Senior Backend Engineer
GitLab is an AI-powered DevSecOps platform that unifies the entire software development lifecycle into a single application. It helps development, security, and operations teams to collaborate and deliver software more efficiently, with security integrated at every step. The platform is trusted by millions of users and a majority of the Fortune 100.
About GitLab Inc.
GitLab is a comprehensive, AI-powered DevSecOps platform that streamlines the entire software delivery process by unifying the development lifecycle into a single application. It integrates source code management, CI/CD, security, and monitoring to help teams build, secure, and operate software more efficiently. Key features include automated security scans built into the development pipeline and AI-driven tools like GitLab Duo for code suggestions and chat, which enhance developer productivity. GitLab serves a diverse client base, from startups and open-source projects to large enterprises, including over half of the Fortune 100. The platform aims to reduce complexity, accelerate delivery cycles, and strengthen security and compliance for its users.
Skills
About the Role
You will design and implement secure backend features for a software supply chain security add-on. You will build package policy evaluation, artifact signing and verification, provenance attestation APIs, and malicious package detection integrations. You will create backend and GraphQL configuration interfaces, integrate with security policy frameworks, maintain RSpec and integration tests, review merge requests with a security-first mindset, and collaborate on architecture and cross-functional product delivery in an all-remote, asynchronous environment.
Requirements
- Proven backend engineering experience with production Ruby on Rails expertise.
- Working knowledge of Go or the willingness and ability to learn it quickly.
- API design experience with REST, GraphQL, and internal service boundaries.
- PostgreSQL knowledge, including schema design, query optimization, and indexing strategies.
- Experience with Redis for caching and distributed coordination patterns.
- Security-aware engineering judgment concerning trust boundaries, input validation, and failure modes.
- Familiarity with software supply chain security concepts such as SLSA, SBOM, artifact signing, or security scanning.
- Interest in rules engines, package ecosystems, cryptographic signing, DevSecOps product development, or related policy, registry, and platform problems.
Responsibilities
- Design and implement backend features for policy enforcement, artifact signing and verification, provenance attestation APIs, and malicious package detection integrations.
- Build and improve the package policy evaluation engine, including rule compilation, request matching, enforcement decisions, and performance-sensitive execution paths.
- Develop artifact signing and verification workflows using Sigstore, Cosign, signing key lifecycle management, keyless signing with OpenID Connect, and policy-based promotion gates.
- Create and evolve backend APIs and GraphQL configuration interfaces for enterprise security teams.
- Integrate add-on capabilities with the existing security policy framework, including policy inheritance and policy-as-code support through YAML.
- Collaborate with adjacent teams to incorporate malicious package intelligence into the add-on.
- Write and maintain RSpec and integration test coverage and improve test reliability.
- Review merge requests with a security-first mindset and implement solutions in partnership with the Staff Backend Engineer.
Benefits
- Health, financial, and well-being benefits.
- Flexible Paid Time Off.
- Team Member Resource Groups.
- Equity compensation and Employee Stock Purchase Plan.
- Growth and Development Fund.
- Parental Leave.
