# Application Security Engineer

**Company:** [Glean](https://hotfix.jobs/companies/glean)
**Location:** Remote
**Role:** Security Engineering
**Salary:** $185k – $260k/yr
**Experience:** 5+ years
**Skills:** Application Security, Vulnerability Management, Cves, Owasp Top 10, SAST, DAST, Dependency Scanning, Snyk, Github Dependabot, Trivy, Burp Suite, Owasp Zap, Kubernetes, Docker, Go
**Posted:** 2026-08-27

> Leads vulnerability management and application-security initiatives across the technology stack, securing operating-system images, open-source dependencies, CI/CD pipelines, containers, and cloud-native systems. Requires 5+ years of application-security experience, coding ability, and expertise in vulnerability-scanning practices.

## Job Description

## Responsibilities
- Own and lead the vulnerability management lifecycle, ensuring the technology stack is free from known CVEs.
- Implement and manage secure, hardened base operating system images.
- Scan, monitor, and patch open-source software dependencies to mitigate supply-chain risks.
- Research and evaluate trusted open-source security solutions, including Google Assured Open Source Software.
- Integrate SAST, DAST, and dependency-scanning tools into CI/CD pipelines.
- Define and maintain secure-coding best practices.
- Develop automated security-validation tests for vulnerability-free deployments.
- Lead adoption of, and potentially develop, custom security solutions to manage risks at scale.
- Provide security guidance, training, and mentorship to engineering teams.

## Requirements
- Bachelor’s degree in Computer Science, Cybersecurity, or a related field, or equivalent industry experience.
- At least 5 years of experience in application security and vulnerability management.
- Deep understanding of CVEs, the OWASP Top 10, software vulnerabilities, and supply-chain risks.
- Experience with SAST, DAST, dependency scanning, and vulnerability-management tools.
- Familiarity with package managers such as npm, pip, Maven, and Go modules.
- Coding experience with Go, Python, Java, or C++.
- Experience with cloud-native security practices across AWS, Google Cloud, or Azure.
- Knowledge of container security, Kubernetes security, and microservices security.
- Ability to lead cross-functional initiatives and drive security adoption.
- Strong problem-solving skills and ability to balance security with performance and usability.
- Experience in fast-paced, collaborative environments.
- Passion for open-source security and current vulnerability-management trends.

## Compensation and Benefits
- Annual base salary: **$185,000–$260,000 USD**.
- Eligibility for variable compensation, equity, and benefits may apply.
- Medical, vision, and dental coverage.
- Generous time off.
- 401(k) plan.
- Home-office improvement stipend.
- Annual education and wellness stipends.

## Similar jobs

- [QMS Manager](https://hotfix.jobs/jobs/4c317f13-ae5c-4532-bffc-617f1e288c04) - Huntress - Remote - $185k – $200k/yr
- [Platform Security Engineer](https://hotfix.jobs/jobs/353f9275-bc29-458a-b515-4512339e0155) - Glean - Remote - $185k – $260k/yr
- [Corporate Security Systems Engineer](https://hotfix.jobs/jobs/9a4ec7a6-0304-4f1e-b7a7-84d64f4413a7) - Onebrief - Remote - $180k – $200k/yr
- [Security Engineer](https://hotfix.jobs/jobs/99797080-4b95-46be-803c-d22bc230444a) - Exa - San Francisco, CA - $180k – $350k/yr
- [Governance, Risk, and Compliance Manager - Privacy](https://hotfix.jobs/jobs/a5153f89-2b1c-40d2-b939-13b82952a049) - Decagon - San Francisco, CA - $190k – $275k/yr

**Apply:** https://hotfix.jobs/jobs/c14cd542-12a5-42f6-baef-8f3a18440238
**Canonical:** https://hotfix.jobs/jobs/c14cd542-12a5-42f6-baef-8f3a18440238