Supply Chain Security Engineer
Glean
Make my CV for this job, freeView job and applyYour CV, rewritten for this role using only your real experience. Sign in with Google and upload your CV. Nothing to install.
Skills named in this job
Read from the description itself, not inferred.
This role on the market
2,789 open security roles across 436 companies are on ApplySarthi right now, most of them in Bengaluru (116), Hyderabad (28), Pune (22).
- Security Engineer, AWS Cloud ResponseAmazon Corporate Services Pty Ltd
- Software Development Engineer, AWS SecurityAmazon Development Centre (London) Limited
- GRC Security SpecialistPayoneer
- Application Security EngineerTeliogroup
- Application Security EngineerPokemoncareers
What security roles keep asking for: AWS (29%), Python (26%), SIEM (14%), GCP (12%), CI/CD (12%) — counted across their open postings here.
AWS jobs · Azure jobs · C++ jobs · CI/CD jobs
Glean has 130 open roles listed here.
- Machine Learning Engineer, Search Quality
- Designated Technical Support Engineer - Central/East
- Strategic Federal Account Executive, SLED
- Designated Technical Support Engineer - Central/East
- Principal Product Marketing Manager (Enterprise Context)
Counted across 14 company job boards, updated as roles open and close.
Preparing for this interview
Interviews for security roles keep coming back to AWS, Python, SIEM, GCP. Practise those questions before you sit with Glean.
Questions you are likely to be asked
- Why do you want to join Glean?
- What is your experience with Supply chain? Tell me one thing you learned the hard way.
- How would you cut the cloud bill of a system without hurting it?
- How do you keep secrets and access safe in your infrastructure?
- Walk me through how code gets from a commit to production where you work.
Prep Sarthi gives you a free mock interview: an AI interviewer asks you questions like these out loud, from your own CV and this job, and shows your score and your weakest answer.
Practise the Supply Chain Security Engineer at Glean interview free →About the Role:
Glean is looking for a Supply Chain Security Engineer with a primary focus on ensuring that our entire technology stack is free of software vulnerabilities (CVEs). This role is responsible for securing our base OS images, ensuring all open-source software (OSS) dependencies are scanned and patched, and integrating cutting-edge security tools into our CI/CD pipeline.
You Will:
- Implement and improve the vulnerability management lifecycle, ensuring our entire tech stack is free from known vulnerabilities/CVEs.
- Continuously scan, monitor, and patch OSS dependencies to mitigate supply chain risks and enforce best practices for dependency management by integrating artifact scanning processes in CI/CD.
- Help build and execute our software supply chain security strategy to expand upon Glean’s ability to deploy secure-by-default open-source artifacts, etc., across the enterprise.
- Improve the supply chain vulnerability scoring mechanism to take into account the environmental/impact controls and the reachability factors.
- Research on ways to reduce the supply chain vulnerability footprint across Python, Java, GO, npm ecosystems and base layers.
- Create hardened images which can be used across multiple deployment stacks.
- Lead and contribute to Software Supply Chain Security initiatives, including SBOM generation and consumption, vulnerability prioritisation, automated fix pipeline, build provenance, artifact signing, signature verification, and trusted release workflows.
- Design automation and policy-driven controls that help teams prove what was built, where it came from, and whether it can be trusted before deployment.
- Develop and manage secure software supply chain usage guidelines and documentation.
- Get Glean FEDRAMP ready with respect to vulnerability management.
About You:
- BA/BS in Computer Science, Cybersecurity, or a related field (or equivalent industry experience).
- 3+ years of experience in application security and vulnerability management.
- Deep understanding of software security vulnerabilities, including CVEs, OWASP Top 10, and supply chain risks.
- Deep understanding security design principles including but not limited to authentication, authorisation, RBAC, database security.
- Strong understanding of software supply chain components and management
- Strong understanding of software supply chain security threats and vulnerabilities
- Strong familiarity with package managers (npm, pip, Maven, Go modules) and securing open-source dependencies.
- Coding experience in languages such as Go, Python, Java, or C++ to develop security test cases and tooling.
- Hands-on experience with cloud-native security best practices across AWS, GCP, or Azure.
- Experience with handling FEDRAMP audit cycles for vulnerability management
- Knowledge of container security, Kubernetes security, and securing microservices architectures.
- Ability to lead cross-functional initiatives and drive security adoption within engineering teams.
- A strong proactive approach to security, identifying risks before they become problems.
- Excellent problem-solving skills and the ability to balance security with performance and usability.
- Experience working in fast-paced, highly collaborative environments where security is a shared responsibility.
- Passion for open-source security and keeping up with the latest trends in software vulnerability management.
Location:
- This role is hybrid (3 days a week in our Bangalore office)
Compensation & Benefits:
Compensation offered will be determined by factors such as location, level, job-related knowledge, skills, and experience. Certain roles may be eligible for variable compensation, equity, and benefits.
We are a diverse bunch of people and we want to continue to attract and retain a diverse range of people into our organization. We're committed to an inclusive and diverse company. We do not discriminate based on gender, ethnicity, sexual orientation, religion, civil or family status, age, disability, or race.
#LI-HYBRID
By clicking “Submit Application,” I confirm that I have read the Global Data Privacy Notice and the Applicant Arbitration Agreement, and I agree to the terms.
Match this job to your CV
ApplySarthi scores your CV against this role, shows the skills you are missing, and writes a tailored version for the application.
Check my match →Similar open roles
- AI Data AnalystGlean · bengaluru
- AI Success Manager, CentralGlean
- AI Success Manager, East Glean
- AI Success Manager (US East Customer Hours)Glean · bengaluru
- AI Success Manager (US West Customer Hours)Glean · bengaluru
- Application Security EngineerGlean
- Technical Program Manager, AI & Cloud EfficiencyGlean · bengaluru
- Enterprise Account Executive, ChicagoGlean
Need answers during your interview? Try Live Sarthi.
Live Sarthi, an Interview Sarthi app, shows answer suggestions during the call.
- Hidden from supported screen sharingThe overlay stays out of supported Windows screen captures.
- Answers start in about 1.5 secondsResponse time varies with your connection and model.
- From your own CVYour projects and your experience, not a generic script.
- 30 minutes freeThen ₹99 for a 2-day pass with unlimited calls — you pay for the days you are interviewing, not a subscription.
A Windows app, from the same team as ApplySarthi.
Listed on greenhouse · posted 2025-09-26. ApplySarthi collects openings and links to application pages; the role is advertised by Glean, not by us.