Supply Chain Security Engineer

Glean
Bengaluru
Workplace: HybridFull timeFunction: CybersecurityExperience: 5+ yearsEducation: bachelorsSkills: ["Secure coding","Vulnerability management","Security testing","Threat modeling","Mentoring"]

Apply security best practices across a large-scale enterprise SaaS platform, focusing on vulnerability management, OSS scanning, and secure CI/CD integration. Lead SAST/DAST and dependency scanning to reduce CVEs, secure open-source components, and mentor engineering teams on secure coding. Work hybrid in Bangalore, collaborating with a global engineering team to protect the platform used by major enterprise products.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Glean
Glean
11 months ago

Supply Chain Security Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 9 minutes agoStatus: Live

Job Summary

Apply security best practices across a large-scale enterprise SaaS platform, focusing on vulnerability management, OSS scanning, and secure CI/CD integration. Lead SAST/DAST and dependency scanning to reduce CVEs, secure open-source components, and mentor engineering teams on secure coding. Work hybrid in Bangalore, collaborating with a global engineering team to protect the platform used by major enterprise products.
Location: Bengaluru
Workplace: Hybrid
Employment Type: Full time
Job Function: Cybersecurity

Key Responsibilities

  • •Implement and improve the vulnerability management lifecycle across the stack to ensure it is free of known vulnerabilities/CVEs.
  • •Continuously scan, monitor, and patch OSS dependencies to mitigate supply chain risks and enforce best practices for dependency management.
  • •Collaborate with engineering to integrate SAST, DAST, and dependency scanning tools into the CI/CD pipeline for early vulnerability detection and remediation.
  • •Define and maintain secure coding best practices to ensure code is vulnerability-free.
  • •Ensure secure posture in SDLC by securing designs, conducting secure code reviews, and performing penetration testing of features.

Key Requirements

  • •BA/BS in Computer Science, Cybersecurity, or related field (or equivalent industry experience)
  • •5+ years of experience in application security and vulnerability management
  • •Deep understanding of software security vulnerabilities (CVEs, OWASP Top 10) and supply chain risks
  • •Experience with SAST, DAST, dependency scanning, and vulnerability management tools (e.g., Snyk, Dependabot, Trivy, Clair, Burp Suite, OWASP ZAP)
  • •Strong familiarity with package managers and securing open-source dependencies (npm, pip, Maven, Go modules) and coding in Go/Python/Java/C++ for tooling
Experience:5+ yearsEnterprise softwareSaaSSecurity tooling
Education:Bachelor's
Skills:Secure codingVulnerability managementSecurity testingThreat modelingMentoring
Languages:English
Tech Stack:SASTDASTDependency scanningGoPythonJavaC++AWSGCPAzureDockerKubernetes

Company Brief

Glean
Provides an enterprise search and knowledge discovery platform that helps organizations find information across apps, drives, and internal tools, improving employee productivity and onboarding through AI-powered search and relevance ranking.
Industry: Enterprise Software
Company Size: Large (251 to 1,000 employees)
Growth: Scaleup
Headquarters: San Francisco, United States
Founded: 2017
WebsiteLinkedIn