Senior Manager, Product Security Engineering
Leads the Product Security team responsible for security posture management, governed security rollouts, and software supply chain security across GitLab’s software factory. The role combines technical security leadership, organizational adoption, audit readiness, team building, and external thought leadership.
About the job
Responsibilities
- Lead governed rollouts of GitLab security capabilities across all projects and maintain alignment with the Project Security Configuration Standard.
- Establish secure defaults and paved paths that accelerate engineering while reducing systemic risk.
- Serve as Customer Zero for GitLab security features; identify adoption friction and provide feedback to Product and Engineering.
- Establish software supply chain security, including third-party component governance, trusted dependency controls, and product-level SBOM requirements.
- Reduce systemic risk across groups and namespaces, including lateral movement and token governance.
- Own the Product Security Risk Register, metrics, and posture dashboards.
- Partner with Compliance to produce control evidence for audits, certifications, and maturity assessments.
- Represent GitLab externally on software factory security and customer trust.
- Lead, coach, hire, and grow the Product Security team.
Requirements
- Experience managing a security or engineering team, including hiring, performance management, and career development.
- Technical fluency in security posture management, software supply chain security, and secure configuration of large SaaS estates.
- Experience driving governed security rollouts across engineering organizations and sustaining adoption.
- Ability to translate security requirements into practical engineering controls.
- Familiarity with audit, certification, or maturity-assessment evidence and collaboration with Compliance or GRC teams.
- Ability to deliver measurable impact in ambiguous environments and build organizational buy-in.
- Strong problem decomposition, judgment, written communication, and effectiveness in an all-remote, asynchronous environment.
Compensation & Benefits
- United States base salary: $168,000–$245,000 USD.
- Benefits include flexible paid time off, team member resource groups, equity compensation and employee stock purchase plan, growth and development fund, and parental leave.
Skills
Security Posture Management, Software Supply Chain Security, Saas Security, Secure Configuration, Third-Party Component Governance, Dependency Management, Software Bill Of Materials, Risk Registers, Security Metrics, Security Dashboards, Compliance Audits, GRC
Similar jobs
Security Engineering jobsLeads application security initiatives across products, APIs, distributed systems, and AI-enabled applications. The role requires at least five years of security or software engineering experience, strong threat-modeling and architecture skills, and the ability to build security automation and drive remediation.
Build and operate scalable malware-analysis, threat-enrichment, and graph-intelligence systems that power security research and detection. The role requires 6+ years of security pipeline or threat-intelligence experience, strong Python or Go skills, and expertise in cloud and distributed systems.
Build and lead product and infrastructure security for systems that move money, creating secure defaults, automation, access controls, and vulnerability management processes. The role requires strong software engineering, cloud infrastructure expertise, risk-based judgment, and the ability to operate independently as the senior security engineer.
Leads engineering for Wiz’s FedRAMP CR26 initiative, translating federal compliance requirements into scalable compliance-as-code, automation, and evidence-generation solutions. Requires 6+ years in security, DevOps, or systems engineering and deep experience with NIST, FedRAMP, and government cloud environments.
The Senior Security Engineer will secure Jasper’s AI systems, cloud infrastructure, software supply chain, and compliance workflows while building automation and security standards for a growing program. The role requires 8+ years of security engineering experience and hands-on expertise across AI, cloud, or GRC security.