Overview
Supply Chain Security Engineer focused on keeping Glean’s technology stack free of known software vulnerabilities (CVEs) and strengthening secure-by-default software supply chain practices.
What you'll do
- Implement and improve the vulnerability management lifecycle to eliminate known CVEs across the tech stack.
- Continuously scan, monitor, and patch OSS dependencies to mitigate supply chain risks via CI/CD integration.
- Build and execute software supply chain security strategy for secure-by-default open-source artifacts.
- Improve supply chain vulnerability scoring by incorporating environmental/impact controls and reachability factors.
- Research approaches to reduce supply chain vulnerability footprint across Python, Java, Go, and npm ecosystems.
- Create hardened images for use across multiple deployment stacks.
- Lead supply chain security initiatives including SBOM generation/consumption, vulnerability prioritization, build provenance, artifact signing, and trusted release workflows.
What you'll need
- 3+ years of experience in application security and vulnerability management.
- Deep understanding of software security vulnerabilities, including CVEs and OWASP Top 10, and supply chain risks.
- Deep understanding of security design principles including authentication, authorization, and RBAC.
- Strong knowledge of software supply chain components and management.
- Familiarity with package managers (npm, pip, Maven, Go modules) and securing open-source dependencies.
- Coding experience in Go, Python, Java, or C++ to develop security test cases and tooling.
- Hands-on experience with cloud-native security best practices across AWS, GCP, or Azure.
Details
- Role is hybrid with 3 days a week in the Bangalore office.
- Location stated as Bangalore (hybrid).
- Role covers getting FEDRAMP ready with respect to vulnerability management.
Read the full description and apply on the company’s own careers page.