Skip to content
GleanGlean

Supply Chain Security Engineer

Secures Glean's software supply chain by managing vulnerabilities, hardening images, protecting open-source dependencies, and embedding trusted release controls in CI/CD. Requires 3+ years in application security or vulnerability management, strong cloud-native and container security knowledge, and experience with FedRAMP audits.

About the job

Responsibilities

  • Implement and improve the vulnerability management lifecycle to keep the technology stack free from known vulnerabilities and CVEs.
  • Scan, monitor, and patch open-source software dependencies; integrate artifact scanning into CI/CD pipelines.
  • Build and execute the software supply chain security strategy, including secure-by-default open-source artifacts.
  • Improve supply chain vulnerability scoring using environmental impact controls and reachability factors.
  • Reduce the supply chain vulnerability footprint across Python, Java, Go, npm, and base-layer ecosystems.
  • Create hardened images for multiple deployment stacks.
  • Lead and contribute to software supply chain security initiatives, including SBOM generation and consumption, vulnerability prioritization, automated fix pipelines, build provenance, artifact signing, signature verification, and trusted release workflows.
  • Design automation and policy-driven controls to establish what was built, its source, and whether it can be trusted before deployment.
  • Develop and manage secure software supply chain usage guidelines and documentation.
  • Prepare Glean for FedRAMP requirements related to vulnerability management.

Requirements

  • Bachelor's degree in Computer Science, Cybersecurity, or a related field, or equivalent industry experience.
  • 3+ years of experience in application security and vulnerability management.
  • Deep understanding of software security vulnerabilities, including CVEs, OWASP Top 10, and software supply chain risks.
  • Understanding of security design principles, including authentication, authorization, RBAC, and database security.
  • Strong understanding of software supply chain components, management, threats, and vulnerabilities.
  • Familiarity with package managers including npm, pip, Maven, and Go modules, and with securing open-source dependencies.
  • Coding experience in Go, Python, Java, or C++ for developing security test cases and tooling.
  • Hands-on experience with cloud-native security best practices across AWS, Google Cloud, or Azure.
  • Experience handling FedRAMP audit cycles for vulnerability management.
  • Knowledge of container security, Kubernetes security, and microservices security.
  • Ability to lead cross-functional initiatives and drive security adoption within engineering teams.
  • Strong problem-solving skills and ability to balance security with performance and usability.
  • Experience in fast-paced, collaborative environments where security is a shared responsibility.
  • Passion for open-source security and current vulnerability management trends.

Work Arrangement

  • Hybrid role requiring three days per week in the Bangalore office.

Compensation and Benefits

  • Compensation is determined by location, level, job-related knowledge, skills, and experience.
  • Certain roles may be eligible for variable compensation, equity, and benefits.

Skills

Cves, Owasp Top 10, Vulnerability Management, Software Supply Chain Security, Sbom, Artifact Signing, Go, Python, Java, C++, Npm, Maven, Kubernetes, Container Security, FedRAMP

Supabase

Supabase

Remote

Platform Security Engineer
No salary listedRemote5+ YOESecurity Engineering

Secures Supabase’s cloud platform, Kubernetes environments, containers, and infrastructure by conducting risk assessments, strengthening controls, and building scalable security guardrails. Requires senior-level platform or cloud security experience with deep AWS, Kubernetes, container, and Linux expertise.

Vanta

Vanta

Remote

Manager, Security Operations
$178k+/yrRemote5+ YOESecurity Engineering

Leads a global Security Operations team, setting detection, response, and security strategy while driving incident response and risk remediation. The role requires strong SaaS and cloud security experience, leadership ability, familiarity with major security standards, and responsible use of AI.

Coinbase

Coinbase

India

Specialist, CSIRT
No salary listedRemote3+ YOESecurity Engineering

Owns frontline security alert triage, incident response, detection coverage, and automation across cloud, SaaS, container, and Web3 environments. Requires at least three years of hands-on security operations experience and proficiency with scripting, SIEM platforms, and threat intelligence tooling.

Greenlight

Greenlight

Bengaluru, India

Senior Security Engineer
No salary listedHybrid5+ YOESecurity Engineering

Senior product security engineer responsible for embedding security across the SDLC, building security automation, conducting reviews and penetration testing, and leading vulnerability response. Requires 5+ years of security experience, strong web and mobile security expertise, and hands-on AWS, CI/CD, and security tooling knowledge.

GoHighLevel

GoHighLevel

India

Lead Security Engineer - Penetration Testing & AI Security
No salary listedRemote8+ YOESecurity Engineering

Leads application and AI security assessments across web, API, cloud-native, and LLM-based systems. Requires 8+ years of cybersecurity experience, hands-on penetration testing and secure SDLC expertise, and experience adversarially testing AI applications.