams to foster a security-first culture at Glean.
About you:
BA/BS in Computer Science, Cybersecurity, or a related field (or equivalent industry experience).
5+ years of experience in application security and vulnerability management.
Deep understanding of software security vulnerabilities, including CVEs, OWASP Top 10, and supply chain risks.
Experience with SAST, DAST, dependency scanning, and vulnerability management tools (e.g., Snyk, GitHub Dependabot, Trivy, Clair, Burp Suite, OWASP ZAP).
Strong familiarity with package managers (npm, pip, Maven, Go modules) and securing open-source dependencies.
Coding experience in languages such as Go, Python, Java, or C++ to develop security test cases and tooling.
Hands-on experience with cloud-native security best practices across AWS, GCP, or Azure.
Knowledge of container security, Kubernetes security, and securing microservices architectures.
Ability to lead cross-function
Similar Jobs
Related searches:
On-site Jobs
Senior Jobs
On-site Senior Jobs
Senior AI Agents & RAGSenior NLP & Language AISenior AI Safety & SecuritySenior Machine LearningSenior Backend & Systems
AI Jobs in San Francisco
AI Agents & RAG in San FranciscoNLP & Language AI in San FranciscoAI Safety & Security in San FranciscoMachine Learning in San FranciscoBackend & Systems in San Francisco
agentsmicroservicessecurityllm