GitLab

Build software faster. The One DevOps Platform enables your entire org to collaborate around your code. We're hiring.

Engineering Manager, AST: Composition Analysis

Engineering ManagerEngineering ManagerFull TimeRemoteTeam 1,001-5,000Since 2014H1B No SponsorCompany SiteLinkedIn

Location

United States

Posted

2 days ago

Salary

$131.6K - $282K / year

Bachelor Degree9 yrs expEnglishSoftware Composition AnalysisApplication SecurityContainer ScanningDependency ManagementOpen Source SecurityDev Sec OpsAgile Project ManagementVulnerability ManagementPackage ManagersSecurity Scanning Tools

Job Description

This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more.

Role Description

As an Engineering Manager for Composition Analysis, you'll lead a team building the software composition analysis capabilities that help GitLab customers find and fix vulnerabilities in their application dependencies and software supply chain. You'll guide engineers working on software composition analysis and container scanning, and you'll be responsible for setting priorities, shaping product architecture, and running agile processes so that our security offerings stay effective, reliable, and easy to use in real DevSecOps environments.

You'll balance complex, security-focused roadmaps and author project plans so that customers get a robust composition analysis experience within GitLab. In your first year, you'll drive key initiatives like:

  • Auto-remediation of vulnerable packages
  • Auto-fix breaking changes with AI
  • Scanning unmanaged C/C++ dependencies
  • Static reachability analysis
  • Snippet detection for open source dependencies

Some examples of our projects:

  • Building hyper-scale vulnerability detection engines for millions of GitLab users around the world
  • Designing auto-remediation workflows for vulnerable open source and third-party dependencies
  • Auto AI fixes for breaking changes that happen following dependency bumps

What you’ll do:

  • Lead engineers across the Composition Analysis team, setting clear priorities and expectations.
  • Drive key security initiatives, including auto-remediation of vulnerable software packages, scanning unmanaged C/C++ dependencies, static reachability analysis, and snippet detection for open source dependencies.
  • Balance priorities and resources across the Composition Analysis team to ensure sustainable delivery and high-quality outcomes.
  • Author and maintain project plans for epics within the Composition Analysis team, aligning work, identifying dependencies, and ensuring quality delivery.
  • Run agile project management processes for the Composition Analysis team, including planning, estimation, and continuous improvement of delivery practices.
  • Provide guidance on the architecture of software composition analysis solutions, ensuring they are robust, scalable, and effective.
  • Collaborate closely with the Composition Analysis team to ensure consistent, high-quality approaches to application security across GitLab's platform.

Qualifications

  • Background leading multiple technical teams or groups, ideally in application security or cloud security
  • Practical understanding of software composition analysis, including how to assess and manage risks in application dependencies
  • Familiarity with containerization technologies, package managers, and dependency management systems
  • Experience working with or around open source security tooling (for example, Syft, Grype, Trivy, or similar tools)
  • Ability to plan and run agile project management processes for the Composition Analysis team, including coordinating priorities and dependencies.
  • Skill in guiding product and architecture decisions for security scanning tools, balancing technical constraints with customer needs
  • Openness to candidates with transferable experience in security engineering, DevSecOps, or vulnerability management who are motivated to grow in application security leadership

About the team

The Composition Analysis team at GitLab sits within our security product area and focuses on building and improving our software composition analysis capabilities across the DevSecOps platform. We own core features such as software composition analysis, container scanning, and related remediation workflows. You'll lead our distributed group of security-focused engineers as we collaborate asynchronously across time zones using GitLab itself for planning, code review, and delivery. Right now, we're focused on advancing capabilities like:

  • Auto-remediation of vulnerable packages
  • Scanning unmanaged C/C++ dependencies
  • Static reachability analysis at the function level
  • Snippet detection for open source dependencies

Benefits

  • Flexible Paid Time Off
  • Team Member Resource Groups
  • Equity Compensation & Employee Stock Purchase Plan
  • Growth and Development Fund
  • Parental leave
  • Home office support

