Build software faster. The One DevOps Platform enables your entire org to collaborate around your code. We're hiring.
Engineering Manager, AST: Composition Analysis
Location
United States
Posted
2 days ago
Salary
$131.6K - $282K / year
Job Description
Role Description
As an Engineering Manager for Composition Analysis, you'll lead a team building the software composition analysis capabilities that help GitLab customers find and fix vulnerabilities in their application dependencies and software supply chain. You'll guide engineers working on software composition analysis and container scanning, and you'll be responsible for setting priorities, shaping product architecture, and running agile processes so that our security offerings stay effective, reliable, and easy to use in real DevSecOps environments.
You'll balance complex, security-focused roadmaps and author project plans so that customers get a robust composition analysis experience within GitLab. In your first year, you'll drive key initiatives like:
- Auto-remediation of vulnerable packages
- Auto-fix breaking changes with AI
- Scanning unmanaged C/C++ dependencies
- Static reachability analysis
- Snippet detection for open source dependencies
Some examples of our projects:
- Building hyper-scale vulnerability detection engines for millions of GitLab users around the world
- Designing auto-remediation workflows for vulnerable open source and third-party dependencies
- Auto AI fixes for breaking changes that happen following dependency bumps
What you’ll do:
- Lead engineers across the Composition Analysis team, setting clear priorities and expectations.
- Drive key security initiatives, including auto-remediation of vulnerable software packages, scanning unmanaged C/C++ dependencies, static reachability analysis, and snippet detection for open source dependencies.
- Balance priorities and resources across the Composition Analysis team to ensure sustainable delivery and high-quality outcomes.
- Author and maintain project plans for epics within the Composition Analysis team, aligning work, identifying dependencies, and ensuring quality delivery.
- Run agile project management processes for the Composition Analysis team, including planning, estimation, and continuous improvement of delivery practices.
- Provide guidance on the architecture of software composition analysis solutions, ensuring they are robust, scalable, and effective.
- Collaborate closely with the Composition Analysis team to ensure consistent, high-quality approaches to application security across GitLab's platform.
Qualifications
- Background leading multiple technical teams or groups, ideally in application security or cloud security
- Practical understanding of software composition analysis, including how to assess and manage risks in application dependencies
- Familiarity with containerization technologies, package managers, and dependency management systems
- Experience working with or around open source security tooling (for example, Syft, Grype, Trivy, or similar tools)
- Ability to plan and run agile project management processes for the Composition Analysis team, including coordinating priorities and dependencies.
- Skill in guiding product and architecture decisions for security scanning tools, balancing technical constraints with customer needs
- Openness to candidates with transferable experience in security engineering, DevSecOps, or vulnerability management who are motivated to grow in application security leadership
About the team
The Composition Analysis team at GitLab sits within our security product area and focuses on building and improving our software composition analysis capabilities across the DevSecOps platform. We own core features such as software composition analysis, container scanning, and related remediation workflows. You'll lead our distributed group of security-focused engineers as we collaborate asynchronously across time zones using GitLab itself for planning, code review, and delivery. Right now, we're focused on advancing capabilities like:
- Auto-remediation of vulnerable packages
- Scanning unmanaged C/C++ dependencies
- Static reachability analysis at the function level
- Snippet detection for open source dependencies
Benefits
- Flexible Paid Time Off
- Team Member Resource Groups
- Equity Compensation & Employee Stock Purchase Plan
- Growth and Development Fund
- Parental leave
- Home office support
Job Requirements
- Background leading multiple technical teams or groups, ideally in application security or cloud security
- Practical understanding of software composition analysis, including how to assess and manage risks in application dependencies
- Familiarity with containerization technologies, package managers, and dependency management systems
- Experience working with or around open source security tooling (for example, Syft, Grype, Trivy, or similar tools)
- Ability to plan and run agile project management processes for the Composition Analysis team, including coordinating priorities and dependencies.
- Skill in guiding product and architecture decisions for security scanning tools, balancing technical constraints with customer needs
- Openness to candidates with transferable experience in security engineering, DevSecOps, or vulnerability management who are motivated to grow in application security leadership
- About the team
- The Composition Analysis team at GitLab sits within our security product area and focuses on building and improving our software composition analysis capabilities across the DevSecOps platform. We own core features such as software composition analysis, container scanning, and related remediation workflows. You'll lead our distributed group of security-focused engineers as we collaborate asynchronously across time zones using GitLab itself for planning, code review, and delivery. Right now, we're focused on advancing capabilities like:
- Auto-remediation of vulnerable packages
- Scanning unmanaged C/C++ dependencies
- Static reachability analysis at the function level
- Snippet detection for open source dependencies
Benefits
- Flexible Paid Time Off
- Team Member Resource Groups
- Equity Compensation & Employee Stock Purchase Plan
- Growth and Development Fund
- Parental leave
- Home office support
Related Guides
Related Categories
Related Job Pages
More Engineering Manager Jobs
We are looking for an Engineering Manager to lead our Intelligence & Integrations team. This team sits at the intersection of our hardware ecosystem and our customers' operational reality, responsible for transforming the raw behavioral data captured by AUGi into actionable insig...
The Area Automation Manager plays a critical role in overseeing and managing the automation systems and technologies within the Missouri and the surrounding states. This role typically involves a combination of technical expertise, management skills, and strategic planning to ens...
Engineering Manager, Native Apps
ezCater, IncezCater is the leading food for work technology company in the US, connecting anyone who needs food for their workplace to over 100,000 restaurants nationwide. For workplaces, ezCater provides flexible and scalable solutions for everything from recurring employee meals to one-off meetings, all backed by 24/7 customer service with real humans. ezCater also enables companies to manage their food spend in a single, customizable platform. For restaurant partners, ezCater helps them grow their business by bringing them more orders and new high-value customers. We're backed by top investors including Insight, Iconiq, Lightspeed, GIC, SoftBank, and Quadrille.
As an Engineering Manager of ezCater’s Native Apps team, you will focus on leading the team that is building ways for partners and customers to experience ezCater’s platform through ezCater’s suite of native applications. This will include building new capabilities for our cateri...
Senior Engineering Manager, Platform Engineering
ezCater, IncezCater is the leading food for work technology company in the US, connecting anyone who needs food for their workplace to over 100,000 restaurants nationwide. For workplaces, ezCater provides flexible and scalable solutions for everything from recurring employee meals to one-off meetings, all backed by 24/7 customer service with real humans. ezCater also enables companies to manage their food spend in a single, customizable platform. For restaurant partners, ezCater helps them grow their business by bringing them more orders and new high-value customers. We're backed by top investors including Insight, Iconiq, Lightspeed, GIC, SoftBank, and Quadrille.
As Senior Engineering Manager, Platform Engineering, you will lead the teams responsible for the foundation that every engineering team builds on: infrastructure, developer experience, shared libraries, CI/CD, observability, and governance. You will own delivery across developer ...