About the job
At GitLab, we are on a mission to revolutionize software development through our cutting-edge AI-powered DevSecOps Platform, trusted by over 100,000 organizations worldwide. Our goal is to empower everyone to contribute to and create the software that shapes our future. By fostering a culture where consumers become contributors, we accelerate human progress and innovation. Our platform facilitates seamless collaboration across teams and organizations, breaking down barriers and redefining the possibilities in software development. With products like Duo Enterprise and Duo Agent Platform, we integrate AI across the entire Software Development Life Cycle (SDLC) for maximum efficiency.
At GitLab, we embrace AI as a fundamental productivity enhancer. Every team member is encouraged to weave AI into their daily tasks, driving innovation, efficiency, and impact. Join us where your career can soar, innovation is nurtured, and every voice is heard. Our high-performance culture, anchored by our core values, promotes continuous knowledge sharing, allowing our team members to achieve their full potential while working alongside industry leaders to tackle complex challenges. Join us in co-creating the future as we build technology that transforms how the world develops software.
Role Overview
As the Engineering Manager for Software Supply Chain Security: Pipeline Security, you will lead a dedicated team focused on enhancing the security and trustworthiness of GitLab CI pipelines for thousands of organizations. You will oversee the design and delivery of critical Software Supply Chain Security features, concentrating on CI job artifact security. This includes the implementation of the SLSA (Supply-chain Levels for Software Artifacts) framework in GitLab CI/CD and the integration of essential capabilities like SBOM, software composition analysis, and vulnerability management. Your role will involve treating your team as a product, ensuring team well-being, recruiting and nurturing a high-performing group of engineers, and working closely with Product Management and Security to fulfill roadmap commitments. Together, you will enhance users' ability to safeguard their software supply chains.
Some examples of our projects:

