Intermediate Backend Engineer, Application Security Testing: Composition Analysis

GitLab • USA

Company

GitLab

Location

USA

Type

Full Time

Job Description

An overview of this role

Your role is to implement new features as well as improve and maintain existing ones in collaboration with your Engineering peers and our colleagues in Product Security and Quality. You will work in tandem with other groups in the Sec Section to deliver products that protect customers applications and provide them with confidence to deliver secure software ever faster.

In your day to day you will experience direct communication with customers open source contributors and with product management. You will work to create a lovable experience for product categories that are used by thousands of users and you will have access to feedback from those users both internal and external. You will work on three main goals:

  • Gather  - Introduce data points that help customers understand the urgency of issues in their security posture; e.g:

    • Reachability analysis - is this dependency used by the customers application?

    • Supply chain poisoning - has this dependency been tampered with?

    • Attribution of vulnerabilities - where and when has vulnerability been introduced?

  • Integrate  - Provide other groups with the means to take advantage of our innovative collection techniques to deliver better workflows for our customers

  • Optimize - Solve data correlation at massive scale

Some examples of our projects:

What You’ll Do

  • Develop features and improvements to the GitLab product in a secure well-tested and performant way.

  • Collaborate with Product Management and other stakeholders within Engineering (Frontend UX etc.) to maintain a high bar for quality in a fast-paced iterative environment.

  • Advocate for improvements to product quality security and performance.

  • Solve technical problems of moderate scope and complexity.

  • Craft code that meets our internal standards for style maintainability and best practices for a high-scale web environment.

  • Maintain and advocate for these standards through code review.

  • Recognize impediments to our efficiency as a team (“technical debt”) propose and implement solutions.

  • Participate in Tier 2 or Tier 3 weekday and weekend and occasional night on-call rotations to assist troubleshooting product operations security operations and urgent engineering issues.

  • Participate in the reaction rotation where engineers take turns addressing security support and maintenance issues.

What You’ll Bring

  • Professional experience with Ruby on Rails and PostgreSQL. Experience with Golang is a bonus.

  • Passion about security

  • Demonstrated capacity to clearly and concisely communicate about complex technical architectural and/or organizational problems and propose thorough iterative solutions.

  • Experience with performance and optimization problems particularly at large scale and a demonstrated ability to both diagnose and prevent these problems.

  • Comfort working in a highly agile intensely iterative software development process.

  • Positive and solution-oriented mindset.

  • An inclination towards communication inclusion and visibility.

  • Experience owning a project from concept to production including proposal discussion and execution.

  • Self-motivated and self-managing with excellent organizational skills.

About the team

The Composition Analysis team is responsible for Software Composition Analysis and Container Scanning categories in GitLab.

Our tools can identify software licenses and search for security vulnerabilities in applications container images and Kubernetes environments so that developers can identify and address them as soon as possible.

We have team members in North America Europe & Asia and because of the multiple time zones we rely heavily on asynchronous work.

Thanks to our Transparency value you can see the priorities in our roadmap the make-up of our team and our milestone planning issues .

How GitLab will support you

Please note that we welcome interest from candidates with varying levels of experience; many successful candidates do not meet every single requirement. Additionally studies have shown that people from underrepresented groups are less likely to apply to a job unless they meet every single qualification. If you're excited about this role please apply and allow our recruiters to assess your application.

Apply Now

Date Posted

01/30/2025

Views

0

Back to Job Listings ❤️Add To Job List Company Info View Company Reviews
Positive
Subjectivity Score: 0.9

Similar Jobs

Events Marketing Specialist - Finalsite

Views in the last 30 days - 0

Finalsite a leading community relationship management platform for K12 schools is seeking a highly organized and detailoriented Events Marketing Speci...

View Details

Developer II - Eventbrite, Inc.

Views in the last 30 days - 0

Eventbrite is seeking a Web Application Developer to join their highperforming GTM Gotomarket Business Systems team The role involves implementing and...

View Details

Mobile Engineering Manager - Mobile Retention - Dropbox

Views in the last 30 days - 0

Dropbox is seeking a Mobile Engineering Manager to lead a team of iOS and Android engineers working on the Dropbox apps The role involves managing cri...

View Details

Commercial Account Executive - Mid Market - MariaDB plc

Views in the last 30 days - 0

MariaDB is a leading database for modern application development used by 75 of the Fortune 500 and billions of people daily The company is seeking a C...

View Details

Senior Data Scientist - Dropbox

Views in the last 30 days - 0

The text describes a unique opportunity for a Senior Data Scientist to join a new division at Dropbox focusing on AI and ML The role involves partneri...

View Details

Solution Engineer - Ottimate

Views in the last 30 days - 0

Ottimate is a company that automates accounts payables for fastgrowing businesses They offer a cloudfirst approach for invoice management and payments...

View Details