Glean logo

Supply Chain Security Engineer

Glean
Posted a month ago

LOCATION

Bangalore · Hybrid

EXPERIENCE

3+ Years

SKILLS REQUIRED

Software Supply Chain SecurityCI/CD Security IntegrationVulnerability Management

Job description

Overview

Supply Chain Security Engineer focused on keeping Glean’s technology stack free of known software vulnerabilities (CVEs) and strengthening secure-by-default software supply chain practices.

What you'll do

  • Implement and improve the vulnerability management lifecycle to eliminate known CVEs across the tech stack.
  • Continuously scan, monitor, and patch OSS dependencies to mitigate supply chain risks via CI/CD integration.
  • Build and execute software supply chain security strategy for secure-by-default open-source artifacts.
  • Improve supply chain vulnerability scoring by incorporating environmental/impact controls and reachability factors.
  • Research approaches to reduce supply chain vulnerability footprint across Python, Java, Go, and npm ecosystems.
  • Create hardened images for use across multiple deployment stacks.
  • Lead supply chain security initiatives including SBOM generation/consumption, vulnerability prioritization, build provenance, artifact signing, and trusted release workflows.

What you'll need

  • 3+ years of experience in application security and vulnerability management.
  • Deep understanding of software security vulnerabilities, including CVEs and OWASP Top 10, and supply chain risks.
  • Deep understanding of security design principles including authentication, authorization, and RBAC.
  • Strong knowledge of software supply chain components and management.
  • Familiarity with package managers (npm, pip, Maven, Go modules) and securing open-source dependencies.
  • Coding experience in Go, Python, Java, or C++ to develop security test cases and tooling.
  • Hands-on experience with cloud-native security best practices across AWS, GCP, or Azure.

Details

  • Role is hybrid with 3 days a week in the Bangalore office.
  • Location stated as Bangalore (hybrid).
  • Role covers getting FEDRAMP ready with respect to vulnerability management.

Read the full description and apply on the company’s own careers page.

Stay safe

Hiring on Abekus is free for applicants

We never charge a fee, and employers are prohibited from doing so. If a recruiter asks for payment, please report them right away.

Supply Chain Security Engineer