Back to jobs

Supply Chain Security Engineer

Bangalore, India
About Glean:
 
Glean is the Work AI platform that helps everyone work smarter with AI. What began as the industry’s most advanced enterprise search has evolved into a full-scale Work AI ecosystem, powering intelligent Search, an AI Assistant, and scalable AI agents on one secure, open platform. With over 100 enterprise SaaS connectors, flexible LLM choice, and robust APIs, Glean gives organizations the infrastructure to govern, scale, and customize AI across their entire business - without vendor lock-in or costly implementation cycles.
 
At its core, Glean is redefining how enterprises find, use, and act on knowledge. Its Enterprise Graph and Personal Knowledge Graph map the relationships between people, content, and activity, delivering deeply personalized, context-aware responses for every employee. This foundation powers Glean’s agentic capabilities - AI agents that automate real work across teams by accessing the industry’s broadest range of data: enterprise and world, structured and unstructured, historical and real-time. The result: measurable business impact through faster onboarding, hours of productivity gained each week, and smarter, safer decisions at every level.
 
Recognized by Fast Company as one of the World’s Most Innovative Companies (Top 10, 2025), by CNBC’s Disruptor 50, Bloomberg’s AI Startups to Watch (2026), Forbes AI 50, and Gartner’s Tech Innovators in Agentic AI, Glean continues to accelerate its global impact. With customers across 50+ industries and 1,000+ employees in more than 25 countries, we’re helping the world’s largest organizations make every employee AI-fluent, and turning the superintelligent enterprise from concept into reality.
 
If you’re excited to shape how the world works, you’ll help build systems used daily across Microsoft Teams, Zoom, ServiceNow, Zendesk, GitHub, and many more - deeply embedded where people get things done. You’ll ship agentic capabilities on an open, extensible stack, with the craft and care required for enterprise trust, as we bring Work AI to every employee, in every company.

About the Role:

Glean is looking for a Supply Chain Security Engineer with a primary focus on ensuring that our entire technology stack is free of software vulnerabilities (CVEs). This role is responsible for securing our base OS images, ensuring all open-source software (OSS) dependencies are scanned and patched, and integrating cutting-edge security tools into our CI/CD pipeline.

You Will:

  • Implement and improve the vulnerability management lifecycle, ensuring our entire tech stack is free from known vulnerabilities/CVEs.
  • Continuously scan, monitor, and patch OSS dependencies to mitigate supply chain risks and enforce best practices for dependency management by integrating artifact scanning processes in CI/CD.
  • Help build and execute our software supply chain security strategy to expand upon Glean’s ability to deploy secure-by-default open-source artifacts, etc., across the enterprise.
  • Improve the supply chain vulnerability scoring mechanism to take into account the environmental/impact controls and the reachability factors.
  • Research on ways to reduce the supply chain vulnerability footprint across Python, Java, GO, npm ecosystems and base layers.
  • Create hardened images which can be used across multiple deployment stacks.
  • Lead and contribute to Software Supply Chain Security initiatives, including SBOM generation and consumption, vulnerability prioritisation, automated fix pipeline, build provenance, artifact signing, signature verification, and trusted release workflows.
  • Design automation and policy-driven controls that help teams prove what was built, where it came from, and whether it can be trusted before deployment.
  • Develop and manage secure software supply chain usage guidelines and documentation.
  • Get Glean FEDRAMP ready with respect to vulnerability management.

About You:

  • BA/BS in Computer Science, Cybersecurity, or a related field (or equivalent industry experience).
  • 3+ years of experience in application security and vulnerability management.
  • Deep understanding of software security vulnerabilities, including CVEs, OWASP Top 10, and supply chain risks.
  • Deep understanding security design principles including but not limited to authentication, authorisation, RBAC, database security.
  • Strong understanding of software supply chain components and management
  • Strong understanding of software supply chain security threats and vulnerabilities
  • Strong familiarity with package managers (npm, pip, Maven, Go modules) and securing open-source dependencies.
  • Coding experience in languages such as Go, Python, Java, or C++ to develop security test cases and tooling.
  • Hands-on experience with cloud-native security best practices across AWS, GCP, or Azure.
  • Experience with handling FEDRAMP audit cycles for vulnerability management
  • Knowledge of container security, Kubernetes security, and securing microservices architectures.
  • Ability to lead cross-functional initiatives and drive security adoption within engineering teams.
  • A strong proactive approach to security, identifying risks before they become problems.
  • Excellent problem-solving skills and the ability to balance security with performance and usability.
  • Experience working in fast-paced, highly collaborative environments where security is a shared responsibility.
  • Passion for open-source security and keeping up with the latest trends in software vulnerability management.

Location:

  • This role is hybrid (3 days a week in our Bangalore office)

Compensation & Benefits:

Compensation offered will be determined by factors such as location, level, job-related knowledge, skills, and experience. Certain roles may be eligible for variable compensation, equity, and benefits.

We are a diverse bunch of people and we want to continue to attract and retain a diverse range of people into our organization. We're committed to an inclusive and diverse company. We do not discriminate based on gender, ethnicity, sexual orientation, religion, civil or family status, age, disability, or race.

#LI-HYBRID

 
AI-First Mindset at Glean:
 
At Glean, AI fluency is core to how we work and we're committed to ensuring every new hire feels confident integrating AI into their everyday work. As part of the interview process, you'll complete a brief AI-focused exercise or discussion so we can understand how you think about, design, and use AI to drive impact in your role. Feel free to reference any tools, platforms, or workflows you use today — prior Glean experience isn't required.
 
Global Data Privacy Notice for Job Candidates and Applicants:
 
Depending on your location, the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), or other privacy laws may regulate the way we manage the data of job applicants. Our full notice outlining how data will be processed as part of the application procedure for applicable locations is available in our Privacy Policy. By submitting your application, you are agreeing to our use and processing of your data as required. US applicants and their applications are subject to arbitration of disputes as outlined in our Applicant Arbitration Agreement.

By clicking “Submit Application,” I confirm that I have read the Global Data Privacy Notice and the Applicant Arbitration Agreement, and I agree to the terms.  

Create a Job Alert

Interested in building your career at Glean? Get future opportunities sent straight to your email.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Select...

We work out of the Palo Alto office on Monday, Wednesday, and Friday.

Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in Glean’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...