Application Security Engineer

Glean, Ai
United States
1 day ago
Apply on weworkremotely.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Compensation
$185,000.0 - $260,000.0
Working hours
Regular working hours

Tech stack

Amazon Web Services Burp Suite Cloud Computing Security Cyber Security Continuous Integration Github Open Source Technology Open Web Application Security Package Management Systems Tripwire Software Vulnerability Management Software Security
+7 more
Kubernetes Information Technology Free and Open-Source Software Service Stack Static Application Security Testing Microservices Dynamic Application Security Testing

Job description

Glean is looking for an experienced Application Security Engineer with a primary focus on ensuring that our entire technology stack is free of software vulnerabilities (CVEs). This role is responsible for securing our base OS images, ensuring all open-source software (OSS) dependencies are scanned and patched, and integrating cutting-edge security tools into our CI/CD pipeline. The ideal candidate will drive the adoption of solutions like Google’s Assured Open Source Software (OSS) and explore alternative approaches to enhance software security. This role will lead the vulnerability management charter at Glean, identifying, evaluating, and implementing new security technologies and processes to proactively protect our infrastructure., * Own the vulnerability management lifecycle across Glean’s technology stack, from discovery and prioritization through remediation, reporting, and measurement.

  • Harden base OS images and secure open-source dependencies, package managers, and the broader software supply chain.
  • Integrate SAST, DAST, dependency scanning, and automated security validation into CI/CD pipelines.
  • Evaluate, adopt, and develop security solutions and tooling, including Google’s Assured OSS and comparable approaches.
  • Define secure-coding practices and drive engineering adoption through guidance, training, and mentorship.

Requirements

  • BA/BS in Computer Science, Cybersecurity, or a related field (or equivalent industry experience).
  • 8+ years of experience in application security and vulnerability management.
  • Deep understanding of software security vulnerabilities, including CVEs, OWASP Top 10, and supply chain risks.
  • Experience with SAST, DAST, dependency scanning, and vulnerability management tools (e.g., Snyk, GitHub Dependabot, Trivy, Clair, Burp Suite, OWASP ZAP).
  • Hands-on experience with cloud-native security across AWS, GCP, including containers, Kubernetes, and microservices.
  • Ability to lead cross-functional initiatives and drive security adoption across engineering teams.
  • Proactive, pragmatic, and collaborative, with strong problem-solving skills and the ability to balance security with performance and usability.

Benefits & conditions

The standard base salary range for this position is $185,000 - $260,000 annually. Compensation offered will be determined by factors such as location, level, job-related knowledge, skills, and experience. Certain roles may be eligible for variable compensation, equity, and benefits. We offer a comprehensive benefits package including competitive compensation, Medical, Vision, and Dental coverage, generous time-off policy, and the opportunity to contribute to your 401k plan to support your long-term goals. When you join, you’ll receive a home office improvement stipend, as well as an annual education and wellness stipends to support your growth and wellbeing. We foster a vibrant company culture through regular events, and provide healthy lunches daily to keep you fueled and focused. We’re committed to building and sustaining a diverse, inclusive workplace. We strive to attract and retain people with a wide range of backgrounds, experiences, and perspectives, and we do not discriminate on the basis of gender, ethnicity, sexual orientation, religion, civil or family status, age, disability, or race. #LI-REMOTE AI-First Mindset at Glean: At Glean, AI fluency is core to how we work and we’re committed to ensuring every new hire feels confident integrating AI into their everyday work. As part of the interview process, you’ll complete a brief AI-focused exercise or discussion so we can understand how you think about, design, and use AI to drive impact in your role. Feel free to reference any tools, platforms, or workflows you use today - prior Glean experience isn’t required.

About the company

Glean is the Work AI platform that helps everyone work smarter with AI. What began as the industry’s most advanced enterprise search has evolved into a full-scale Work AI ecosystem, powering intelligent Search, an AI Assistant, and scalable AI agents on one secure, open platform. With over 100 enterprise SaaS connectors, flexible LLM choice, and robust APIs, Glean gives organizations the infrastructure to govern, scale, and customize AI across their entire business - without vendor lock-in or costly implementation cycles. At its core, Glean is redefining how enterprises find, use, and act on knowledge. Its Enterprise Graph and Personal Knowledge Graph map the relationships between people, content, and activity, delivering deeply personalized, context-aware responses for every employee. This foundation powers Glean’s agentic capabilities - AI agents that automate real work across teams by accessing the industry’s broadest range of data: enterprise and world, structured and unstructured, historical and real-time. The result: measurable business impact through faster onboarding, hours of productivity gained each week, and smarter, safer decisions at every level. Recognized by Fast Company as one of the World’s Most Innovative Companies (Top 10, 2025), by CNBC’s Disruptor 50, Bloomberg’s AI Startups to Watch (2026), Forbes AI 50, and Gartner’s Tech Innovators in Agentic AI, Glean continues to accelerate its global impact. With customers across 50+ industries and 1,000+ employees in more than 25 countries, we’re helping the world’s largest organizations make every employee AI-fluent, and turning the superintelligent enterprise from concept into reality. If you’re excited to shape how the world works, you’ll help build systems used daily across Microsoft Teams, Zoom, ServiceNow, Zendesk, GitHub, and many more - deeply embedded where people get things done. You’ll ship agentic capabilities on an open, extensible stack, with the craft and care required for enterprise trust, as we bring Work AI to every employee, in every company.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on weworkremotely.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:22 min

Addressing the shortage of application security specialists

Joseph Katsioloudes Joseph Katsioloudes · World Congress 2025

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · World Congress 2023

4:36 min

Exploiting e-commerce basket identifiers with Burp Suite

Anna Bacher · LIVE

2:40 min

Using GitHub primitives for internal documentation and corporate operations

Kyle Daigle · Coffee With Developers

3:31 min

Setting up a penetration testing environment for web apps

Anna Bacher · LIVE

4:58 min

Scaling security teams through developer advocates

Tanya Janca · World Congress 2021

Videos

See all

Related articles

See all