Senior Backend Engineer, SSCS: Supply Chain

1 month, 1 week ago
Full-time
Senior
Software Development
GitLab

GitLab

GitLab: The comprehensive DevOps platform revolutionizing software development with automation, AI workflows, and essential tools for efficient collaboration.

Internet Software & Services
1K-5K
Founded 2014

Description

  • Design and implement backend features across the software supply chain security Add-On, including policy enforcement, signing and verification, provenance attestation, and malicious package detection integrations.
  • Build and improve the package policy evaluation engine, including rule compilation, request matching, enforcement decisions, and performance-sensitive execution paths.
  • Develop artifact signing and verification workflows using Sigstore and Cosign, including signing key lifecycle management, keyless signing with OIDC, and policy-based promotion gates.
  • Create and evolve backend APIs and GraphQL interfaces for enterprise security teams to express supply chain security requirements.
  • Integrate Add-On capabilities with GitLab's security policy framework, including policy inheritance and policy-as-code support through YAML.
  • Collaborate with adjacent teams to incorporate malicious package intelligence into the Add-On offering.
  • Write and maintain comprehensive RSpec and integration tests, and help improve test reliability across the team.
  • Review merge requests with a security-first mindset and help implement solutions with substantial decision-making scope.

Requirements

  • Production experience with Ruby on Rails backend engineering.
  • Working knowledge of Go or the ability and willingness to ramp up quickly.
  • Experience designing APIs, including REST and GraphQL, and defining clear internal service boundaries.
  • Strong PostgreSQL fundamentals, including schema design, query optimization, and indexing strategies.
  • Experience with Redis for caching and distributed coordination patterns.
  • A security-aware engineering mindset with sound judgment around trust boundaries, input validation, and failure modes.
  • Familiarity with software supply chain security concepts such as SLSA, SBOM, artifact signing, or related security scanning approaches.
  • Interest in complex policy, registry, or platform problems such as rules engines, package ecosystems, cryptographic signing, or DevSecOps product development.

Benefits

  • Benefits to support health, finances, and well-being.
  • Flexible Paid Time Off.
  • Equity compensation and an Employee Stock Purchase Plan.
  • Growth and Development Fund.
  • Parental leave.
  • Home office support.
  • Team Member Resource Groups.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Backend Engineer - Platform - Stacks | UK | Remote

Grafana 1K-5K IT Services

Grafana Labs is hiring a Backend Engineer for its Platform Stacks team to build and operate the systems that create, configure, reconcile, and manage Grafana Cloud stacks across regions and services.

AWS Azure Flux GCP Go Grafana Helm Kubernetes Microservices Node.js Terraform TypeScript
1 hour, 25 minutes ago

Senior Backend Engineer (Elixir)

Remote 251-1K Professional Services

Remote is hiring a full-time engineer to help build tools, APIs, and integrations for its global HR and Payroll products in a fully remote, async environment.

Angular AWS CI/CD Docker Elixir GitHub GitLab Jenkins Kubernetes Next.js Phoenix PostgreSQL React Vue.js
2 hours, 5 minutes ago

Senior Backend Engineer - Grafana Search & Storage | Spain | Remote

Grafana 1K-5K IT Services

Grafana Labs is hiring a Senior Backend Engineer to help build and operate its next-generation search and storage platform for Grafana Cloud and related products.

Go Grafana Kubernetes Prometheus
2 hours, 34 minutes ago

Software Engineer II - Model Platform

Abnormal AI Internet Software & Services

Abnormal AI is hiring a Software Backend Engineer II to join its Detection Team and build the Model Platform infrastructure that supports ML and Data Science work on advanced email and cloud attack detection.

AWS Azure Django GCP Go Kubernetes Machine Learning OWASP PostgreSQL Python
2 hours, 51 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers