At a Glance
- Tasks: Lead a team to enhance software supply chain security in GitLab CI pipelines.
- Company: Join GitLab, a pioneering open-core software company transforming software development.
- Benefits: Enjoy flexible paid time off, equity compensation, and home office support.
- Why this job: Make a real impact on software security while collaborating with industry leaders.
- Qualifications: Experience in leading engineering teams and knowledge of software supply chain security.
- Other info: Remote work culture with opportunities for growth and development.
The predicted salary is between 100000 - 140000 £ per year.
Join to apply for the Engineering Manager, Software Supply Chain Security: Pipeline Security role at GitLab. GitLab is an open-core software company that develops the most comprehensive AI-powered DevSecOps Platform, used by more than 100,000 organizations. Our mission is to enable everyone to contribute to and co-create the software that powers our world. Our platform unites teams and organizations, breaking down barriers and redefining what is possible in software development. We embrace AI as a core productivity multiplier; all team members are expected to incorporate AI into their daily workflows to drive efficiency, innovation, and impact.
An overview of this role:
As the Engineering Manager, Software Supply Chain Security: Pipeline Security, you will lead a team that makes GitLab CI pipelines more secure and trustworthy for thousands of organizations. You will guide the design and delivery of Software Supply Chain Security features, with a primary focus on CI job artifact security. This includes implementing the SLSA (Supply-chain Levels for Software Artifacts) framework in GitLab CI/CD and integrating related capabilities like SBOM, software composition analysis, and vulnerability management. You will treat your team as your product, safeguarding team health, hiring and developing a high-performing group of engineers, and collaborating closely with Product Management and Security to deliver on roadmap commitments.
Some Examples Of Our Projects:
- Developing a native secrets management system for GitLab CI pipelines
- Implementing SLSA Level 3 compliance features for CI job artifacts
What you will do:
- Lead a team of engineers building Software Supply Chain Security features with a focus on CI job artifact security.
- Guide the design and implementation of SLSA compliance within GitLab CI/CD pipelines.
- Collaborate with Product Managers to define, prioritize, and deliver the roadmap for supply chain security capabilities.
- Partner with Security team members to ensure new and existing features meet GitLab's security standards and align with best practices.
- Stay current with software supply chain security standards and tools, including SLSA, SBOM, software composition analysis, and vulnerability management.
- Educate and advocate for supply chain security best practices across engineering teams to drive adoption of secure patterns in CI pipelines.
- Represent the Pipeline Security team in cross-functional initiatives and, when appropriate, in external industry forums focused on software supply chain security.
- Drive continuous improvement in team health, delivery predictability, and documentation quality for pipeline and supply chain security features.
What you will bring:
- Experience leading and developing engineering teams, with a focus on building secure, reliable product features.
- Practical knowledge of software supply chain security concepts, tools, and industry standards.
- Understanding of the SLSA framework and how to apply it in CI/CD pipelines.
- Familiarity with software artifact provenance, attestation, and verification techniques.
- Knowledge of secure software development practices, including container security, software composition analysis, and vulnerability management.
- Experience working with CI/CD systems and their security considerations.
- Ability to collaborate effectively with product management, security, and other cross-functional partners, and to advocate for supply chain security best practices.
- Openness to learning new technologies and approaches, with transferable skills from related security, infrastructure, or software engineering domains.
About The Team:
Our Pipeline Security team is a globally distributed group of engineers who collaborate asynchronously across time zones. We are focused on building Software Supply Chain Security features into the core GitLab platform, with current priorities including native secrets management for CI pipelines, artifact provenance and verification, and achieving SLSA Level 3 compliance. We value clear communication, thorough documentation, and making new features straightforward for users to adopt.
How GitLab Will Support You:
- Benefits to support your health, finances, and well-being
- Flexible Paid Time Off
- Team Member Resource Groups
- Equity Compensation & Employee Stock Purchase Plan
- Growth and Development Fund
- Parental leave
- Home office support
Please note that we welcome interest from candidates with varying levels of experience; many successful candidates do not meet every single requirement.
GitLab is proud to be an equal opportunity workplace and is an affirmative action employer. GitLab's policies and practices relating to recruitment, employment, career development and advancement, promotion, and retirement are based solely on merit, regardless of race, color, religion, ancestry, sex, national origin, age, citizenship, marital status, mental or physical disability, genetic information, discharge status from the military, protected veteran status, or any other basis protected by law. GitLab will not tolerate discrimination or harassment based on any of these characteristics.
Engineering Manager, Software Supply Chain Security: Pipeline Security in London employer: GitLab
Contact Detail:
GitLab Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Engineering Manager, Software Supply Chain Security: Pipeline Security in London
✨Tip Number 1
Network like a pro! Reach out to your connections in the industry, especially those at GitLab. A friendly chat can open doors and give you insider info about the role.
✨Tip Number 2
Prepare for the interview by diving deep into GitLab's products and values. Show us how your experience aligns with our mission and how you can contribute to our Software Supply Chain Security goals.
✨Tip Number 3
Practice your technical skills! Brush up on software supply chain security concepts and be ready to discuss how you would implement SLSA compliance in CI/CD pipelines.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re serious about joining our team.
We think you need these skills to ace Engineering Manager, Software Supply Chain Security: Pipeline Security in London
Some tips for your application 🫡
Tailor Your Application: Make sure to customise your CV and cover letter for the Engineering Manager role. Highlight your experience with software supply chain security and CI/CD systems, as this will show us you understand what we're looking for.
Showcase Your Leadership Skills: We want to see how you've led teams in the past. Share specific examples of how you've developed engineers and improved team dynamics, as this is crucial for the role.
Demonstrate Your Knowledge: Familiarise yourself with SLSA and other relevant security standards. Mention any practical experience you have with these concepts in your application to show us you're up to speed.
Apply Through Our Website: Don't forget to submit your application through our website! This ensures it gets to the right people and helps us keep track of all applicants efficiently.
How to prepare for a job interview at GitLab
✨Know Your Stuff
Make sure you brush up on software supply chain security concepts, especially the SLSA framework. Be ready to discuss how you would implement these in CI/CD pipelines, as this will show your technical expertise and understanding of the role.
✨Show Your Leadership Skills
As an Engineering Manager, you'll need to demonstrate your ability to lead and develop a team. Prepare examples of how you've successfully managed teams in the past, focusing on building secure and reliable product features. Highlight your approach to team health and collaboration.
✨Collaborate Like a Pro
GitLab values cross-functional collaboration, so be prepared to discuss how you've worked with Product Management and Security teams in previous roles. Share specific instances where your collaboration led to successful project outcomes or improved security practices.
✨Stay Current and Curious
The tech world is always evolving, especially in security. Show your enthusiasm for learning by discussing recent trends or tools in software supply chain security. This not only demonstrates your commitment to the field but also your openness to adopting new technologies.