Engineering Manager, Sscs: Supply Chain

GitLab GitLab · Enterprise · India · Sec Engineering

Engineering Manager for GitLab's Software Supply Chain Security (SSCS) Add-On team, focusing on developing core capabilities like Dependency Firewall, Build Provenance, Malicious Packages detection, and Artifact Signing. The role involves managing a backend engineering team, driving delivery for general availability milestones, developing team members, and ensuring predictable execution for enterprise customers with strict security and compliance needs. The team operates in a regulated industry context and collaborates closely with product management and leadership.

What you'd actually do

  1. Guide a backend engineering team building the SSCS Add-On across dependency enforcement, build provenance, malicious package detection, and artifact signing.
  2. Be responsible for Drive engineering delivery for general availability milestones by aligning sequencing, scope, and dependencies with the Staff Backend Engineer and Product Manager.
  3. Develop the team by partnering with Talent Acquisition on sourcing, interview design, candidate evaluation, and hiring decisions.
  4. Run regular 1:1s, performance reviews, and career development conversations that enable growth and clear expectations.
  5. Advance engineering quality by monitoring cycle time, defect rates, and test coverage, and by addressing risks early.

Skills

Required

  • Over 3 years of experience guiding backend product engineering teams in security, DevOps, or platform engineering environments.
  • Ability to hire and grow backend or security engineers in distributed team environments, with practical understanding of the talent landscape for these roles.
  • Technical credibility to contribute to architecture discussions involving package registries, CI/CD pipeline security, and signing infrastructure.
  • Experience managing predictable delivery across multi-quarter product roadmaps and managing cross-team dependencies.
  • Comfort working in an asynchronous, documentation-driven organization with clear written communication.
  • Familiarity with supply chain security, artifact management, or compliance-focused product areas, or transferable experience from related domains.
  • Working knowledge of concepts related to frameworks and ecosystems such as SLSA and Sigstore.
  • Ability to build credibility with engineers, product partners, and customer-facing stakeholders through clear judgment, coaching, and teamwork.

What the JD emphasized

  • strict security and compliance needs
  • customers in regulated industries
  • strict security and compliance needs