Role in brief
GitLab is seeking an Engineering Manager for their Composition Analysis team. This role involves leading engineers to develop and enhance software composition analysis and container scanning capabilities, helping customers identify and fix vulnerabilities in application dependencies. Candidates with experience in application security, cloud security, or DevSecOps, and familiarity with open-source security tools, should consider applying.
About the role
This Engineering Manager position focuses on leading a team dedicated to software composition analysis and container scanning. The primary goal is to help GitLab customers detect and resolve vulnerabilities within their application dependencies and software supply chain. The role involves guiding engineers, setting priorities, shaping product architecture, and managing agile processes to ensure security offerings are effective and reliable in DevSecOps environments.
Key responsibilities include driving initiatives such as auto-remediation of vulnerable packages, scanning unmanaged C/C++ dependencies, and static reachability analysis. The manager will also be responsible for authoring project plans and balancing team priorities to ensure consistent delivery of high-quality outcomes. Collaboration with the team is essential to maintain a unified approach to application security across the GitLab platform.
Success in this role means delivering a robust composition analysis experience for GitLab customers. This involves balancing a complex, security-focused roadmap with practical implementation. The manager will provide architectural guidance for security solutions, ensuring they are scalable and effective, while also coordinating with product and architecture decisions to meet customer needs.
The salary range for this position is between $80,500 and $138,000 USD.
Skills that matter here
- application security: This role requires a background in application security to lead a team focused on identifying and mitigating software vulnerabilities.
- cloud security: Experience in cloud security is relevant for understanding modern deployment environments where software composition analysis is critical.
- software composition analysis: A practical understanding of software composition analysis is essential for assessing and managing risks in application dependencies.
- containerization technologies: Familiarity with containerization technologies is necessary as the role involves container scanning capabilities.
- package managers: Knowledge of package managers is important for understanding how software dependencies are managed and scanned.
- open source security tooling: Experience with open source security tools is beneficial for guiding the team's work on security analysis.
Who this role suits
- A leader who can balance complex technical roadmaps with practical implementation and agile processes.
- Someone with a background in application security or cloud security, capable of guiding a technical team.
- An individual who can plan and coordinate priorities, ensuring consistent delivery of security solutions.
- A person who can provide architectural guidance for security scanning tools while considering customer needs.
From the employer
- Lead engineers across the Composition Analysis team, setting clear priorities and expectations.
- Drive key security initiatives, including auto-remediation of vulnerable software packages, scanning unmanaged C/C++ dependencies, static reachability analysis, and snippet detection for open source dependencies.
- Balance priorities and resources across the Composition Analysis team to ensure sustainable delivery and high-quality outcomes.
- Author and maintain project plans for epics within the Composition Analysis team, aligning work, identifying dependencies, and ensuring quality delivery.
- Run agile project management processes for the Composition Analysis team, including planning, estimation, and continuous improvement of delivery practices.
- Provide guidance on the architecture of software composition analysis solutions, ensuring they are robust, scalable, and effective.
- Collaborate closely with the Composition Analysis team to ensure consistent, high-quality approaches to application security across GitLab's platform.
- Background leading multiple technical teams or groups, ideally in application security or cloud security.
- Practical understanding of software composition analysis, including how to assess and manage risks in application dependencies.
- Familiarity with containerization technologies, package managers, and dependency management systems.
- Experience working with or around open source security tooling (for example, Syft, Grype, Trivy, or similar tools).
- Ability to plan and run agile project management processes for the Composition Analysis team, including coordinating priorities and dependencies.
- Skill in guiding product and architecture decisions for security scanning tools, balancing technical constraints with customer needs.
- Openness to candidates with transferable experience in security engineering, DevSecOps, or vulnerability management who are motivated to grow in application security leadership.
Questions about this role
What is the remote work policy for this position?
This is a fully remote position.
What is the seniority level for this role?
This is a middle-seniority position.
What are some of the key technical areas this role will focus on?
The role will focus on application security, cloud security, software composition analysis, and containerization technologies, including working with open source security tooling.