Staff Backend Engineer, Software Supply Chain Security
Core
Senior technical leader shaping GitLab's Software Supply Chain Security offering, building backend systems to secure how software is built, verified, and delivered.
Role type
Staff Backend Engineer (Software Supply Chain Security)
Builds
GitLab SSCS Add-On, including package policy enforcement, build provenance, artifact signing, and malicious package detection capabilities.
Domain
Software Supply Chain Security / DevSecOps
Deliverable
production ML models | product features
Required skills
Ruby on Rails (high-scale), Go (backend/infrastructure), architectural leadership, technical proposal writing, security mindset, supply chain security concepts (provenance, signing, SBOM)
Preferred skills
Sigstore ecosystem familiarity, SLSA Level 2/3 implementation experience, open source contribution
Technologies
Ruby on Rails, Go, Sigstore (Cosign, Fulcio, Rekor), SLSA
Responsibilities
Define and drive technical architecture for the SSCS Add-On; Lead design and implementation of SLSA Level 2 and 3 capabilities; Architect integrations with Sigstore services; Design backend services for package policies; Review merge requests for security and quality; Mentor Backend Engineers; Partner with cross-functional teams on technical decisions.
Seniority
Staff, hands-on IC with architectural leadership