Staff Backend Engineer (Go), Software Supply Chain Security: Secrets Management
About GitLab
The Secrets Management team is part of the Pipeline Security group within GitLab's Software Supply Chain Security stage. The team is responsible for GitLab Secrets Manager, an OpenBao-powered solution for securely storing, distributing, and managing the lifecycle of secrets in CI/CD pipelines. They work closely with Authentication, Authorization, Compliance, and Platform teams to ensure secure defaults, reliable operations for GitLab.com, and robust integration between GitLab and OpenBao. The primary challenge is building scalable multi-tenant secrets management while balancing open-source collaboration with customer needs.
About the Position
Introduction
Join GitLab's Software Supply Chain Security team as a Staff Engineer specializing in Secrets Management. You will provide technical leadership for GitLab's strategic investment in integrated secrets management, setting the direction for GitLab Secrets Manager, an OpenBao-powered solution. This role involves driving architecture decisions for multi-tenant secrets management at scale, guiding integration into GitLab, and contributing upstream to the OpenBao open-source project.
Success in your first year will involve establishing a clear, scalable architecture for GitLab Secrets Manager, ensuring reliable performance in collaboration with Infrastructure teams, and fostering strong cross-team alignment across Pipeline Security, Authentication, and Platform. You will also represent GitLab in OpenBao's governance and technical discussions, aligning product direction with upstream contributions.
Responsibilities
- Lead the technical strategy for GitLab Secrets Manager, defining architecture for secure, multi-tenant secrets management at scale.
- Own the integration between GitLab and OpenBao, focusing on namespaces, authentication mechanisms, and policy management.
- Collaborate with Pipeline Security, Authentication, and Platform teams to propose, review, and implement cross-team secrets management enhancements.
- Partner with GitLab.com Infrastructure teams to ensure secrets management meets reliability, performance, and operational standards.
- Represent GitLab in the OpenBao open-source project through upstream feature contributions, technical steering discussions, and maintaining technical credibility.
- Mentor and advise engineers on secrets management, cryptographic systems, and secure architecture patterns to enhance design and implementation quality.
- Interface with engineering managers and senior leadership to define initiatives, evaluate tradeoffs, and facilitate delivery across teams.
- Engage with customers and external stakeholders to understand needs and communicate GitLab's secrets management capabilities and roadmap.
Requirements
- Experience designing and operating secrets management systems such as HashiCorp Vault, OpenBao, or cloud-native offerings, including secure storage, access control, and audit logging.
- Ability to lead architecture decisions for resilient, multi-tenant services handling secrets operations at scale, including high availability and cluster management patterns.
- Working knowledge of cryptographic and key management concepts, including encryption in transit and at rest, key derivation, and hardware security module (HSM) or PKCS#11 integrations.
- Experience implementing authentication and authorization integrations (e.g., JSON Web Token (JWT), OpenID Connect (OIDC), mutual Transport Layer Security (mTLS), and certificate-based authentication).
- Proficiency in building product integrations using Go (within the OpenBao or Vault ecosystem) and Ruby on Rails for GitLab platform integration.
- Experience contributing to open-source projects and effectively navigating distributed governance, balancing upstream needs with product requirements.
- Demonstrated ability to operate with high autonomy, drive strategy, and provide trusted partnership to senior leaders, including constructively challenging assumptions and tradeoffs.
- Strong communication and collaboration skills to influence across teams and levels, including mentoring engineers in a fully remote, asynchronous environment.
About Company
The Secrets Management team is part of the Pipeline Security group within GitLab's Software Supply Chain Security stage. The team is responsible for GitLab Secrets Manager, an OpenBao-powered solution for securely storing, distributing, and managing the lifecycle of secrets in CI/CD pipelines. They work closely with Authentication, Authorization, Compliance, and Platform teams to ensure secure defaults, reliable operations for GitLab.com, and robust integration between GitLab and OpenBao. The primary challenge is building scalable multi-tenant secrets management while balancing open-source collaboration with customer needs.
Apply Now
Your data is only shared with GitLab
Location
Remote, Canada; Remote, Ireland; Remote, Israel; Remote, Netherlands; Remote, United Kingdom; Remote, US
Type
Full-Time
Keywords
Similar Roles
Explore comparable positions
Staff Backend Engineer (Go), Software Supply Chain Security: Secrets Management
GitLab