Supply Chain Security Engineer positions focus on delivering results in their domain. This page aggregates open Supply Chain Security Engineer roles and what employers typically expect.
About Glean: Glean is the Work AI platform that helps everyone work smarter with AI. What began as the industry’s most advanced enterprise search has evolved into a full-scale Work AI ecosystem, powering intelligent Search, an AI Assistant, and scalable AI agents on one secure, open platform. With over 100 enterprise SaaS connectors, flexible LLM choice, and robust APIs, Glean gives organizations the infrastructure to govern, scale, and customize AI across their entire business - without vendor lock-in or costly implementation cycles. At its core, Glean is redefining how enterprises find, use, and act on knowledge. Its Enterprise Graph and Personal Knowledge Graph map the relationships between people, content, and activity, delivering deeply personalized, context-aware responses for every employee. This foundation powers Glean’s agentic capabilities - AI agents that automate real work across teams by accessing the industry’s broadest range of data: enterprise and world, structured and unstructured, historical and real-time. The result: measurable business impact through faster onboarding, hours of productivity gained each week, and smarter, safer decisions at every level. Recognized by Fast Company as one of the World’s Most Innovative Companies (Top 10, 2025), by CNBC’s Disruptor 50, Bloomberg’s AI Startups to Watch (2026), Forbes AI 50, and Gartner’s Tech Innovators in Agentic AI, Glean continues to accelerate its global impact. With customers across 50+ industries and 1,000+ employees in more than 25 countries, we’re helping the world’s largest organizations make every employee AI-fluent, and turning the superintelligent enterprise from concept into reality. If you’re excited to shape how the world works, you’ll help build systems used daily across Microsoft Teams, Zoom, ServiceNow, Zendesk, GitHub, and many more - deeply embedded where people get things done. You’ll ship agentic capabilities on an open, extensible stack, with the craft and care required for enterprise trust, as we bring Work AI to every employee, in every company. About the Role: Glean is looking for a Supply Chain Security Engineer with a primary focus on ensuring that our entire technology stack is free of software vulnerabilities (CVEs). This role is responsible for securing our base OS images, ensuring all open-source software (OSS) dependencies are scanned and patched, and integrating cutting-edge security tools into our CI/CD pipeline. You Will: Implement and improve the vulnerability management lifecycle, ensuring our entire tech stack is free from known vulnerabilities/CVEs. Continuously scan, monitor, and patch OSS dependencies to mitigate supply chain risks and enforce best practices for dependency management by integrating artifact scanning processes in CI/CD. Help build and execute our software supply chain security strategy to expand upon Glean’s ability to deploy secure-by-default open-source artifacts, etc., across the enterprise. Improve the supply chain vulnerability scoring mechanism to take into account the environmental/impact controls and the reachability factors. Research on ways to reduce the supply chain vulnerability footprint across Python, Java, GO, npm ecosystems and base layers. Create hardened images which can be used across multiple deployment stacks. Lead and contribute to Software Supply Chain Security initiatives, including SBOM generation and consumption, vulnerability prioritisation, automated fix pipeline, build provenance, artifact signing, signature verification, and trusted release workflows. Design automation and policy-driven controls that help teams prove what was built, where it came from, and whether it can be trusted before deployment. Develop and manage secure software supply chain usage guidelines and documentation. Get Glean FEDRAMP ready with respect to vulnerability management. About You: BA/BS in Computer Science, Cybersecurity, or a related field (or equivalent industry experience). 3+ years of experien…