Engineering Manager, Software Supply Chain Security: Pipeline Security

GitLab

Remote, US
Base: $131,600 - $282,000 usd; bonus/equity: not s...
Remote
Lead engineering team for supply chain security
Implement slsa framework in ci/cd pipelines
Experience with sbom and software composition analysis
This role leads a team dedicated to making GitLab CI pipelines more secure by implementing the SLSA framework and managing artifact security

Job Summary

  • This role leads a team dedicated to making GitLab CI pipelines more secure by implementing the SLSA framework and managing artifact security.
  • The position requires close collaboration with Product Management and Security teams to define roadmaps for native secrets management and compliance features.
  • GitLab offers a high-performance culture driven by values, continuous knowledge exchange, and the integration of AI into daily workflows.

Matching Summary

This role leads a team dedicated to making GitLab CI pipelines more secure by implementing the SLSA framework and managing artifact security.

Salary

Base: $131,600 - $282,000 USD; Bonus/Equity: Not specified; Benefits: Flexible PTO, Health, Stock Options

Skills & Requirements

Must-have

  • Lead engineering team for supply chain security
  • Implement SLSA framework in CI/CD pipelines
  • Experience with SBOM and software composition analysis
  • Knowledge of container security and vulnerability management
  • Collaborate with Product Management on roadmap delivery

Nice-to-have

  • Advocate for secure development best practices
  • Represent team in external industry forums
  • Drive continuous improvement in team health
  • Asynchronous collaboration across global time zones
  • Openness to learning new AI-driven approaches

Key Requirements

  • Experience leading engineering teams in secure product development
  • Practical knowledge of software supply chain security standards
  • Understanding of SLSA framework application in CI/CD
  • Familiarity with software artifact provenance and attestation
  • Knowledge of secure software development practices

Work Rights

Not specified

Tailored Resume

Cover Letter