Director of Engineering Security Factory
GitLab is an AI-powered DevSecOps platform that unifies the entire software development lifecycle into a single application. It helps development, security, and operations teams to collaborate and deliver software more efficiently, with security integrated at every step. The platform is trusted by millions of users and a majority of the Fortune 100.
About GitLab Inc.
GitLab is a comprehensive, AI-powered DevSecOps platform that streamlines the entire software delivery process by unifying the development lifecycle into a single application. It integrates source code management, CI/CD, security, and monitoring to help teams build, secure, and operate software more efficiently. Key features include automated security scans built into the development pipeline and AI-driven tools like GitLab Duo for code suggestions and chat, which enhance developer productivity. GitLab serves a diverse client base, from startups and open-source projects to large enterprises, including over half of the Fortune 100. The platform aims to reduce complexity, accelerate delivery cycles, and strengthen security and compliance for its users.
Skills
About the Role
You will lead a distributed engineering organization responsible for customer-facing security capabilities. You will set the engineering vision and multi-quarter roadmap, guide managers and individual contributors, make architectural decisions, and deliver proprietary scanners, AI-driven detection, agentic remediation, and security foundations. You will partner with product management, represent the function in planning and customer discussions, establish delivery and quality standards, and contribute through documentation, issues, and merge requests.
Requirements
- Experience leading engineering organizations with multiple teams and managers in a distributed environment.
- Understanding of application security fundamentals, including Static Application Security Testing, Software Composition Analysis, secret detection, vulnerability management workflows, and software supply chain security.
- Experience building detection, analysis, or scanning systems in a software as a service or DevSecOps environment.
- Experience shipping a customer-facing AI or machine learning product feature tied to detection or remediation quality outcomes.
- Ability to partner with product management on roadmap planning, prioritization, and requirements.
- Written communication skills and comfort leading through documentation in a remote, async-first organization.
- Familiarity with agentic AI systems, AI agent orchestration, threat intelligence research, or open source security tooling is useful.
Responsibilities
- Set the engineering vision and multi-quarter roadmap for security scanners, AI-driven workflows, research, vulnerability management, and security foundations.
- Lead a distributed engineering organization of managers and individual contributors.
- Drive architectural decisions for AI and machine learning detection engines, agentic remediation flows, and scalable scanning infrastructure.
- Partner with product management to define priorities, shape requirements, and deliver security capabilities.
- Own engineering delivery for proprietary application security scanners, agentic remediation workflows, and AI security research.
- Represent the Security Factory stage in cross-functional planning, executive reviews, security disclosures, and customer conversations.
- Establish engineering standards for delivery, observability, incident response, scanner quality, and code quality.
- Contribute through issues, merge requests, and the GitLab handbook.
Benefits
- Health, financial, and well-being benefits
- Flexible Paid Time Off
- Team Member Resource Groups
- Equity compensation and Employee Stock Purchase Plan
- Parental Leave
