Base: $131,600 - $282,000 usd; bonus/equity: not s...
Remote
Software composition analysis expertise
Dependency scanning and container scanning
Backend technologies go and/or ruby on rails
As a Staff Engineer on GitLab's Software Composition Analysis team, you'll drive hands-on implementation of security features that help customers understand and manage risks in their software supply chain
Job Summary
As a Staff Engineer on GitLab's Software Composition Analysis team, you'll drive hands-on implementation of security features that help customers understand and manage risks in their software supply chain.
You'll implement complex features in dependency scanning and container scanning, shipping improvements that increase scan coverage, improve accuracy, and drive adoption of GitLab's SCA capabilities.
GitLab offers benefits to support your health, finances, and well-being, flexible Paid Time Off, Team Member Resource Groups, and equity compensation.
Matching Summary
As a Staff Engineer on GitLab's Software Composition Analysis team, you'll drive hands-on implementation of security features that help customers understand and manage risks in their software supply chain.
Salary
Base: $131,600 - $282,000 USD; Bonus/Equity: Not specified; Benefits: Not specified
Skills & Requirements
Must-have
Software Composition Analysis expertise
dependency scanning and container scanning
backend technologies Go and/or Ruby on Rails
distributed async-first teams
technical mentorship
Nice-to-have
AI in daily workflows
continuous knowledge exchange
innovative collection techniques
solving novel technical challenges
Key Requirements
Hands-on experience in Software Composition Analysis
Deep hands-on expertise in building and evolving dependency scanning and container scanning capabilities
Ability to design solutions that balance complexity, performance, and maintainability
Expertise with backend technologies, particularly Go and/or Ruby on Rails
Ability to evaluate technical tradeoffs in SCA and security tooling
Ability to work effectively in distributed, async-first teams across multiple time zones
Experience explaining complex technical and security concepts