MENU
  • Remote Jobs
  • Companies
  • Go Premium
  • Job Alerts
  • Post a Job
  • Log in
  • Sign up
Working Nomads logo Working Nomads
  • Remote Jobs
  • Companies
  • Post Jobs
  • Go Premium
  • Get Free Job Alerts
  • Log in

Engineering Manager - Software Supply Chain Security: Pipeline Security

GitLab

Full-time
USA
$132k-$282k per year
supply chain
security
software engineering
Apply for this position

An overview of this role

As the Engineering Manager, Software Supply Chain Security: Pipeline Security, you’ll lead a team that makes GitLab CI pipelines more secure and trustworthy for thousands of organizations. You’ll guide the design and delivery of Software Supply Chain Security features, with a primary focus on CI job artifact security. This includes implementing the SLSA (Supply-chain Levels for Software Artifacts) framework in GitLab CI/CD and integrating related capabilities like SBOM, software composition analysis, and vulnerability management. You’ll treat your team as your product, safeguarding team health, hiring and developing a high-performing group of engineers, and collaborating closely with Product Management and Security to deliver on roadmap commitments. Together, you’ll improve how users protect their software supply chains in their first year and beyond.

Some examples of our projects:

  • Developing a native secrets management system for GitLab CI pipelines

  • Implementing SLSA Level 3 compliance features for CI job artifacts

What you’ll do

  • Lead a team of engineers building Software Supply Chain Security features with a focus on CI job artifact security.

  • Guide the design and implementation of SLSA (Supply-chain Levels for Software Artifacts) compliance within GitLab CI/CD pipelines.

  • Collaborate with Product Managers to define, prioritize, and deliver the roadmap for supply chain security capabilities.

  • Partner with Security team members to ensure new and existing features meet GitLab’s security standards and align with best practices.

  • Stay current with software supply chain security standards and tools, including SLSA, SBOM, software composition analysis, and vulnerability management. Translate what you learn into actionable product improvements.

  • Educate and advocate for supply chain security best practices across engineering teams to drive adoption of secure patterns in CI pipelines.

  • Represent the Pipeline Security team in cross-functional initiatives and, when appropriate, in external industry forums focused on software supply chain security.

  • Drive continuous improvement in team health, delivery predictability, and documentation quality for pipeline and supply chain security features.

What you’ll bring

  • Experience leading and developing engineering teams, with a focus on building secure, reliable product features.

  • Practical knowledge of software supply chain security concepts, tools, and industry standards.

  • Understanding of the SLSA (Supply-chain Levels for Software Artifacts) framework and how to apply it in CI/CD pipelines.

  • Familiarity with software artifact provenance, attestation, and verification techniques.

  • Knowledge of secure software development practices, including container security, software composition analysis, and vulnerability management.

  • Experience working with CI/CD systems and their security considerations.

  • Ability to collaborate effectively with product management, security, and other cross-functional partners, and to advocate for supply chain security best practices.

  • Openness to learning new technologies and approaches, with transferable skills from related security, infrastructure, or software engineering domains.

About the team

Our Pipeline Security team is a globally distributed group of engineers who collaborate asynchronously across time zones. We're focused on building Software Supply Chain Security features into the core GitLab platform, with current priorities including native secrets management for CI pipelines, artifact provenance and verification, and achieving SLSA Level 3 compliance. We partner closely with Product, Security, and other stage groups to design and implement these capabilities. We value clear communication, thorough documentation, and making new features straightforward for users to adopt.

The base salary range for this role’s listed level is currently for residents of the United States only. This range is intended to reflect the role's base salary rate in locations throughout the US. Grade level and salary ranges are determined through interviews and a review of education, experience, knowledge, skills, abilities of the applicant, equity with other team members, alignment with market data, and geographic location. The base salary range does not include any bonuses, equity, or benefits. See more information on our benefits and equity. Sales roles are also eligible for incentive pay targeted at up to 100% of the offered base salary.

United States Salary Range

$131,600—$282,000 USD

Apply for this position
Bookmark Report

About the job

Full-time
USA
Senior Level
$132k-$282k per year
Posted 7 hours ago
supply chain
security
software engineering

Apply for this position

Bookmark
Report
Enhancv advertisement
+ 1,284 new jobs added today
30,000+
Remote Jobs

Don't miss out — new listings every hour

Join Premium

Engineering Manager - Software Supply Chain Security: Pipeline Security

GitLab

An overview of this role

As the Engineering Manager, Software Supply Chain Security: Pipeline Security, you’ll lead a team that makes GitLab CI pipelines more secure and trustworthy for thousands of organizations. You’ll guide the design and delivery of Software Supply Chain Security features, with a primary focus on CI job artifact security. This includes implementing the SLSA (Supply-chain Levels for Software Artifacts) framework in GitLab CI/CD and integrating related capabilities like SBOM, software composition analysis, and vulnerability management. You’ll treat your team as your product, safeguarding team health, hiring and developing a high-performing group of engineers, and collaborating closely with Product Management and Security to deliver on roadmap commitments. Together, you’ll improve how users protect their software supply chains in their first year and beyond.

