Skip to content
GleanGlean

Application Security Engineer

Leads vulnerability management and application-security initiatives across the technology stack, securing operating-system images, open-source dependencies, CI/CD pipelines, containers, and cloud-native systems. Requires 5+ years of application-security experience, coding ability, and expertise in vulnerability-scanning practices.

About the job

Responsibilities

  • Own and lead the vulnerability management lifecycle, ensuring the technology stack is free from known CVEs.
  • Implement and manage secure, hardened base operating system images.
  • Scan, monitor, and patch open-source software dependencies to mitigate supply-chain risks.
  • Research and evaluate trusted open-source security solutions, including Google Assured Open Source Software.
  • Integrate SAST, DAST, and dependency-scanning tools into CI/CD pipelines.
  • Define and maintain secure-coding best practices.
  • Develop automated security-validation tests for vulnerability-free deployments.
  • Lead adoption of, and potentially develop, custom security solutions to manage risks at scale.
  • Provide security guidance, training, and mentorship to engineering teams.

Requirements

  • Bachelor’s degree in Computer Science, Cybersecurity, or a related field, or equivalent industry experience.
  • At least 5 years of experience in application security and vulnerability management.
  • Deep understanding of CVEs, the OWASP Top 10, software vulnerabilities, and supply-chain risks.
  • Experience with SAST, DAST, dependency scanning, and vulnerability-management tools.
  • Familiarity with package managers such as npm, pip, Maven, and Go modules.
  • Coding experience with Go, Python, Java, or C++.
  • Experience with cloud-native security practices across AWS, Google Cloud, or Azure.
  • Knowledge of container security, Kubernetes security, and microservices security.
  • Ability to lead cross-functional initiatives and drive security adoption.
  • Strong problem-solving skills and ability to balance security with performance and usability.
  • Experience in fast-paced, collaborative environments.
  • Passion for open-source security and current vulnerability-management trends.

Compensation and Benefits

  • Annual base salary: $185,000–$260,000 USD.
  • Eligibility for variable compensation, equity, and benefits may apply.
  • Medical, vision, and dental coverage.
  • Generous time off.
  • 401(k) plan.
  • Home-office improvement stipend.
  • Annual education and wellness stipends.

Skills

Application Security, Vulnerability Management, Cves, Owasp Top 10, SAST, DAST, Dependency Scanning, Snyk, Github Dependabot, Trivy, Burp Suite, Owasp Zap, Kubernetes, Docker, Go

Huntress

Huntress

United States

QMS Manager
$185k+/yrRemote5+ YOESecurity Engineering

Build and lead a Security Quality Management System for agentic and human-led SOC investigations, establishing quality standards, sampling, validation, reporting, and corrective actions. The role requires 5+ years in quality, governance, operational excellence, or controls, plus security operations and people-management experience.

Glean

Glean

United States

Platform Security Engineer
$185k+/yrRemote5+ YOESecurity Engineering

Develop and maintain secure platform software spanning authentication, authorization, communications, data access, and automated security testing. The role requires 5+ years of security-focused software development experience, strong coding skills, and expertise in cloud and container security.

Onebrief

Onebrief

United States

Corporate Security Systems Engineer
$180k+/yrRemote4+ YOESecurity Engineering

Own and strengthen Onebrief’s corporate security stack across endpoints, identity, SaaS, Zero Trust, and monitoring. The role emphasizes security automation, configuration-baseline enforcement, telemetry integration, and continuously validated compliance controls.

Exa

Exa

San Francisco, CA

Security Engineer
$180k+/yrOn-siteSecurity Engineering

The Security Engineer will secure cloud infrastructure, engineering systems, APIs, model-training environments, and GPU clusters while supporting rapid delivery. The role requires hands-on cloud security, IAM, secrets and certificate management, compliance ownership, vulnerability monitoring, and incident response experience.

Decagon

Decagon

San Francisco, CA

Governance, Risk, and Compliance Manager - Privacy
$190k+/yrOn-site5+ YOESecurity Engineering

Own and operate Decagon’s privacy and GRC programs, including regulatory compliance, data governance, customer security engagements, audits, and cross-functional privacy initiatives. The role requires 5+ years of GRC experience, strong communication and project management skills, and familiarity with enterprise security controls.