Software Engineering Manager, Application Security Testing: Composition Analysis & Dynamic Analysis jobs in United States
cer-icon
Apply on Employer Site
company-logo

GitLab · 2 weeks ago

Software Engineering Manager, Application Security Testing: Composition Analysis & Dynamic Analysis

GitLab is an open-core software company that develops the most comprehensive AI-powered DevSecOps Platform, used by more than 100,000 organizations. As an Engineering Manager for Composition Analysis and Dynamic Analysis, you will lead multiple teams to build application security scanning capabilities that help customers find and fix vulnerabilities in their software supply chain and web applications.

Cloud SecurityDeveloper ToolsDevOpsOpen SourceSaaS
check
Comp. & Benefits

Responsibilities

Lead engineers across the Composition Analysis and Dynamic Analysis groups, setting clear priorities and expectations
Drive key security initiatives, including auto-remediation of vulnerable software packages, scanning unmanaged C/C++ dependencies, static reachability analysis, and snippet detection for open source dependencies
Improve Dynamic Analysis Security Testing (DAST) capabilities by enhancing the crawler for efficiency, stability, and consistent web application traversal
Balance priorities and resources across multiple security-focused engineering teams to ensure sustainable delivery and high-quality outcomes
Author and maintain project plans for epics spanning both groups, aligning work, identifying dependencies, and avoiding duplication of effort
Run agile project management processes for multiple teams, including planning, estimation, and continuous improvement of delivery practices
Provide guidance on the architecture of security products, ensuring that software composition analysis and dynamic analysis solutions are robust and scalable
Collaborate closely with Composition Analysis and Dynamic Analysis teams to ensure consistent, complementary approaches to application security across GitLab’s platform

Qualification

Application SecurityDynamic Application Security TestingSoftware Composition AnalysisAPI SecurityContainerization TechnologiesAgile Project ManagementOpen Source Security ToolingDependency ManagementTechnical Decision MakingTeam Leadership

Required

Background leading multiple technical teams or groups, ideally in application security or related domains
Practical understanding of software composition analysis, including how to assess and manage risks in application dependencies
Knowledge of dynamic application security testing (DAST), API security, and web application security testing techniques and tools
Familiarity with containerization technologies, package managers, and dependency management systems
Experience working with or around open source security tooling (for example, OWASP ZAP, Trivy, or similar tools)
Ability to plan and run agile project management processes across several teams, including coordinating priorities and dependencies
Skill in guiding product and architecture decisions for security scanning tools, balancing technical constraints with customer needs
Openness to candidates with transferable experience in security engineering, DevSecOps, or vulnerability management who are motivated to grow in application security leadership

Benefits

Flexible Paid Time Off
Team Member Resource Groups
Equity Compensation & Employee Stock Purchase Plan
Growth and Development Fund
Parental leave
Home office support

Company

GitLab is a web-based Git repository manager that offers a variety of features for software development teams.

Funding

Current Stage
Public Company
Total Funding
$413.5M
Key Investors
ICONIQ GrowthGoogle VenturesAugust Capital
2021-10-14IPO
2019-09-17Series E· $268M
2018-09-19Series D· $100M

Leadership Team

leader-logo
Bill Staples
Chief Executive Officer
linkedin
leader-logo
Sytse Sijbrandij
Co-founder and Executive Chair
linkedin
Company data provided by crunchbase