Some examples of our projects:

  • Developing a native secrets management system for GitLab CI pipelines

  • Implementing SLSA Level 3 compliance features for CI job artifacts

What you’ll do

  • Lead a team of engineers building Software Supply Chain Security features with a focus on CI job artifact security.

  • Guide the design and implementation of SLSA (Supply-chain Levels for Software Artifacts) compliance within GitLab CI/CD pipelines.

  • Collaborate with Product Managers to define, prioritize, and deliver the roadmap for supply chain security capabilities.

  • Partner with Security team members to ensure new and existing features meet GitLab’s security standards and align with best practices.

  • Stay current with software supply chain security standards and tools, including SLSA, SBOM, software composition analysis, and vulnerability management. Translate what you learn into actionable product improvements.

  • Educate and advocate for supply chain security best practices across engineering teams to drive adoption of secure patterns in CI pipelines.

  • Represent the Pipeline Security team in cross-functional initiatives and, when appropriate, in external industry forums focused on software supply chain security.

  • Drive continuous improvement in team health, delivery predictability, and documentation quality for pipeline and supply chain security features.

What you’ll bring

  • Experience leading and developing engineering teams, with a focus on building secure, reliable product features.

  • Practical knowledge of software supply chain security concepts, tools, and industry standards.

  • Understanding of the SLSA (Supply-chain Levels for Software Artifacts) framework and how to apply it in CI/CD pipelines.

  • Familiarity with software artifact provenance, attestation, and verification techniques.

  • Knowledge of secure software development practices, including container security, software composition analysis, and vulnerability management.

  • Experience working with CI/CD systems and their security considerations.

  • Ability to collaborate effectively with product management, security, and other cross-functional partners, and to advocate for supply chain security best practices.

  • Openness to learning new technologies and approaches, with transferable skills from related security, infrastructure, or software engineering domains.

About the team

Our Pipeline Security team is a globally distributed group of engineers who collaborate asynchronously across time zones. We're focused on building Software Supply Chain Security features into the core GitLab platform, with current priorities including native secrets management for CI pipelines, artifact provenance and verification, and achieving SLSA Level 3 compliance. We partner closely with Product, Security, and other stage groups to design and implement these capabilities. We value clear communication, thorough documentation, and making new features straightforward for users to adopt.

The base salary range for this role’s listed level is currently for residents of the United States only. This range is intended to reflect the role's base salary rate in locations throughout the US. Grade level and salary ranges are determined through interviews and a review of education, experience, knowledge, skills, abilities of the applicant, equity with other team members, alignment with market data, and geographic location. The base salary range does not include any bonuses, equity, or benefits. See more information on our benefits and equity. Sales roles are also eligible for incentive pay targeted at up to 100% of the offered base salary.

United States Salary Range

$131,600—$282,000 USD

Working Nomads

Post Jobs
Premium Subscription
Sponsorship
Reviews
Job Alerts

Job Skills
Jobs by Location
API
FAQ
Privacy policy
Terms and conditions
Contact us
About us

Jobs by Category

Remote Administration jobs
Remote Consulting jobs
Remote Customer Success jobs
Remote Development jobs
Remote Design jobs
Remote Education jobs
Remote Finance jobs
Remote Legal jobs
Remote Healthcare jobs
Remote Human Resources jobs
Remote Management jobs
Remote Marketing jobs
Remote Sales jobs
Remote System Administration jobs
Remote Writing jobs

Jobs by Position Type

Remote Full-time jobs
Remote Part-time jobs
Remote Contract jobs

Jobs by Region

Remote jobs Anywhere
Remote jobs North America
Remote jobs Latin America
Remote jobs Europe
Remote jobs Middle East
Remote jobs Africa
Remote jobs APAC

Jobs by Skill

Remote Accounting jobs
Remote Assistant jobs
Remote Copywriting jobs
Remote Cyber Security jobs
Remote Data Analyst jobs
Remote Data Entry jobs
Remote English jobs
Remote Spanish jobs
Remote Project Management jobs
Remote QA jobs
Remote SEO jobs

Jobs by Country

Remote jobs Australia
Remote jobs Argentina
Remote jobs Brazil
Remote jobs Canada
Remote jobs Colombia
Remote jobs France
Remote jobs Germany
Remote jobs Ireland
Remote jobs India
Remote jobs Japan
Remote jobs Mexico
Remote jobs Netherlands
Remote jobs New Zealand
Remote jobs Philippines
Remote jobs Poland
Remote jobs Portugal
Remote jobs Singapore
Remote jobs Spain
Remote jobs UK
Remote jobs USA


Working Nomads curates remote digital jobs from around the web.

© 2025 Working Nomads.