Engineering Manager, Software Supply Chain Security: Pipeline Security

1 hour, 48 minutes ago
GitLab

GitLab

GitLab: The comprehensive DevOps platform revolutionizing software development with automation, AI workflows, and essential tools for efficient collaboration.

Internet Software & Services
1K-5K
Founded 2014

Description

  • Lead a team of engineers building software supply chain security features with a focus on CI job artifact security.
  • Guide the design and implementation of SLSA compliance within GitLab CI/CD pipelines.
  • Collaborate with Product Managers to define, prioritize, and deliver the roadmap for supply chain security capabilities.
  • Partner with Security team members to ensure features meet GitLab security standards and best practices.
  • Stay current on supply chain security standards and tools such as SLSA, SBOM, software composition analysis, and vulnerability management, and translate insights into product improvements.
  • Educate and advocate for supply chain security best practices across engineering teams to drive adoption of secure CI pipeline patterns.
  • Represent the Pipeline Security team in cross-functional initiatives and, when appropriate, external industry forums.
  • Drive continuous improvement in team health, delivery predictability, and documentation quality.
  • Develop a native secrets management system for GitLab CI pipelines.
  • Work on artifact provenance, verification, and SLSA Level 3 compliance features.

Requirements

  • Experience leading and developing engineering teams, with a focus on building secure, reliable product features.
  • Practical knowledge of software supply chain security concepts, tools, and industry standards.
  • Understanding of the SLSA framework and how to apply it in CI/CD pipelines.
  • Familiarity with software artifact provenance, attestation, and verification techniques.
  • Knowledge of secure software development practices, including container security, software composition analysis, and vulnerability management.
  • Experience working with CI/CD systems and their security considerations.
  • Ability to collaborate effectively with product management, security, and other cross-functional partners.
  • Openness to learning new technologies and approaches, with transferable skills from related security, infrastructure, or software engineering domains.
  • Experience in a globally distributed, asynchronous team environment is beneficial.
  • Prior experience with GitLab CI/CD or similar DevSecOps platforms is preferred.

Benefits

  • United States base salary range of $131,600 to $282,000 USD.
  • Benefits to support your health, finances, and well-being.
  • Flexible Paid Time Off.
  • Equity compensation and an Employee Stock Purchase Plan.
  • Growth and Development Fund.
  • Parental leave.
  • Home office support.
  • Team Member Resource Groups.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Engineering Manager, Content Creation

Panopto 51-250 Media

Panopto is hiring a remote Engineering Manager to lead its Content Generation team and advance AI-driven content pipelines for a rapidly growing video learning platform.

AWS Azure GCP Generative AI JavaScript Machine Learning MongoDB Node.js React
3 minutes ago

Engineering Manager

Copper 51-250 Internet Software & Services

Copper is hiring an Engineering Manager to lead the Automations and Integrations team in building reliable, high-impact workflows for a Google Workspace-native client and project management platform serving professional services businesses.

CRM Go JavaScript Ruby on Rails
3 minutes ago

Engineering Manager

DBSync 51-250 Internet Software & Services

DBSync is hiring an Engineering Manager/Architect to lead its engineering organization in building and scaling cloud data integration products for SaaS and enterprise customers.

Agile AWS Bootstrap CRM Docker E-commerce HTML Java JavaScript Kubernetes Microservices MySQL Salesforce SQL SQL Server XML
3 minutes ago

Software Engineering Manager

Anytime Mailbox 51-250 Professional Services

Software Engineering Manager at Anytime Mailbox, leading a Microsoft-stack engineering team in an Agile environment to deliver high-quality product solutions and drive team growth.

Agile Azure C# CI/CD .NET Scrum
18 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers