GitLab

Build software faster. The One DevOps Platform enables your entire org to collaborate around your code. We're hiring.

Engineering Manager, Software Supply Chain Security – Pipeline Security

Engineering ManagerEngineering ManagerFull TimeRemoteTeam 1,001-5,000Since 2014H1B No SponsorCompany SiteLinkedIn

Location

United States

Posted

86 days ago

Salary

$131.6K - $282K / year

Bachelor DegreeEnglish

Job Description

• Lead a team of engineers building Software Supply Chain Security features with a focus on CI job artifact security. • Guide the design and implementation of SLSA (Supply-chain Levels for Software Artifacts) compliance within GitLab CI/CD pipelines. • Collaborate with Product Managers to define, prioritize, and deliver the roadmap for supply chain security capabilities. • Partner with Security team members to ensure new and existing features meet GitLab’s security standards and align with best practices. • Stay current with software supply chain security standards and tools, including SLSA, SBOM, software composition analysis, and vulnerability management. Translate what you learn into actionable product improvements. • Educate and advocate for supply chain security best practices across engineering teams to drive adoption of secure patterns in CI pipelines. • Represent the Pipeline Security team in cross-functional initiatives and, when appropriate, in external industry forums focused on software supply chain security. • Drive continuous improvement in team health, delivery predictability, and documentation quality for pipeline and supply chain security features.

Job Requirements

  • Experience leading and developing engineering teams, with a focus on building secure, reliable product features.
  • Practical knowledge of software supply chain security concepts, tools, and industry standards.
  • Understanding of the SLSA (Supply-chain Levels for Software Artifacts) framework and how to apply it in CI/CD pipelines.
  • Familiarity with software artifact provenance, attestation, and verification techniques.
  • Knowledge of secure software development practices, including container security, software composition analysis, and vulnerability management.
  • Experience working with CI/CD systems and their security considerations.
  • Ability to collaborate effectively with product management, security, and other cross-functional partners, and to advocate for supply chain security best practices.
  • Openness to learning new technologies and approaches, with transferable skills from related security, infrastructure, or software engineering domains.

Benefits

  • Benefits to support your health, finances, and well-being
  • Flexible Paid Time Off
  • Team Member Resource Groups
  • Equity Compensation & Employee Stock Purchase Plan
  • Growth and Development Fund
  • Parental leave
  • Home office support

Related Categories

Related Job Pages

More Engineering Manager Jobs

Senior Engineering Manager, Replication and Storage

Redpanda Data

Redpanda is pioneering the Agentic Data Plane (ADP) - a new category in AI infrastructure that makes it simple and secure to connect AI agents with enterprise data and systems. Global leaders including Activision Blizzard, Cisco, Moody's, Texas Instruments, Vodafone and 2 of the top 5 banks in the U.S. rely on Redpanda to process hundreds of terabytes of data a day. Join Redpanda if you’d enjoy being part of a fast-moving, 100% remote organization with team members around the globe and a culture based on trust, transparency, communication, and kindness.

Engineering Manager86 days ago
Full TimeRemoteTeam 197Since 2019

We are looking for an experienced Senior Engineering Manager to lead a team of distributed systems engineers working on Redpanda. Work with and guide a distributed engineering team that is solving highly unique and complex problems in distributed consensus, transactions and our S...

C++CRustLinuxRPCRaftPaxosProfilingBenchmarkingDatabaseStorageDistributed Systems
United States
$231K - $275K / year

Software Development Manager

Law School Admission Council (LSAC)

LSAC is a not-for-profit organization committed to quality, access, and equity in law and education.

Engineering Manager87 days ago
Full TimeRemoteTeam 201-500Since 1947H1B No Sponsor

Technical Software Development Manager focusing on agile product strategies

AzureNoSQLReactSQL.NET
Pennsylvania
$130K - $145K / year

Engineering Manager – Crypto

Underdog Fantasy

Underdog Fantasy is one of the fastest-growing fantasy sports companies on the market.

Engineering Manager87 days ago
Full TimeRemoteTeam 201-500H1B No Sponsor

Engineering Manager leading new crypto initiatives for sports entertainment app

United States
$208K - $310K / year

VP of Engineering

Runwise

A smarter way to run your building.

Engineering Manager87 days ago
Full TimeRemoteTeam 11-50H1B No Sponsor

VP of Engineering at Runwise leading technology for urban infrastructure.

IoTPythonSQLGo
United States
$250K - $280K / year