Engineering Manager - Application Security Testing: Composition & Dynamic Analysis at GitLab

We are redirecting you to the source. If you are not redirected in 3 seconds, please click here.

Engineering Manager - Application Security Testing: Composition & Dynamic Analysis at GitLab. Location Information: Anywhere. The Engineering Manager for Composition Analysis and Dynamic Analysis specializes in leading teams focused on application security scanning technologies. This role oversees multiple security-focused engineering groups and is responsible for balancing priorities across these specialized teams.. This role is an extension of the . Engineering Manager position. .. Groups Overview. Composition Analysis -The Composition Analysis group is responsible for:. Software Composition Analysis. Container Scanning. Dynamic Analysis - The Dynamic Analysis group is responsible for:. API Security. Dynamic Analysis Security Testing (DAST). Fuzz Testing. What you’ll do. Manage engineers across both the Composition Analysis and Dynamic Analysis groups. Drive key initiatives including:. Auto-remediation of vulnerable software packages. Scanning of unmanaged dependencies in C/C++. Static reachability analysis with function-level granularity. Snippet detection for open source dependencies. Improve the DAST crawler for efficiency, stability, and consistent web application traversal. Balance priorities across multiple security-focused engineering teams. Author project plans for epics across both groups, ensuring alignment and avoiding duplication of effort. Run agile project management processes for multiple teams. Provide guidance on security product architecture. Coordinate between Composition Analysis and Dynamic Analysis teams to ensure consistent and complementary approaches to application security. What you’ll bring. In-depth understanding of application security concepts, particularly in software composition analysis techniques to evaluate the security risks associated with application dependencies and dynamic analysis security testing (DAST) tools.. Understanding of the challenges in developing and maintaining security scanning tools. Experience managing multiple technical teams simultaneously. Familiarity with containerization technologies and dependency management systems. Knowledge of web application security testing techniques and tools. Experience with open source security tooling (such as OWASP ZAP, Trivy, or similar). Experience in DevSecOps practices and implementation. Experience in vulnerability management and remediation. How GitLab will support you. Benefits to support your health, finances, and well-being. All remote. , . asynchronous. work environment. Flexible Paid Time Off.  . Team Member Resource Groups. Equity Compensation & Employee Stock Purchase Plan. Growth and Development Fund. Parental leave.  . Home office. support. Please note that we welcome interest from candidates with varying levels of experience; many successful candidates do not meet every single requirement. Additionally, studies have shown that people from . underrepresented groups. are less likely to apply to a job unless they meet every single qualification. If you're excited about this role, please apply and allow our recruiters to assess your application.. The base salary range for this role’s listed level is currently for residents of listed locations only. Grade level and salary ranges are determined through interviews and a review of education, experience, knowledge, skills, abilities of the applicant, equity with other team members, and alignment with market data. See more information on our . benefits. and . equity. . Sales roles are also eligible for incentive pay targeted at up to 100% of the offered base salary.. California/Colorado/Hawaii/New Jersey/New York/Washington/DC/Illinois/Minnesota pay range. $131,600—$282,000 USD