Senior Application Security Engineer: Secure SDLC & OSS

Glean

United States

Remote

USD 185,000 - 260,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Home office stipend
Education stipend (annual)
Wellness stipend (annual)
401k matching

Job summary

Glean is seeking an experienced Application Security Engineer to secure our platform against CVEs and OSS risks. You will own the vulnerability management lifecycle, harden base OS images, and integrate SAST, DAST, and dependency scanning into CI/CD pipelines.

The role requires 8+ years in application security, with deep knowledge of OWASP Top 10 and supply chain risks, plus hands-on work with Snyk, Dependabot, Trivy, Clair, Burp Suite, and OWASP ZAP across AWS and GCP. Remote work is available.

Qualifications

  • 8+ years of experience in application security and vulnerability management.
  • Deep understanding of CVEs, OWASP Top 10, and supply chain risks.
  • Experience with SAST, DAST, and dependency scanning tools.
  • Hands-on cloud security across AWS and GCP, containers and Kubernetes.

Responsibilities

  • Own the vulnerability management lifecycle from discovery to remediation.
  • Harden base OS images and secure OSS dependencies.
  • Integrate SAST, DAST, and dependency scanning into CI/CD pipelines.
  • Evaluate and adopt new security tooling and practices.
  • Define secure-coding practices and mentor engineers.

Skills

Application security
Vulnerability management
Cloud security
Security tooling

Education

BA/BS in Computer Science, Cybersecurity, or related field

Tools

Snyk
GitHub Dependabot
Trivy
Clair
Burp Suite
OWASP ZAP

Job description

Glean is seeking an experienced Application Security Engineer to secure our platform against CVEs and OSS risks. You will own the vulnerability management lifecycle, harden base OS images, and integrate SAST, DAST, and dependency scanning into CI/CD pipelines.

The role requires 8+ years in application security, with deep knowledge of OWASP Top 10 and supply chain risks, plus hands-on work with Snyk, Dependabot, Trivy, Clair, Burp Suite, and OWASP ZAP across AWS and GCP. Remote work is available.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Security Engineer – Vulnerability & OSS
Application Security Engineer – Vulnerability & OSS

Glean • Northern (KY)

Hybrid
USD 185,000 - 260,000
Home office stipend
Education stipend
Wellness stipend
+1
Remote AppSec Engineer: Vulnerability & OSS Security
Remote AppSec Engineer: Vulnerability & OSS Security

NEPSE Trading • United States

On-site
USD 185,000 - 260,000
Home office stipend
Education stipend
Wellness stipend
+1
Remote App Security Engineer — Vulnerability & OSS Champion
Remote App Security Engineer — Vulnerability & OSS Champion

Zim Directory • Northern (KY)

Hybrid
USD 185,000 - 260,000
Medical coverage
Vision coverage
Dental coverage
+1
Senior Application Security Engineer
Senior Application Security Engineer

High Trail • Arlington (VA)

On-site
USD 140,000 - 190,000
Senior Application Security Engineer
Senior Application Security Engineer

Interactive Resources - iR • Jacksonville (FL)

On-site
USD 120,000 - 180,000
Senior Application Security Engineer - Remote
Senior Application Security Engineer - Remote

Agile Defense • United States

On-site
USD 110,000 - 165,000
Senior Security Engineer
Senior Security Engineer

Mach7 Technologies • New Jersey

On-site
USD 120,000 - 190,000
Security Engineer – SAST & SCA (Application Security)
Security Engineer – SAST & SCA (Application Security)

US staffing Inc • San Jose (CA)

On-site
USD 150,000 - 210,000
Senior Application Security Engineer | Flexible/Remote
Senior Application Security Engineer | Flexible/Remote

AgileEngine • Irving (IA)

On-site
USD 130,000 - 170,000
Professional growth
Competitive compensation
Exciting projects
+1
Application Security Engineer
Application Security Engineer

RedStream Technology • Charlotte (NC)

On-site
USD 120,000 - 150,000