Staff Backend Engineer, Software Supply Chain Security

GitLab
India
Workplace: RemoteFull timeFunction: Software EngineeringSkills: ["Communication","Mentoring","Leadership","Architecture","Teamwork"]

Senior backend engineer leading architecture and implementation for GitLab’s Software Supply Chain Security (SSCS) Add-On, shaping backend systems for package policy enforcement, build provenance, and artifact signing. You’ll drive SLSA level capabilities within CI/CD, integrate with Sigstore components, and mentor engineers, all in a remote, asynchronous environment focused on security, scalability, and cross-team collaboration.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
GitLab
GitLab
5 months ago

Staff Backend Engineer, Software Supply Chain Security

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 11 hours agoStatus: Live

Job Summary

Senior backend engineer leading architecture and implementation for GitLab’s Software Supply Chain Security (SSCS) Add-On, shaping backend systems for package policy enforcement, build provenance, and artifact signing. You’ll drive SLSA level capabilities within CI/CD, integrate with Sigstore components, and mentor engineers, all in a remote, asynchronous environment focused on security, scalability, and cross-team collaboration.
Location: India
Workplace: Remote
Employment Type: Full time
Job Function: Software Engineering

Key Responsibilities

  • •Define and drive the technical architecture for the SSCS Add-On, including backend systems for package policy enforcement, provenance generation, artifact signing, and malicious package detection.
  • •Lead design and implementation work for SLSA Level 2 and Level 3 capabilities within GitLab CI/CD.
  • •Architect integrations with Sigstore services such as Cosign, Fulcio, and Rekor, including approaches for signing workflows, verification, and trust boundaries.
  • •Design backend services and request paths that support allow, deny, and quarantine package policies with strong performance and reliability expectations.
  • •Review merge requests with a focus on security, architectural consistency, maintainability, and test quality.

Key Requirements

  • •Strong experience building backend applications with Ruby on Rails in a high-scale production environment.
  • •Professional experience with Go for backend or infrastructure-oriented services.
  • •A track record of leading architecture across multiple systems and influencing technical direction through strong engineering judgment.
  • •Experience writing clear technical proposals, RFCs/documents, and decision records in an async, documentation-first environment.
  • •A solid security mindset and comfort working on products where trust, risk reduction, and secure defaults are central requirements.
Experience:SoftwareSecurityDevsecopsCloud
Skills:CommunicationMentoringLeadershipArchitectureTeamwork
Languages:English
Tech Stack:Ruby on RailsGoSigstoreCosignFulcioRekorCI/CD

Company Brief

GitLab
Provides a single application for the complete DevSecOps lifecycle, offering source code management, CI/CD, security, and collaboration tools to help teams deliver software faster and more securely.
Industry: Developer Tools
Company Size: Enterprise (1,001+ employees)
Revenue: USD 250M to 500M
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: San Francisco, United States
Founded: 2011
WebsiteLinkedIn