Job Requirements

  • Background leading multiple technical teams or groups, ideally in application security or cloud security
  • Practical understanding of software composition analysis, including how to assess and manage risks in application dependencies
  • Familiarity with containerization technologies, package managers, and dependency management systems
  • Experience working with or around open source security tooling (for example, Syft, Grype, Trivy, or similar tools)
  • Ability to plan and run agile project management processes for the Composition Analysis team, including coordinating priorities and dependencies.
  • Skill in guiding product and architecture decisions for security scanning tools, balancing technical constraints with customer needs
  • Openness to candidates with transferable experience in security engineering, DevSecOps, or vulnerability management who are motivated to grow in application security leadership
  • About the team
  • The Composition Analysis team at GitLab sits within our security product area and focuses on building and improving our software composition analysis capabilities across the DevSecOps platform. We own core features such as software composition analysis, container scanning, and related remediation workflows. You'll lead our distributed group of security-focused engineers as we collaborate asynchronously across time zones using GitLab itself for planning, code review, and delivery. Right now, we're focused on advancing capabilities like:
  • Auto-remediation of vulnerable packages
  • Scanning unmanaged C/C++ dependencies
  • Static reachability analysis at the function level
  • Snippet detection for open source dependencies

Benefits

  • Flexible Paid Time Off
  • Team Member Resource Groups
  • Equity Compensation & Employee Stock Purchase Plan
  • Growth and Development Fund
  • Parental leave
  • Home office support

Related Categories

Related Job Pages

More Engineering Manager Jobs

Engineering Manager2 days ago
Full TimeRemoteTeam 1-10H1B No Sponsor

We are looking for an Engineering Manager to lead our Intelligence & Integrations team. This team sits at the intersection of our hardware ecosystem and our customers' operational reality, responsible for transforming the raw behavioral data captured by AUGi into actionable insig...

AWSTypeScriptNode.jsPostgreSQLReactHL7FHIRDatabricksData PipelinesDistributed Systems
United States + 1 moreAll locations: United States, Canada
$200K - $230K / year
Full TimeRemoteTeam 10,001

The Area Automation Manager plays a critical role in overseeing and managing the automation systems and technologies within the Missouri and the surrounding states. This role typically involves a combination of technical expertise, management skills, and strategic planning to ens...

Industrial Control WiringPLC ProgrammingHMI ProgrammingSCADAProcess DesignAutomation SystemsInstrumentationElectrical Controls
United States

Engineering Manager, Native Apps

ezCater, Inc

ezCater is the leading food for work technology company in the US, connecting anyone who needs food for their workplace to over 100,000 restaurants nationwide. For workplaces, ezCater provides flexible and scalable solutions for everything from recurring employee meals to one-off meetings, all backed by 24/7 customer service with real humans. ezCater also enables companies to manage their food spend in a single, customizable platform. For restaurant partners, ezCater helps them grow their business by bringing them more orders and new high-value customers. We're backed by top investors including Insight, Iconiq, Lightspeed, GIC, SoftBank, and Quadrille.

Engineering Manager2 days ago
Full TimeRemoteTeam 501-1,000

As an Engineering Manager of ezCater’s Native Apps team, you will focus on leading the team that is building ways for partners and customers to experience ezCater’s platform through ezCater’s suite of native applications. This will include building new capabilities for our cateri...

AndroidiOSKotlinJavaSwiftObjective-CReact NativeFlutterMobile ArchitecturePerformance Optimization
United States
$195K - $255K / year

Senior Engineering Manager, Platform Engineering

ezCater, Inc

ezCater is the leading food for work technology company in the US, connecting anyone who needs food for their workplace to over 100,000 restaurants nationwide. For workplaces, ezCater provides flexible and scalable solutions for everything from recurring employee meals to one-off meetings, all backed by 24/7 customer service with real humans. ezCater also enables companies to manage their food spend in a single, customizable platform. For restaurant partners, ezCater helps them grow their business by bringing them more orders and new high-value customers. We're backed by top investors including Insight, Iconiq, Lightspeed, GIC, SoftBank, and Quadrille.

Engineering Manager3 days ago
Full TimeRemoteTeam 501-1,000

As Senior Engineering Manager, Platform Engineering, you will lead the teams responsible for the foundation that every engineering team builds on: infrastructure, developer experience, shared libraries, CI/CD, observability, and governance. You will own delivery across developer ...

KubernetesEKSInfrastructure as CodeContainer OrchestrationService NetworkingCI/CDObservabilityDistributed SystemsCloud-Native InfrastructureEvent StreamingAuthenticationMonitoringLoggingTracingAlertingNetworkingAutoscalingGitOpsService TemplatesHTTPAuthentication Middleware
United States
$218K - $280K / year