About the job
GitLab is the cutting-edge orchestration platform for DevSecOps, empowering organizations to elevate developer productivity, enhance operational efficiency, mitigate security and compliance risks, and expedite digital transformation. Trusted by over 50 million registered users and more than half of the Fortune 100 companies, GitLab helps teams deliver superior and more secure software at an accelerated pace.
Our team embodies the same principles that drive our products: we leverage AI as a foundational productivity enhancer, expecting all team members to integrate AI into their daily workflows to foster efficiency, innovation, and impactful results. At GitLab, careers thrive, innovation flourishes, and every voice is heard. Our high-performance culture is guided by our values and a commitment to continuous knowledge sharing, allowing each team member to maximize their potential while collaborating with industry leaders to tackle complex challenges. Join us in co-creating the future as we develop transformative technology for software development.
Fortune 500® is a registered trademark of Fortune Media IP Limited, used under license. Claim based on GitLab data. Fortune 100 refers to the top 20% ranked companies in the 2025 Fortune 500 list, published in June 2025. Fortune and Fortune Media IP Limited are not affiliated with, and do not endorse products or services of GitLab.
Role Overview
As the Engineering Manager for Composition Analysis, you will lead a dedicated team focused on developing software composition analysis capabilities that assist GitLab customers in identifying and resolving vulnerabilities in their application dependencies and software supply chain. You will guide engineers working on software composition analysis and container scanning, and be responsible for establishing priorities, shaping product architecture, and implementing agile processes to maintain the effectiveness, reliability, and usability of our security solutions in real DevSecOps environments.
Your role will require you to navigate complex, security-centered roadmaps and draft project plans that ensure customers enjoy a robust composition analysis experience within GitLab. In your first year, you will spearhead critical initiatives such as auto-remediation of vulnerable packages, AI-driven auto-fixes for breaking changes, scanning unmanaged C/C++ dependencies, static reachability analysis, and snippet detection for open-source dependencies.
Examples of our projects include:
- Creating hyper-scale vulnerability detection engines for millions of GitLab users globally.
- Designing auto-remediation workflows for vulnerable open-source and third-party dependencies.

