Staff Backend Engineer, Software Supply Chain Security
Job description
About the role
GitLab is the intelligent orchestration platform for DevSecOps, and this role defines how we secure the software supply chain at scale. You will own the backend systems that enforce package policy, generate build provenance, and implement artifact signing to protect the integrity of the software delivery lifecycle. This position requires you to design foundational capabilities such as dependency firewall rules, build attestations, and malicious package detection with a focus on reliability and enterprise-grade security. You will serve as a senior technical leader who translates complex security requirements into clear technical proposals and implementation plans. You will work across tightly coupled services including CI/CD, dependency management, and security workflows to ensure cohesive and consistent protection. The role demands comfort with abstract thinking, rigorous design before coding, and the ability to guide multiple engineering teams toward a shared security vision. You will thrive in a remote-first, asynchronous culture where ownership, written communication, and continuous learning define how we build the future of secure software development.
Key facts
What you'll do
Define and drive the technical architecture for the SSCS Add-On, including backend systems for package policy enforcement, provenance generation, artifact signing, and malicious package detection.
Lead design and implementation work for Supply-chain Levels for Software Artifacts (SLSA) Level 2 and Level 3 capabilities within GitLab CI/CD, ensuring alignment with industry standards and best practices.
Architect integrations with Sigstore services such as Cosign, Fulcio, and Rekor, including approaches for signing workflows, verification processes, and managing trust boundaries across services.
Design backend services and request paths that support allow, deny, and quarantine package policies while meeting strict performance, scalability, and reliability expectations under production load.
Review merge requests with a focus on security implications, architectural consistency, long-term maintainability, and the quality and coverage of tests and documentation.
Mentor Backend Engineers across experience levels, helping raise the technical bar through design guidance, actionable feedback, and active participation in hiring and career development discussions.
Partner with Product, Infrastructure, Authentication, Authorization, and Security counterparts on cross-team technical decisions to ensure cohesive and consistent behavior across the platform.
Contribute to relevant open source projects and industry conversations, including participation in working groups related to software supply chain security when alignment with GitLab strategy and open source practices exists.
Define observability and monitoring strategies for security controls, ensuring that backend services emit actionable insights for debugging, auditing, and continuous improvement.
Champion secure coding practices, threat modeling, and risk assessment activities that feed directly into the design and delivery of backend components.
Collaborate with compliance and audit stakeholders to ensure that supply chain security features meet internal policies and external regulatory expectations where applicable.
Lead proof-of-concept efforts for emerging security capabilities, validating feasibility, performance, and integration complexity before broader rollout.
Requirements
Must have strong experience building backend applications with Ruby on Rails in a high-scale production environment, with a deep understanding of frameworks, middleware, and deployment patterns.
Must bring professional experience with Go for backend or infrastructure-oriented services, demonstrating comfort with concurrency, networking, and efficient resource utilization.
Must show a track record of leading architecture across multiple systems and influencing technical direction through strong engineering judgment and clear decision-making.
Must be capable of translating ambiguous problems into well-defined technical proposals, documenting design decisions, and communicating them effectively to both technical and non-technical audiences.
Must have experience implementing and operating secure systems, including familiarity with authentication, authorization, encryption, and secure communication patterns in distributed environments.
Must demonstrate a history of writing clean, testable code, with a focus on maintainability, extensibility, and robust test coverage at the unit and integration level.
Must be comfortable working in a remote, asynchronous, and values-driven environment where written communication is primary and ownership is expected at all levels of responsibility.
Must be eligible to work in the location specified for this role and comply with GitLab policies regarding collaboration, security, and data protection.
Nice to have
Experience contributing to or working with open source supply chain security tools, including Sigstore ecosystem components where relevant.
Familiarity with container image formats, SBOM standards, and artifact verification workflows in cloud-native environments.
Understanding of regulatory and compliance considerations related to software supply chain security in highly regulated industries.
Practical notes
This role is based in Bangalore, India.
Please ensure you are able to commit to the location and any associated requirements before applying.
No specific compensation details are provided in this source text.