Senior Backend Engineer, Software Supply Chain Security (SSCS)
About GitLab
GitLab is developing a commercial offering dedicated to software supply chain security. The SSCS Add-On team is focused on addressing real challenges for enterprise customers by combining various parts of the GitLab product into a comprehensive security solution. This work is both technically engaging and strategically crucial, operating in an environment characterized by rapid threats, evolving customer needs, and close collaboration with other security teams. Engineers within this team have the opportunity to influence product direction while solving practical backend challenges across GitLab's platform.
About the Position
Introduction
As a Senior Backend Engineer at GitLab, you will play a pivotal role in developing the core capabilities of our software supply chain security Add-On. This commercial offering assists organizations in managing software integrity throughout their build processes, verifying released software, and detecting malicious packages pre-production. You'll contribute to backend systems focused on package policy enforcement, artifact signing, verification, provenance attestation, and malicious package intelligence.
This is a foundational position within a lean team, carrying significant responsibility. Your decisions in API design, testing, performance, and security will directly influence product evolution. You will collaborate closely with a Staff Backend Engineer on architectural decisions and other engineers to deliver secure, reliable features for enterprise clients with intricate supply chain security requirements. This role is ideal for individuals seeking to apply strong Ruby on Rails expertise to complex technical challenges in security, platform design, and product development within GitLab's all-remote, asynchronous work environment.
Examples of projects include:
- Building backend services for package policy enforcement and dependency control.
- Implementing artifact signing, verification, and provenance workflows leveraging the Sigstore ecosystem.
Responsibilities
- Design and implement backend features across the Add-On's software supply chain security surface, including policy enforcement, artifact signing and verification, provenance attestation APIs, and malicious package detection integrations, ensuring secure capabilities that meet enterprise customer needs.
- Develop and enhance the package policy evaluation engine, covering rule compilation, request matching, enforcement decisions, and performance-critical execution paths integrated with GitLab's Dependency Firewall infrastructure, to boost accuracy, reliability, and performance.
- Create artifact signing and verification workflows, incorporating Sigstore and Cosign integrations, signing key lifecycle management, keyless signing with OpenID Connect (OIDC), and policy-based promotion gates, to enable trusted and auditable software delivery.
- Build and refine configuration interfaces for enterprise security teams, including backend APIs and the GraphQL surface for expressing supply chain security requirements, improving usability and adoption for administrators.
- Integrate Add-On functionalities with GitLab's existing security policy framework, featuring policy inheritance and policy-as-code support via YAML, thereby extending coverage across customer security workflows.
- Collaborate with related teams to integrate malicious package intelligence into the Add-On offering, aiming for cohesive workflows and faster responses to package risks.
- Write and maintain extensive RSpec and integration test coverage, and contribute to enhancing test reliability across the team, increasing confidence in releases and reducing regressions.
- Conduct merge request reviews with a security-first approach and implement solutions with significant decision-making autonomy in partnership with the Staff Backend Engineer, ensuring code quality and secure engineering standards.
Requirements
- Proven backend engineering experience, with expertise in production Ruby on Rails, which is the primary language for the team.
- Working knowledge of Go or a strong aptitude and willingness to quickly learn it.
- Excellent API design skills, including experience with REST, GraphQL, and defining clear internal service boundaries.
- Strong understanding of PostgreSQL fundamentals, including schema design, query optimization, and indexing strategies.
- Experience with Redis for caching and distributed coordination patterns.
- A security-conscious engineering mindset, demonstrating sound judgment regarding trust boundaries, input validation, and failure modes.
- Familiarity with software supply chain security concepts such as Supply-chain Levels for Software Artifacts (SLSA), software bill of materials (SBOM), artifact signing, or related security scanning methods.
- Interest in complex policy, registry, or platform challenges, including areas like rules engines, package ecosystems, cryptographic signing, or DevSecOps product development.
About Company
GitLab is developing a commercial offering dedicated to software supply chain security. The SSCS Add-On team is focused on addressing real challenges for enterprise customers by combining various parts of the GitLab product into a comprehensive security solution. This work is both technically engaging and strategically crucial, operating in an environment characterized by rapid threats, evolving customer needs, and close collaboration with other security teams. Engineers within this team have the opportunity to influence product direction while solving practical backend challenges across GitLab's platform.
How to Apply
Please apply through the provided link.
Apply Now
Your data is only shared with GitLab
Location
Remote, India
Type
Full-Time
Keywords
Similar Roles
Explore comparable positions
Senior Backend Engineer, Software Supply Chain Security (SSCS)
GitLab