Staff Backend Engineer, Ast: Composition Analysis

GitLab GitLab · Enterprise · Australia +9 · Remote · Sec Engineering

Staff Backend Engineer on GitLab's Software Composition Analysis team, focusing on enhancing dependency scanning and container scanning capabilities to help customers manage software supply chain risks. The role involves hands-on implementation, architecture, and technical leadership in areas like reachability analysis and supply chain poisoning detection.

What you'd actually do

  1. Implement complex features in dependency scanning and container scanning, shipping improvements that increase scan coverage, improve accuracy, and drive adoption of GitLab's SCA capabilities
  2. Solve novel technical problems in SCA, establishing reusable patterns that reduce delivery time and improve engineering effectiveness across the team
  3. Guide architectural and implementation decisions in collaboration with engineering managers, product managers, and peer engineers to improve scalability, reliability, and delivery outcomes across the team's SCA architecture
  4. Contribute code, design reviews, and technical mentorship that raise quality standards, improve maintainability, and strengthen performance across the codebase
  5. Collaborate across GitLab's security domain to align SCA work with related efforts in vulnerability management and adjacent product areas, accelerating delivery of shared roadmap goals and improving coordination across related security efforts

Skills

Required

  • Software Composition Analysis
  • dependency scanning
  • container scanning
  • backend technologies
  • Go
  • Ruby on Rails
  • cloud providers (GCP, CloudFlare, AWS)
  • evaluating technical tradeoffs in SCA and security tooling
  • working in distributed, async-first teams
  • explaining complex technical and security concepts

Nice to have

  • pick up new technologies quickly

What the JD emphasized

  • drive hands-on implementation of security features
  • focus will be on enhancing GitLab's SCA capabilities
  • work directly on architecture and technical implementation
  • contribute hands-on code
  • Hands-on experience in Software Composition Analysis
  • ability to contribute to complex security features
  • Deep hands-on expertise in building and evolving dependency scanning and container scanning analyzers
  • Demonstrated ability to design solutions that balance complexity, performance, and maintainability
  • Expertise with backend technologies
  • Ability to evaluate technical tradeoffs in SCA and security tooling
  • proven success delivering maintainable solutions