Intermediate Backend Engineer, Sscs: Supply Chain

GitLab GitLab · Enterprise · India · Sec Engineering

GitLab is seeking an Intermediate Backend Engineer for their SSCS Add-On team to build a dedicated software supply chain security feature for regulated enterprise organizations. The role involves contributing to capabilities that help customers control software dependencies, verify artifact integrity, and identify malicious packages. The engineer will work with Ruby on Rails and Go, integrate with existing security scanning, and focus on backend development, product integration, and security-focused development.

What you'd actually do

  1. Implement well-scoped backend features across the Add-On's supply chain security product, including package policy integrations, ingestion pipeline improvements, signing and verification support, and reliability-focused work, delivering maintainable code on agreed timelines and meeting team-defined delivery commitments.
  2. Build and maintain integrations between Add-On functionality and GitLab's existing software composition analysis scanning infrastructure so findings appear consistently and accurately in merge request security reports, reducing integration issues and supporting a reliable user experience.
  3. Write and maintain comprehensive automated test coverage, including RSpec and integration tests, to improve test reliability, reduce regressions, and support safe, consistent releases as the codebase grows.
  4. Take on work across multiple feature areas as priorities evolve, contributing as a generalist where the team needs support most.
  5. Participate actively in code review by giving thoughtful, actionable feedback and incorporating feedback constructively into your own work to help maintain code quality and reduce rework.

Skills

Required

  • Backend development experience
  • Ruby on Rails
  • PostgreSQL
  • Automated test coverage
  • RSpec
  • Written communication skills
  • Asynchronous workflows

Nice to have

  • Golang
  • Interest in package ecosystems (npm, Maven, PyPI, OCI containers)
  • Interest in software supply chain security
  • Interest in dependency management
  • Interest in DevSecOps
  • Interest in security-adjacent product development

What the JD emphasized

  • regulated enterprise organizations
  • security-focused development
  • software supply chain security
  • dependency management
  • DevSecOps
  • security-adjacent product development