GitLab · 2 weeks ago
Software Engineering Manager, Application Security Testing: Composition Analysis & Dynamic Analysis
GitLab is an open-core software company that develops the most comprehensive AI-powered DevSecOps Platform, used by more than 100,000 organizations. As an Engineering Manager for Composition Analysis and Dynamic Analysis, you will lead multiple teams to build application security scanning capabilities that help customers find and fix vulnerabilities in their software supply chain and web applications.
Cloud SecurityDeveloper ToolsDevOpsOpen SourceSaaS
Responsibilities
Lead engineers across the Composition Analysis and Dynamic Analysis groups, setting clear priorities and expectations
Drive key security initiatives, including auto-remediation of vulnerable software packages, scanning unmanaged C/C++ dependencies, static reachability analysis, and snippet detection for open source dependencies
Improve Dynamic Analysis Security Testing (DAST) capabilities by enhancing the crawler for efficiency, stability, and consistent web application traversal
Balance priorities and resources across multiple security-focused engineering teams to ensure sustainable delivery and high-quality outcomes
Author and maintain project plans for epics spanning both groups, aligning work, identifying dependencies, and avoiding duplication of effort
Run agile project management processes for multiple teams, including planning, estimation, and continuous improvement of delivery practices
Provide guidance on the architecture of security products, ensuring that software composition analysis and dynamic analysis solutions are robust and scalable
Collaborate closely with Composition Analysis and Dynamic Analysis teams to ensure consistent, complementary approaches to application security across GitLab’s platform
Qualification
Required
Background leading multiple technical teams or groups, ideally in application security or related domains
Practical understanding of software composition analysis, including how to assess and manage risks in application dependencies
Knowledge of dynamic application security testing (DAST), API security, and web application security testing techniques and tools
Familiarity with containerization technologies, package managers, and dependency management systems
Experience working with or around open source security tooling (for example, OWASP ZAP, Trivy, or similar tools)
Ability to plan and run agile project management processes across several teams, including coordinating priorities and dependencies
Skill in guiding product and architecture decisions for security scanning tools, balancing technical constraints with customer needs
Openness to candidates with transferable experience in security engineering, DevSecOps, or vulnerability management who are motivated to grow in application security leadership
Benefits
Flexible Paid Time Off
Team Member Resource Groups
Equity Compensation & Employee Stock Purchase Plan
Growth and Development Fund
Parental leave
Home office support
Company
GitLab
GitLab is a web-based Git repository manager that offers a variety of features for software development teams.
Funding
Current Stage
Public CompanyTotal Funding
$413.5MKey Investors
ICONIQ GrowthGoogle VenturesAugust Capital
2021-10-14IPO
2019-09-17Series E· $268M
2018-09-19Series D· $100M
Recent News
2026-01-16
2026-01-16
2026-01-13
Company data provided by crunchbase