Senior Security Engineer
Glia
| Company | Glia |
| Category | Engineering |
| Location | Estonia - Remote |
| Remote | Remote |
| Employment | Not stated |
| Level | Senior |
| Salary | Not stated by the employer |
| Posted | 28 Jul 2026 |
| Last verified | 30 Jul 2026 |
| Source | Employer career page (ashby) |
Description
About Glia
Glia is the #1 Banking AI platform, empowering community and regional financial institutions to create efficiencies, accelerate loan growth, drive deposits, and deliver experiences that win against megabanks and fintechs.
Glia's Banking AI Operating System is a central intelligence layer on top of existing tech stacks, activating an AI workforce of specialized agents that draw from banking data, interaction history, and integrated systems of record. These banking-trained agents automate workflows across voice and digital–from front office to back office–resulting in decreased operational costs and the Universal Banker model.
Trusted by 700+ banks and credit unions for its ironclad security and reliability, Glia delivers the industry’s first contractual no-hallucination guarantee. It’s why Glia customers quickly and confidently put Banking AI to work with measurable results from day one. More information about Glia can be found at glia.com http://glia.com.
The DevSec team owns developer-facing and platform security at Glia — building guardrails and paved paths that let product teams move fast, safely. There is a saying in Glia: security is not just a feature, it's a part of our service.
THE ROLE
We're looking for a Senior Security Engineer who thinks about security end to end — not one domain deep, but the whole posture: application, infrastructure, supply chain, endpoints, operations, and the compliance surface behind them.
- You will co-own the company security roadmap together with our Security Leader, balancing domains by risk — while staying a hands-on technical contributor.
- You will own security programs end-to-end: from roadmap shaping and stakeholder alignment through implementation and adoption.
- This role carries a realistic growth path to DevSec Team Lead — a player-coach role: leading the team's delivery and growth while remaining deeply hands-on, with career progression on the engineering IC track.
THE WORK
The role spans the whole security surface, prioritising by risk rather than by specialty:
- Application & product security — threat modelling, secure SDLC, design/code review, supply chain security
- Infrastructure & cloud security — AWS posture, runtime security, IAM; close collaboration with the Infrastructure team
- Security automation & AI — develop and own automation and AI tooling supporting company security goals; secure our AI-assisted development practices and LLM tooling
- Endpoint & corporate security — developer endpoint security (MDM, privilege, software governance), secrets hygiene
- Whole-posture assessment — run framework-based assessments (CIS Controls), identify where attention bears most value, and turn findings into prioritised, engineering-consumable plans
- Compliance interface — connect technical work to SOC 2 / PCI-DSS / ISO 42001 needs
- Mentor engineers, lead blameless post-mortems for security incidents, and present to and align senior management
DevSec is part of the Platform group and works closely with Infrastructure, Developer Acceleration, and Observability. The team is remote-first with fully remote rituals — we have team members in Estonia and Poland today, and for this role we hire anywhere in Europe.
TECH STACK YOU WILL BE WORKING WITH
- Infrastructure: AWS (Terraform, Kubernetes)
- CI/CD: GitHub Actions
- Vulnerability detection & runtime security: Snyk, Sysdig/Falco
- SSO & MDM: Okta, Jamf
- Coding: Python preferred; our product stack includes Elixir, Ruby, and Golang
- AI-assisted development: Claude Code and agentic tooling are part of everyday engineering at Glia
REQUIREMENTS
- Credible hands-on experience in at least two security domains (e.g. AppSec + cloud/infra) and literacy across the rest — you think in overall posture and risk, not tools
- You have built or scaled a security program end-to-end (process, tooling, adoption), ideally in a low-structure environment