Application Security Engineer

Glean Glean · Enterprise · Bangalore, India · Engineering

Application Security Engineer focused on securing Glean's technology stack, managing vulnerabilities in OS images and OSS dependencies, and integrating security tools into CI/CD pipelines. Responsibilities include scanning, patching, secure coding practices, and developing automated security validation tests.

What you'd actually do

  1. Implement and improve the vulnerability management lifecycle, ensuring our entire tech stack is free from known vulnerabilities/CVEs.
  2. Continuously scan, monitor, and patch OSS dependencies to mitigate supply chain risks and enforce best practices for dependency management.
  3. Work closely with engineering teams to integrate state-of-the-art SAST, DAST, and dependency scanning tools into the CI/CD pipeline to detect and remediate vulnerabilities early.
  4. Define and maintain best practices for secure coding to ensure all code developed by Glean engineers is free from vulnerabilities.
  5. Ensure secure posture in SDLC by securing designs, conducting secure code reviews and penetration testing the features.

Skills

Required

  • 5+ years of experience in application security and vulnerability management
  • Deep understanding of software security vulnerabilities, including CVEs, OWASP Top 10, and supply chain risks
  • Deep understanding security design principles including but not limited to authentication, authorisation, RBAC, database security
  • Experience with SAST, DAST, dependency scanning, and vulnerability management tools (e.g., Snyk, GitHub Dependabot, Trivy, Clair, Burp Suite, OWASP ZAP)
  • Strong familiarity with package managers (npm, pip, Maven, Go modules) and securing open-source dependencies
  • Coding experience in languages such as Go, Python, Java, or C++ to develop security test cases and tooling
  • Hands-on experience with cloud-native security best practices across AWS, GCP, or Azure
  • Knowledge of container security, Kubernetes security, and securing microservices architectures
  • Ability to lead cross-functional initiatives and drive security adoption within engineering teams
  • A strong proactive approach to security, identifying risks before they become problems
  • Excellent problem-solving skills and the ability to balance security with performance and usability

Nice to have

  • BA/BS in Computer Science, Cybersecurity, or a related field (or equivalent industry experience)
  • Passion for open-source security and keeping up with the latest trends in software vulnerability management
  • Experience working in fast-paced, highly collaborative environments where security is a shared responsibility

What the JD emphasized

  • primary focus on ensuring that our entire technology stack is free of software vulnerabilities (CVEs)
  • vulnerability management lifecycle
  • mitigate supply chain risks
  • detect and remediate vulnerabilities early
  • free from vulnerabilities