Supply Chain Security Engineer
Glean is an enterprise AI platform that connects company knowledge and systems to provide permission-aware search, AI assistance, and agents.
Funding history
About Glean
Glean develops enterprise Work AI software. Its platform provides enterprise search, a conversational AI assistant, and tools to build, govern, and orchestrate AI agents using a company’s connected data and permissions.
Skills
Candidate Availability
Required and preferred rules are kept separate and reflect the wording in the original posting.
About the Role
You will improve the vulnerability-management lifecycle, scan and patch open-source dependencies, and integrate artifact scanning into CI/CD. You will create hardened images, develop supply-chain security controls and documentation, lead SBOM and artifact-signing initiatives, and prepare vulnerability-management practices for FedRAMP.
Requirements
- Bachelor's degree in computer science, cybersecurity, or a related field, or equivalent industry experience
- 3+ years of application security and vulnerability-management experience
- Knowledge of CVEs, OWASP Top 10, and supply-chain risks
- Knowledge of authentication, authorization, RBAC, and database security
- Knowledge of software supply-chain components, threats, and vulnerabilities
- Familiarity with npm, pip, Maven, and Go modules
- Coding experience with Go, Python, Java, or C++
- Cloud-native security experience with AWS, GCP, or Azure
- Experience with FedRAMP vulnerability-management audit cycles
- Knowledge of container security, Kubernetes security, and microservices security
- Ability to lead cross-functional security initiatives
Responsibilities
- Implement and improve the vulnerability-management lifecycle
- Scan, monitor, and patch open-source dependencies
- Integrate artifact-scanning processes into CI/CD
- Build and execute software supply-chain security strategy
- Improve supply-chain vulnerability scoring
- Research ways to reduce vulnerabilities across Python, Java, Go, npm, and base layers
- Create hardened images for deployment stacks
- Lead SBOM, automated-fix, build-provenance, artifact-signing, signature-verification, and trusted-release initiatives
- Design automation and policy-driven supply-chain controls
- Develop secure software supply-chain guidelines and documentation
- Prepare vulnerability management for FedRAMP
Hiring Process
Brief AI-focused exercise or discussion.
