At a Glance
- Tasks: Lead a team to develop innovative authorization systems for GitLab's platform.
- Company: GitLab is a leading open core software company with a mission to empower global collaboration.
- Benefits: Enjoy remote work, flexible time off, equity compensation, and a supportive work environment.
- Why this job: Make a significant impact on security and scalability while nurturing a talented team.
- Qualifications: Experience in authorization systems and identity management is essential; familiarity with policy-as-code is a plus.
- Other info: Open to candidates with varying experience levels; apply even if you don't meet every requirement.
The predicted salary is between 42000 - 84000 £ per year.
GitLab is an open core software company that develops the most comprehensive AI-powered DevSecOps Platform, used by more than 100,000 organizations. Our mission is to enable everyone to contribute to and co-create the software that powers our world. When everyone can contribute, consumers become contributors, significantly accelerating the rate of human progress. This mission is integral to our culture, influencing how we hire, build products, and lead our industry. We make this possible at GitLab by running our operations on our product and staying aligned with our values.
Thanks to products like Duo Enterprise and Duo Workflow, customers get the benefit of AI at every stage of the SDLC. The same principles built into our products are reflected in how our team works: we embrace AI as a core productivity multiplier. All team members are encouraged and expected to incorporate AI into their daily workflows to drive efficiency, innovation, and impact across our global organisation.
As an Engineering Manager for the Authorization team at GitLab, you will lead a talented group of engineers who are fundamentally transforming how permissions work across our platform. You will be at the forefront of our major authorization systems redesign initiative, guiding your team through exciting challenges like implementing Fine-Grained Access Control and developing our new policy-as-code approach.
At GitLab, we see our team as our product. While you will need to be technically credible in authorization frameworks and identity management, your primary focus will be on nurturing your team’s health, hiring exceptional talent, and positioning them for success. You will collaborate closely with Product Managers to shape the roadmap for modern authorization features that balance security, usability, and performance at scale. This is a unique opportunity to lead critical infrastructure work that touches every part of the GitLab platform while helping transform our permission systems to be more secure, scalable, and flexible.
Your leadership will be instrumental as we transition from our current Declarative Policies framework to a more sophisticated policy-based system that supports advanced multi-tenancy features and reinforces GitLab’s security posture. If you’re passionate about building teams and systems that enable secure collaboration at scale, this role offers the chance to make a significant impact on GitLab’s future.
What You’ll Do
- Lead a team focused on developing features for Software Supply Chain Security, with a primary focus on authorization systems and user permission models.
- Guide the implementation of advanced authorization controls across GitLab's platform.
- Collaborate with Product Managers to define and prioritize the roadmap for Supply Chain Security and authorization features in particular.
- Stay current with industry standards and best practices in identity and access management, particularly least-privilege and zero-trust access models.
- Partner with Security team members to ensure features meet the highest security standards.
- Educate and advocate for supply chain security best practices across GitLab.
- Represent GitLab in industry forums related to software supply chain security when appropriate.
What You’ll Bring
- Experience with authorization systems, identity management, and access control models.
- Understanding of policy-as-code approaches (ideally familiarity with Cedar, Rego, or similar policy languages).
- Knowledge of modern authorization frameworks like RBAC, ABAC, FGAC and context-aware authorization systems.
- Familiarity with identity federation concepts and tools.
- Strong technical leadership abilities to guide the team through complex architectural transitions.
- Experience implementing SLSA compliance in production environments is ideal, but not required.
Performance Indicators
- Successful implementation of components for the GitLab authorization components and IAM.
- Adoption rate of new authorization features by GitLab users.
- Reduction in security vulnerabilities related to authorization sub-systems.
- Integration completeness with other GitLab security features.
- Community engagement around GitLab's supply chain security capabilities.
- Documentation quality for supply chain security features.
About The Team
The Authorization team is responsible for building and maintaining GitLab's permission systems to be more secure, scalable, and flexible. We're currently embarking on a major authorization systems redesign initiative that will fundamentally transform how authorization works across GitLab. The team is focused on key projects including Fine-Grained Access Control, Policy Standardization, and developing a new policy-as-code approach that will replace our current Declarative Policies framework. This work is critical to GitLab's security posture, performance at scale, and ability to support advanced multi-tenancy features.
