Supply Chain Security Engineer

Glean is an enterprise AI platform that connects company knowledge and systems to provide permission-aware search, AI assistance, and agents.

San Francisco, United States
About Glean

Glean develops enterprise Work AI software. Its platform provides enterprise search, a conversational AI assistant, and tools to build, govern, and orchestrate AI agents using a company’s connected data and permissions.

View jobs by Glean

Skills

Candidate Availability

Required and preferred rules are kept separate and reflect the wording in the original posting.

About the Role

You will improve the vulnerability-management lifecycle, scan and patch open-source dependencies, and integrate artifact scanning into CI/CD. You will create hardened images, develop supply-chain security controls and documentation, lead SBOM and artifact-signing initiatives, and prepare vulnerability-management practices for FedRAMP.

Requirements

  • Bachelor's degree in computer science, cybersecurity, or a related field, or equivalent industry experience
  • 3+ years of application security and vulnerability-management experience
  • Knowledge of CVEs, OWASP Top 10, and supply-chain risks
  • Knowledge of authentication, authorization, RBAC, and database security
  • Knowledge of software supply-chain components, threats, and vulnerabilities
  • Familiarity with npm, pip, Maven, and Go modules
  • Coding experience with Go, Python, Java, or C++
  • Cloud-native security experience with AWS, GCP, or Azure
  • Experience with FedRAMP vulnerability-management audit cycles
  • Knowledge of container security, Kubernetes security, and microservices security
  • Ability to lead cross-functional security initiatives

Responsibilities

  • Implement and improve the vulnerability-management lifecycle
  • Scan, monitor, and patch open-source dependencies
  • Integrate artifact-scanning processes into CI/CD
  • Build and execute software supply-chain security strategy
  • Improve supply-chain vulnerability scoring
  • Research ways to reduce vulnerabilities across Python, Java, Go, npm, and base layers
  • Create hardened images for deployment stacks
  • Lead SBOM, automated-fix, build-provenance, artifact-signing, signature-verification, and trusted-release initiatives
  • Design automation and policy-driven supply-chain controls
  • Develop secure software supply-chain guidelines and documentation
  • Prepare vulnerability management for FedRAMP

Hiring Process

Brief AI-focused exercise or discussion.

Supply Chain Security Engineer at Glean | JobStash