GitLab

Intermediate Backend Engineer, Security Risk Management: Security Policies (Ruby)

Remote

Not SpecifiedCompensation
Junior (1 to 2 years)Experience Level
Full TimeJob Type
UnknownVisa
Cybersecurity, DevSecOps, Software DevelopmentIndustries

Backend Engineer, Security Policies

Company Information

GitLab is an open-core software company that develops the most comprehensive AI-powered DevSecOps Platform, used by more than 100,000 organizations. Our mission is to enable everyone to contribute to and co-create the software that powers our world. We embrace AI as a core productivity multiplier, encouraging team members to incorporate AI into their daily workflows.

Position Overview

Join GitLab's Security Policies team as a Backend Engineer to architect the security infrastructure protecting millions of applications worldwide. This role involves a major technical transformation: migrating from YAML-based policy storage to first-class GitLab entities. You will become a cross-platform integration expert, connecting features across the entire GitLab platform. This is an opportunity to design solutions that efficiently enforce security policies across thousands of projects for the world's largest organizations, making policies invisible to developers while providing unprecedented control to security teams.

Examples of our projects:

  • Pipeline Execution Policies - Intelligent automation for security workflows
  • Scan Execution Policies - Adaptive security scanning across diverse tech stacks
  • Merge Request Approval Policies - Sophisticated approval workflows that scale with enterprise needs
  • External Status Checks - Seamless third-party security tool integration

Responsibilities

  • Lead the architectural transformation of policy storage from YAML files to first-class GitLab entities.
  • Design and implement security policy features that enforce behaviors across thousands of projects efficiently.
  • Serve as DRI (Directly Responsible Individual) for features, taking them from initial planning through successful release with post-coverage.
  • Connect and integrate features across GitLab's platform, working with teams from Verify to Code Review.
  • Champion comprehensive testing and code quality improvements to ensure reliability at scale.
  • Collaborate with Sec Section teams and cross-functional partners to deliver seamless security automation.
  • Optimize performance and security in high-scale distributed systems.
  • Provide technical leadership by independently solving complex requirements with minimal guidance.
  • Contribute to on-call rotations, ensuring the stability and security of GitLab operations.

Requirements

  • Proven expertise in Ruby on Rails development (2-4 years experience).
  • Proficiency in SQL databases, particularly PostgreSQL.
  • Strong understanding of software testing methodologies and test-driven development practices.
  • API development and integration experience with complex systems.
  • Ability to understand and work with large, interconnected codebases and abstract complex problems.
  • Experience taking projects from concept to production independently.
  • Effective communication skills and ability to collaborate across multiple teams and time zones.
  • Security domain knowledge.

Employment Type

  • [Employment Type Not Specified]

Location Type

  • [Location Type Not Specified]

Salary

  • [Salary Not Specified]

Application Instructions

  • [Application Instructions Not Specified]

Skills

Ruby
Security Policies
Security Automation
GitLab Entities
Cross-platform Integration
Security Infrastructure Design

GitLab

Unified DevOps platform for software development

About GitLab

GitLab offers a DevOps platform that simplifies the software development process by providing a single application for collaboration, visibility, and speed. The platform integrates various tools needed for software development, which helps teams manage their projects more efficiently without juggling multiple tools. This allows companies to concentrate on enhancing their products instead of spending too much time on builds. GitLab serves a wide range of clients, including large corporations from different industries, demonstrating its versatility. The company operates on a subscription-based model, where clients pay for access to the platform, which includes features for continuous integration and deployment. GitLab also provides free trials and regularly updates its platform to deliver ongoing value to its users. By customizing its offerings and partnering with other technology providers, GitLab aims to enhance its ecosystem and drive revenue.

San Francisco, CaliforniaHeadquarters
2014Year Founded
$421.8MTotal Funding
IPOCompany Stage
Consulting, Enterprise SoftwareIndustries
1,001-5,000Employees

Benefits

Spending Company Money
Equity Compensation
Life Insurance
Financial Wellness
Paid Time Off
Growth and Development Benefit
GitLab Contribute
Business Travel Accident Policy
Immigration
Employee Assistance Program
Incentives
All-Remote
Part-time contracts
Meal Train
Fertility & Family Planning
Parental Leave

Risks

AI-powered coding assistants like Claude pose a competitive threat to GitLab's platform.
Potential sale to Datadog may lead to strategic shifts misaligned with customer expectations.
Integration of Oxeye may distract from GitLab's core DevOps offerings.

Differentiation

GitLab offers a unified DevOps platform, reducing complexity in software development.
The platform integrates tools for collaboration, visibility, and speed, enhancing development processes.
GitLab's open-source model fosters continuous innovation with a large developer community.

Upsides

Acquiring Oxeye enhances GitLab's cloud security, appealing to security-conscious enterprises.
Partnership with Ooredoo Kuwait expands GitLab's influence in the telecommunications sector.
Potential sale to Datadog could create strategic synergies and expand market reach.

Land your dream remote job 3x faster with AI