Back to jobs

    About GitLab

    The SSCS Add-On team is an integral part of GitLab's Software Supply Chain Security stage. The team is dedicated to developing a commercial offering that addresses complex supply chain security challenges faced by enterprise customers. This involves combining various parts of the GitLab product to create comprehensive security solutions for organizations with stringent compliance and risk management needs. The work offers both technical challenges and strategic importance in a rapidly evolving threat landscape, fostering an environment where engineers can significantly influence product direction while solving practical backend problems within GitLab's platform.

    About the Position

    Introduction

    As a Staff Backend Engineer at GitLab, you will play a pivotal role in evolving our Software Supply Chain Security offering. This position involves serving as a senior technical leader for backend systems focused on securing how software is built, verified, and delivered within the GitLab platform. You will concentrate on foundational capabilities such as package policy enforcement, build provenance, artifact signing, and malicious package detection, with an emphasis on enterprise-grade security and performance. This is a remote, asynchronous, and values-driven environment where strong communication and teamwork are essential.

    Responsibilities

    • Define and drive the technical architecture for the Software Supply Chain Security (SSCS) Add-On, including backend systems for package policy enforcement, provenance generation, artifact signing, and malicious package detection.
    • Lead design and implementation efforts for Supply-chain Levels for Software Artifacts (SLSA) Level 2 and Level 3 capabilities within GitLab CI/CD.
    • Architect integrations with Sigstore services like Cosign, Fulcio, and Rekor, covering signing workflows, verification, and trust boundaries.
    • Design high-performance and reliable backend services and request paths to support allow, deny, and quarantine package policies.
    • Conduct thorough merge request reviews, focusing on security, architectural consistency, maintainability, and test quality.
    • Mentor Backend Engineers at various experience levels, contributing to technical excellence through design guidance, feedback, and involvement in hiring.
    • Collaborate with Product, Infrastructure, Authentication, Authorization, and Security teams on cross-team technical decisions.
    • Contribute to relevant open-source and industry discussions, including working groups focused on software supply chain security.

    Requirements

    • Strong experience building backend applications with Ruby on Rails in a high-scale production environment.
    • Professional experience with Go for backend or infrastructure-oriented services.
    • A proven track record of leading architecture across multiple systems and influencing technical direction with sound engineering judgment.
    • Experience writing clear technical proposals, Request for Comments (RFCs), and decision records in an asynchronous, documentation-first environment.
    • A solid security mindset and comfort working on products where trust, risk reduction, and secure defaults are critical requirements.
    • Familiarity with software supply chain security concepts such as build provenance, artifact signing, dependency security, or software bill of materials.
    • Strong teamwork and communication skills, with the ability to collaborate effectively across distributed teams and functions.
    • Interest in GitLab's values and in building secure, scalable product capabilities that empower customers to ship software with confidence.

    About Company

    The SSCS Add-On team is an integral part of GitLab's Software Supply Chain Security stage. The team is dedicated to developing a commercial offering that addresses complex supply chain security challenges faced by enterprise customers. This involves combining various parts of the GitLab product to create comprehensive security solutions for organizations with stringent compliance and risk management needs. The work offers both technical challenges and strategic importance in a rapidly evolving threat landscape, fostering an environment where engineers can significantly influence product direction while solving practical backend problems within GitLab's platform.

    Apply Now

    Your data is only shared with GitLab

    Location

    Remote, India

    Type

    Full-Time

    Keywords

    AI
    Backend Engineering
    Software Supply Chain Security
    Ruby on Rails
    Go
    CI/CD
    Dependency Management
    Security Workflows
    SLSA
    Sigstore
    Cosign
    Fulcio
    Rekor
    Artifact Signing
    Malicious Package Detection
    Enterprise Security
    Open Source
    Verified Company

    Staff Backend Engineer, Software Supply Chain Security

    GitLab