🏢
Gitlab
Senior Manager, Product Security Engineering (Security Posture and Supply Chain)
Job Description
ABOUT THE ROLE
GitLab’s Product Security Department is building the most trusted DevSecOps platform in the world, and the Senior Manager of Security Posture Management leads the team that secures the very factory that delivers that platform. In this role you will own the strategy, delivery, and growth of the Security Posture Management (SPM) team, ensuring that every GitLab project is aligned with the Project Security Configuration Standard and that our own software factory remains a living example of secure engineering. You will be the Customer Zero for our security features, turning internal adoption data into actionable insights for Product and Engineering and shaping the roadmap that protects millions of developers worldwide. Your work will directly influence the security posture of the entire GitLab ecosystem, reduce systemic risk, and provide audit evidence that satisfies external certifications and internal maturity assessments.
WHAT YOU'LL DO
Lead comprehensive, governed rollouts of GitLab’s security capabilities across the entire estate, ensuring every project meets the Project Security Configuration Standard and remains compliant over time. Set secure defaults and streamlined paths that accelerate engineering rather than gate it, so teams can ship faster with built‑in protection. Serve as Customer Zero, capturing adoption friction at scale and feeding that intelligence back to Product and Engineering to guide roadmap decisions. Establish proactive software supply chain security as a core capability, including third‑party component governance, trusted dependency controls, and product‑level SBOM requirements. Own the Product Security Risk Register, developing metrics and dashboards that give the department a single, data‑driven view of our posture. Partner with Compliance to produce evidence of security control implementation for audits, certifications, and maturity assessments, ensuring that hardening the estate also satisfies auditors. Represent this work externally, contributing thought leadership that strengthens GitLab’s go‑to‑market narrative and builds customer trust. Lead, coach, and grow a high‑performance team, shaping its operating model as it evolves.
WHAT YOU'LL NEED
Experience managing a security or engineering team, including hiring, performance management, and career development. Deep technical fluency in security posture management, software supply chain security, and secure configuration of large SaaS estates, with the ability to translate requirements into engineering‑friendly controls. Proven track record of driving broad, governed rollouts of security capabilities across an engineering organization you do not own, and sustaining adoption after launch. Familiarity with producing control evidence for audit, certification, or maturity assessment and partnering with Compliance or GRC counterparts. Ability to drive measurable impact under high ambiguity, building organizational buy‑in and breaking large problems into iterative wins that ship and compound. Strong written communication and sound judgment, essential for leading in an all‑remote, asynchronous environment.
WHY REMOTE
GitLab’s culture is built on distributed, asynchronous collaboration that empowers teams to work from anywhere while maintaining high performance. Flexible schedules allow you to align your work hours with your personal rhythm and your team’s needs, ensuring that critical decisions and reviews happen when all stakeholders are ready. The remote model eliminates commuting time, giving you more focus on strategic initiatives and continuous learning. By working from any location, you join a global community of engineers, product managers, and security professionals who bring diverse perspectives to solve complex problems and drive innovation.
BENEFITS
Health, dental, and vision coverage for you and your family. Generous paid time