Engineering Manager, Software Supply Chain Security: Pipeline Security jobs in United States
cer-icon
Apply on Employer Site
company-logo

GitLab · 18 hours ago

Engineering Manager, Software Supply Chain Security: Pipeline Security

GitLab is an open-core software company that develops an AI-powered DevSecOps Platform used by over 100,000 organizations. The Engineering Manager will lead a team focused on enhancing the security of CI pipelines and implementing software supply chain security features, ensuring compliance with industry standards.

Cloud SecurityDeveloper ToolsDevOpsOpen SourceSaaS
check
Comp. & Benefits

Responsibilities

Lead a team of engineers building Software Supply Chain Security features with a focus on CI job artifact security
Guide the design and implementation of SLSA (Supply-chain Levels for Software Artifacts) compliance within GitLab CI/CD pipelines
Collaborate with Product Managers to define, prioritize, and deliver the roadmap for supply chain security capabilities
Partner with Security team members to ensure new and existing features meet GitLab’s security standards and align with best practices
Stay current with software supply chain security standards and tools, including SLSA, SBOM, software composition analysis, and vulnerability management. Translate what you learn into actionable product improvements
Educate and advocate for supply chain security best practices across engineering teams to drive adoption of secure patterns in CI pipelines
Represent the Pipeline Security team in cross-functional initiatives and, when appropriate, in external industry forums focused on software supply chain security
Drive continuous improvement in team health, delivery predictability, and documentation quality for pipeline and supply chain security features

Qualification

Software Supply Chain SecuritySLSA FrameworkCI/CD SystemsVulnerability ManagementSoftware Composition AnalysisSecure Software DevelopmentOpenness to LearningTeam LeadershipCollaboration Skills

Required

Experience leading and developing engineering teams, with a focus on building secure, reliable product features
Practical knowledge of software supply chain security concepts, tools, and industry standards
Understanding of the SLSA (Supply-chain Levels for Software Artifacts) framework and how to apply it in CI/CD pipelines
Familiarity with software artifact provenance, attestation, and verification techniques
Knowledge of secure software development practices, including container security, software composition analysis, and vulnerability management
Experience working with CI/CD systems and their security considerations
Ability to collaborate effectively with product management, security, and other cross-functional partners, and to advocate for supply chain security best practices
Openness to learning new technologies and approaches, with transferable skills from related security, infrastructure, or software engineering domains

Benefits

Benefits to support your health, finances, and well-being
Flexible Paid Time Off
Team Member Resource Groups
Equity Compensation & Employee Stock Purchase Plan
Growth and Development Fund
Parental leave
Home office support

Company

GitLab is a web-based Git repository manager that offers a variety of features for software development teams.

Funding

Current Stage
Public Company
Total Funding
$413.5M
Key Investors
ICONIQ GrowthGoogle VenturesAugust Capital
2021-10-14IPO
2019-09-17Series E· $268M
2018-09-19Series D· $100M

Leadership Team

leader-logo
Bill Staples
Chief Executive Officer
linkedin
leader-logo
Sytse Sijbrandij
Co-Founder and Executive Chair
linkedin
Company data provided by crunchbase