How GitLab Will Support You
- Benefits to support your health, finances, and well-being.
- All remote, asynchronous work environment.
- Flexible Paid Time Off.
- Team Member Resource Groups.
- Equity Compensation & Employee Stock Purchase Plan.
- Growth and Development Fund.
- Parental leave.
- Home office support.
Please note that we welcome interest from candidates with varying levels of experience; many successful candidates do not meet every single requirement. Additionally, studies have shown that people from underrepresented groups are less likely to apply to a job unless they meet every single qualification. If you’re excited about this role, please apply and allow our recruiters to assess your application.
The base salary range for this role’s listed level is currently for residents of listed locations only. Grade level and salary ranges are determined through interviews and a review of education, experience, knowledge, skills, abilities of the applicant, equity with other team members, and alignment with market data.
GitLab is proud to be an equal opportunity workplace and is an affirmative action employer. GitLab’s policies and practices relating to recruitment, employment, career development and advancement, promotion, and retirement are based solely on merit, regardless of race, color, religion, ancestry, sex (including pregnancy, lactation, sexual orientation, gender identity, or gender expression), national origin, age, citizenship, marital status, mental or physical disability, genetic information (including family medical history), discharge status from the military, protected veteran status (which includes disabled veterans, recently separated veterans, active duty wartime or campaign badge veterans, and Armed Forces service medal veterans), or any other basis protected by law. GitLab will not tolerate discrimination or harassment based on any of these characteristics.
Software Engineering Manager, Software Supply Chain Security: Authorization employer: GitLab
Contact Detail:
GitLab Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Software Engineering Manager, Software Supply Chain Security: Authorization
✨Tip Number 1
Familiarise yourself with GitLab's products and their approach to software supply chain security. Understanding their mission and how they integrate AI into their workflows will help you align your experience with their goals during discussions.
✨Tip Number 2
Engage with the GitLab community by participating in forums or discussions related to software supply chain security. This not only shows your interest but also helps you network with current employees and gain insights into their culture.
✨Tip Number 3
Prepare to discuss your leadership style and how you've successfully guided teams through complex transitions in the past. Highlight specific examples of how you've implemented advanced authorization controls or similar projects.
✨Tip Number 4
Stay updated on the latest trends and best practices in identity and access management, particularly around zero-trust models. Being able to speak knowledgeably about these topics will demonstrate your commitment to security and innovation.
We think you need these skills to ace Software Engineering Manager, Software Supply Chain Security: Authorization
Some tips for your application 🫡
Understand the Role: Before applying, make sure you fully understand the responsibilities and requirements of the Engineering Manager position at GitLab. Familiarise yourself with their mission and how your experience aligns with their goals in software supply chain security.
Tailor Your CV: Customise your CV to highlight relevant experience in authorization systems, identity management, and access control models. Emphasise your leadership skills and any experience with policy-as-code approaches, as these are crucial for this role.
Craft a Compelling Cover Letter: Write a cover letter that not only showcases your technical expertise but also reflects your passion for building teams and systems that enable secure collaboration. Mention specific projects or achievements that demonstrate your ability to lead complex architectural transitions.
Showcase Your Knowledge: In your application, include examples of how you've stayed current with industry standards and best practices in identity and access management. This could involve mentioning any relevant certifications, courses, or conferences you've attended.
How to prepare for a job interview at GitLab
✨Understand the Role and Responsibilities
Make sure you have a clear understanding of the Engineering Manager role, especially in relation to Software Supply Chain Security and authorization systems. Familiarise yourself with GitLab's mission and how this role contributes to their goals.
✨Showcase Your Technical Expertise
Be prepared to discuss your experience with authorization frameworks, identity management, and access control models. Highlight any familiarity with policy-as-code approaches and modern authorization frameworks like RBAC and ABAC.
✨Demonstrate Leadership Skills
Since this role focuses on nurturing a team, be ready to share examples of how you've successfully led teams through complex projects. Discuss your approach to hiring exceptional talent and fostering a healthy team environment.
✨Engage with Industry Standards
Stay current with industry standards and best practices in identity and access management. Be prepared to discuss how you would implement these practices at GitLab, particularly around least-privilege and zero-trust access models.