Senior Manager, Product Security Engineering (Security Posture and Supply Chain)

at GitLab
USD 168,000-245,000 per year
SENIOR
✅ Remote

Tech Stack

Communication @ 7 Compliance @ 3 Hiring @ 4 Security @ 6

Details

As the Senior Manager of the Security Posture Management team within the Product Security Department, you will lead the team responsible for securing GitLab's software factory. The team drives governed rollouts of GitLab security capabilities across every project, applies GitLab's own product as a customer would, and builds proactive software supply chain security as a core Product Security capability.

This role serves as Customer Zero for GitLab security features. You will identify adoption challenges at scale, provide feedback to Product and Engineering, own the team's direction and delivery, grow the organization, and create the conditions for engineers to perform at their best.

Responsibilities

  • Lead comprehensive, governed rollouts of GitLab security capabilities across the estate, aligning projects with the Project Security Configuration Standard.
  • Establish security baselines that provide secure defaults and paved paths without unnecessarily slowing engineering teams.
  • Serve as Customer Zero for GitLab security features and use adoption evidence to influence product roadmaps and customer outcomes.
  • Establish proactive software supply chain security, including third-party component governance, trusted dependency controls, and requirements for product-level software bills of materials (SBOMs).
  • Reduce systemic risk across groups and namespaces, including lateral movement and token governance.
  • Own the Product Security Risk Register and the metrics and dashboards used to provide a data-driven view of security posture.
  • Partner with Compliance to produce evidence of security control implementation for audits, certifications, and internal security maturity assessments.
  • Represent GitLab's approach to securing its software factory externally through thought leadership.
  • Lead, coach, hire, and develop the team while shaping its operating model.

Requirements

  • Experience managing a security or engineering team, including hiring, performance management, and career development.
  • Technical fluency in security posture management, software supply chain security, and secure configuration of a large SaaS estate.
  • Experience driving broad, governed security capability rollouts across engineering organizations and sustaining adoption after launch.
  • Experience translating security requirements into controls that engineering teams can meet efficiently.
  • Familiarity with producing control evidence for audits, certifications, or maturity assessments and partnering with Compliance or GRC teams.
  • Ability to drive measurable impact in ambiguous environments and build organizational buy-in.
  • Ability to break large problems into iterative improvements that ship and compound.
  • Sound judgment and strong written communication skills for leading in an all-remote, asynchronous environment.

Benefits

  • Benefits supporting health, finances, and well-being.
  • Flexible paid time off.
  • Team member resource groups.
  • Equity compensation and employee stock purchase plan.
  • Growth and development fund.
  • Parental leave.

The United States base salary range for this role is $168,000–$245,000 USD. The range excludes bonuses, equity, and benefits. GitLab welcomes candidates with varying levels of experience and is an equal opportunity workplace.

More jobs at GitLab

Similar jobs