Application Security Engineer

Glean

$185K — $260K *
US-AnywhereRemote in United States
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • BA/BS in Computer Science, Cybersecurity, or related field (or equivalent experience)
  • 8+ years of experience in application security and vulnerability management
  • Deep understanding of software security vulnerabilities (CVEs, OWASP Top 10, supply chain risks)
  • Experience with SAST, DAST, and vulnerability management tools (e.g., Snyk, GitHub Dependabot, Trivy)
  • Hands-on experience with cloud-native security across AWS/GCP, including containers and Kubernetes
  • Ability to lead cross-functional security initiatives
  • Strong problem-solving skills with a collaborative, pragmatic approach

Responsibilities

  • Own the vulnerability management lifecycle, from discovery to remediation and reporting
  • Harden base OS images and secure open-source dependencies
  • Integrate security validation tools into CI/CD pipelines
  • Evaluate and adopt cutting-edge security solutions like Google's Assured OSS
  • Define secure-coding practices and mentor engineering teams

Benefits

  • Comprehensive Medical, Vision, and Dental coverage
  • Generous time-off policy
  • 401k plan to support long-term goals
  • Home office improvement stipend
  • Annual education and wellness stipends
  • Regular company events and daily healthy lunches
Full Job Description
About the Role:

Glean is looking for an experienced Application Security Engineer with a primary focus on ensuring that our entire technology stack is free of software vulnerabilities (CVEs). This role is responsible for securing our base OS images, ensuring all open-source software (OSS) dependencies are scanned and patched, and integrating cutting-edge security tools into our CI/CD pipeline. The ideal candidate will drive the adoption of solutions like Google's Assured Open Source Software (OSS) and explore alternative approaches to enhance software security. This role will lead the vulnerability management charter at Glean, identifying, evaluating, and implementing new security technologies and processes to proactively protect our infrastructure.
You will:
  • Own the vulnerability management lifecycle across Glean's technology stack, from discovery and prioritization through remediation, reporting, and measurement.
  • Harden base OS images and secure open-source dependencies, package managers, and the broader software supply chain.
  • Integrate SAST, DAST, dependency scanning, and automated security validation into CI/CD pipelines.
  • Evaluate, adopt, and develop security solutions and tooling, including Google's Assured OSS and comparable approaches.
  • Define secure-coding practices and drive engineering adoption through guidance, training, and mentorship.
About you:
  • BA/BS in Computer Science, Cybersecurity, or a related field (or equivalent industry experience).
  • 8+ years of experience in application security and vulnerability management.
  • Deep understanding of software security vulnerabilities, including CVEs, OWASP Top 10, and supply chain risks.
  • Experience with SAST, DAST, dependency scanning, and vulnerability management tools (e.g., Snyk, GitHub Dependabot, Trivy, Clair, Burp Suite, OWASP ZAP).
  • Hands-on experience with cloud-native security across AWS, GCP, including containers, Kubernetes, and microservices.
  • Ability to lead cross-functional initiatives and drive security adoption across engineering teams.
  • Proactive, pragmatic, and collaborative, with strong problem-solving skills and the ability to balance security with performance and usability.

Location:
  • This role is remote

Compensation & Benefits:

The standard base salary range for this position is $185,000 - $260,000 annually. Compensation offered will be determined by factors such as location, level, job-related knowledge, skills, and experience. Certain roles may be eligible for variable compensation, equity, and benefits.

We offer a comprehensive benefits package including competitive compensation, Medical, Vision, and Dental coverage, generous time-off policy, and the opportunity to contribute to your 401k plan to support your long-term goals. When you join, you'll receive a home office improvement stipend, as well as an annual education and wellness stipends to support your growth and wellbeing. We foster a vibrant company culture through regular events, and provide healthy lunches daily to keep you fueled and focused.

#LI-REMOTE

AI-First Mindset at Glean:

At Glean, AI fluency is core to how we work and we're committed to ensuring every new hire feels confident integrating AI into their everyday work. As part of the interview process, you'll complete a brief AI-focused exercise or discussion so we can understand how you think about, design, and use AI to drive impact in your role. Feel free to reference any tools, platforms, or workflows you use today - prior Glean experience isn't required.

Similar Jobs

More Jobs at Glean

More Information Technology Jobs

Find similar Application Security Engineer jobs: