An Overview Of This Role
As a Senior Backend Engineer at GitLab, you will help build the core capabilities of our dedicated software supply chain security Add‑On, a commercial offering that lets organizations control what software enters their builds, verify what they ship and identify malicious packages before they reach production. You will work across backend systems that support package policy enforcement, artifact signing and verification, provenance attestation, and malicious package intelligence.
Some Examples Of Our Projects
- Building backend services for package policy enforcement and dependency control
- Implementing artifact signing, verification, and provenance workflows using the Sigstore ecosystem
What You’ll Do
- Design and implement backend features across the Add‑On’s software supply chain security surface, including policy enforcement, artifact signing and verification, provenance attestation APIs, and malicious package detection integrations.
- Build and improve the package policy evaluation engine, including rule compilation, request matching, enforcement decisions and performance‑sensitive execution paths tied to GitLab’s Dependency Firewall infrastructure.
- Develop artifact signing and verification workflows, including Sigstore and Cosign integrations, signing key lifecycle management, keyless signing with OpenID Connect (OIDC), and policy‑based promotion gates.
- Create and evolve configuration interfaces that enterprise security teams use, including backend APIs and the GraphQL surface for expressing supply chain security requirements.
- Integrate Add‑On capabilities with GitLab’s existing security policy framework, including policy inheritance and policy‑as‑code support through YAML.
- Collaborate with adjacent teams as malicious package intelligence is incorporated into the Add‑On offering.
- Write and maintain comprehensive RSpec and integration test coverage, and help improve test reliability across the team.
- Review merge requests with a security‑first mindset and partner with the Staff Backend Engineer to maintain code quality and secure engineering standards.
What You’ll Bring
- Proven backend engineering experience with production Ruby on Rails expertise.
- Working knowledge of Go or a willingness to ramp up quickly.
- Solid API design skills, including REST, GraphQL, and defining clear internal service boundaries.
- Solid PostgreSQL fundamentals, including schema design, query optimization and indexing strategies.
- Experience with Redis for caching and distributed coordination patterns.
- A security‑aware engineering mindset with sound judgment around trust boundaries, input validation and failure modes.
- Familiarity with software supply chain security concepts such as SLSA, SBOM, artifact signing and related scanning approaches.
- Interest in complex policy, registry or platform problems, including rules engines, package ecosystems, cryptographic signing or DevSecOps product development.
About The Team
The SSCS Add‑On team is part of GitLab’s Software Supply Chain Security stage, focused on building a commercial offering that addresses real supply chain security challenges for enterprise customers. The team builds in a space shaped by fast‑moving threats, evolving customer requirements and close coordination with other security teams.
How GitLab Supports Full-Time Employees
- Benefits to support your health, finances and well‑being
- Flexible Paid Time Off
- Team Member Resource Groups
- Equity Compensation & Employee Stock Purchase Plan
- Growth and Development Fund
- Parental leave
- Home office support
GitLab is proud to be an equal opportunity workplace and is an affirmative action employer. GitLab’s policies and practices relating to recruitment, employment, career development and advancement, promotion, and retirement are based solely on merit, regardless of race, color, religion, ancestry, sex (including pregnancy, lactation, sexual orientation, gender identity, or gender expression), national origin, age, citizenship, marital status, mental or physical disability, genetic information (including family medical history), discharge status from the military, protected veteran status (which includes disabled veterans, recently separated veterans, active duty wartime or campaign badge veterans, and Armed Forces service medal veterans), or any other basis protected by law. GitLab will not tolerate discrimination or harassment based on any of these characteristics. See also GitLab’s EEO Policy and EEO is the Law. If you have a disability or special need that requires accommodation, please let us know during the recruiting process.