# Supply Chain Security Engineer

**Company:** [Glean](https://hotfix.jobs/companies/glean)
**Location:** Bengaluru, India
**Role:** Security Engineering
**Experience:** 3+ years
**Skills:** Cves, Owasp Top 10, Vulnerability Management, Software Supply Chain Security, Sbom, Artifact Signing, Go, Python, Java, C++, Npm, Maven, Kubernetes, Container Security, FedRAMP
**Posted:** 2026-08-12

> Secures Glean's software supply chain by managing vulnerabilities, hardening images, protecting open-source dependencies, and embedding trusted release controls in CI/CD. Requires 3+ years in application security or vulnerability management, strong cloud-native and container security knowledge, and experience with FedRAMP audits.

## Job Description

## Responsibilities
- Implement and improve the vulnerability management lifecycle to keep the technology stack free from known vulnerabilities and CVEs.
- Scan, monitor, and patch open-source software dependencies; integrate artifact scanning into CI/CD pipelines.
- Build and execute the software supply chain security strategy, including secure-by-default open-source artifacts.
- Improve supply chain vulnerability scoring using environmental impact controls and reachability factors.
- Reduce the supply chain vulnerability footprint across Python, Java, Go, npm, and base-layer ecosystems.
- Create hardened images for multiple deployment stacks.
- Lead and contribute to software supply chain security initiatives, including SBOM generation and consumption, vulnerability prioritization, automated fix pipelines, build provenance, artifact signing, signature verification, and trusted release workflows.
- Design automation and policy-driven controls to establish what was built, its source, and whether it can be trusted before deployment.
- Develop and manage secure software supply chain usage guidelines and documentation.
- Prepare Glean for FedRAMP requirements related to vulnerability management.

## Requirements
- Bachelor's degree in Computer Science, Cybersecurity, or a related field, or equivalent industry experience.
- 3+ years of experience in application security and vulnerability management.
- Deep understanding of software security vulnerabilities, including CVEs, OWASP Top 10, and software supply chain risks.
- Understanding of security design principles, including authentication, authorization, RBAC, and database security.
- Strong understanding of software supply chain components, management, threats, and vulnerabilities.
- Familiarity with package managers including npm, pip, Maven, and Go modules, and with securing open-source dependencies.
- Coding experience in Go, Python, Java, or C++ for developing security test cases and tooling.
- Hands-on experience with cloud-native security best practices across AWS, Google Cloud, or Azure.
- Experience handling FedRAMP audit cycles for vulnerability management.
- Knowledge of container security, Kubernetes security, and microservices security.
- Ability to lead cross-functional initiatives and drive security adoption within engineering teams.
- Strong problem-solving skills and ability to balance security with performance and usability.
- Experience in fast-paced, collaborative environments where security is a shared responsibility.
- Passion for open-source security and current vulnerability management trends.

## Work Arrangement
- Hybrid role requiring three days per week in the Bangalore office.

## Compensation and Benefits
- Compensation is determined by location, level, job-related knowledge, skills, and experience.
- Certain roles may be eligible for variable compensation, equity, and benefits.

## Similar jobs

- [Platform Security Engineer](https://hotfix.jobs/jobs/e556dd76-0f95-4dfa-9d3d-e476f24057c0) - Supabase - Remote
- [Manager, Security Operations](https://hotfix.jobs/jobs/0a4637da-6072-4ec3-a0a9-8b6d4a412d45) - Vanta - Remote - $178k – $209k/yr
- [Specialist, CSIRT](https://hotfix.jobs/jobs/d5cdd102-2c55-4adf-a397-fb50362f7fea) - Coinbase - Remote
- [Senior Security Engineer](https://hotfix.jobs/jobs/2a1ede09-d608-462e-bb14-223603034206) - Greenlight - Bengaluru, India
- [Lead Security Engineer - Penetration Testing & AI Security](https://hotfix.jobs/jobs/ac8bc34d-2a43-4c67-870e-a1e01edee0cb) - GoHighLevel - Remote

**Apply:** https://hotfix.jobs/jobs/7ea430fb-72cd-43f4-9700-2698a4cc949f
**Canonical:** https://hotfix.jobs/jobs/7ea430fb-72cd-43f4-9700-2698a4cc949f