Staff Backend Engineer, AST: Composition Analysis

· Remote

Location

Remote

Type

Full Time

Job Description

GitLabJobs
Staff Backend Engineer AST: Composition Analysis

Staff Backend Engineer AST: Composition Analysis

Reposted 5 Hours Ago
Easy Apply
Be an Early Applicant
10 Locations
In-Office or Remote
132K-282K Annually
Senior level
Cloud • Security • Software • Cybersecurity • Automation
The intelligent orchestration platform for DevSecOps
The Role
As a Staff Engineer you will implement security features for software supply chain management focusing on dependency and container scanning while collaborating with cross-functional teams to optimize GitLab's capabilities.
Summary Generated by Built In

GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity improve operational efficiency reduce security and compliance risk and accelerate digital transformation. More than 50 million registered users and more than 50% of the Fortune 100* trust GitLab to ship better more secure software faster.

The same principles built into our products are reflected in how our team works: we embrace AI as a core productivity multiplier with all team members expected to incorporate AI into their daily workflows to drive efficiency innovation and impact. GitLab is where careers accelerate innovation flourishes and every voice is valued. Our high-performance culture is driven by our values and continuous knowledge exchange enabling our team members to reach their full potential while collaborating with industry leaders to solve complex problems. Co-create the future with us as we build technology that transforms how the world develops software.

*Fortune 500® is a registered trademark of Fortune Media IP Limited used under license. Claim based on GitLab data. Fortune 100 refers to the top 20% ranked companies in the 2025 Fortune 500 list published in June 2025. Fortune and Fortune Media IP Limited are not affiliated with and do not endorse products or services of GitLab.

An overview of this role

As a Staff Engineer on GitLab's Software Composition Analysis team you'll drive hands-on implementation of security features that help customers understand and manage risks in their software supply chain. Your focus will be on enhancing GitLab's SCA capabilities in dependency scanning and container scanning. You'll work directly on architecture and technical implementation and help the team push forward on three core goals: Gather (introducing data points that help customers understand the urgency of issues like reachability analysis and supply chain poisoning detection) Integrate (providing other teams with innovative collection techniques for better workflows) and Optimize (solving data correlation at massive scale). You'll contribute hands-on code help solve novel technical challenges and establish patterns that improve how the distributed team works together across multiple time zones.

Examples of some future features that you may help build: 
- Dependency scanning for unmanaged C/C++ 
- Dependency Scanning for Yocto environments 
- Vulnerability detection using CPE-based matching against package metadata

What you’ll do

  • Implement complex features in dependency scanning and container scanning shipping improvements that increase scan coverage improve accuracy and drive adoption of GitLab's SCA capabilities
  • Solve novel technical problems in SCA establishing reusable patterns that reduce delivery time and improve engineering effectiveness across the team
  • Guide architectural and implementation decisions in collaboration with engineering managers product managers and peer engineers to improve scalability reliability and delivery outcomes across the team's SCA architecture
  • Contribute code design reviews and technical mentorship that raise quality standards improve maintainability and strengthen performance across the codebase
  • Collaborate across GitLab's security domain to align SCA work with related efforts in vulnerability management and adjacent product areas accelerating delivery of shared roadmap goals and improving coordination across related security efforts
  • Identify and resolve technical debt prioritizing changes that improve team velocity code health and long-term maintainability across the team's core SCA services
  • Translate product needs and customer feedback into technical solutions in partnership with product UX and security stakeholders delivering features that address high-impact customer risks and advance shared roadmap goals

What you’ll bring

  • Hands-on experience in Software Composition Analysis and the ability to contribute to complex security features in dependency scanning and container scanning
  • Deep hands-on expertise in building and evolving dependency scanning and container scanning analyzers
  • Demonstrated ability to design solutions that balance complexity performance and maintainability
  • Expertise with backend technologies particularly Go and/or Ruby on Rails with ability to pick up new technologies quickly
  • Familiarity with cloud providers like GCP CloudFlare or AWS
  • Ability to evaluate technical tradeoffs in SCA and security tooling with proven success delivering maintainable solutions that help customers manage software supply chain risk
  • Ability to work effectively in distributed async-first teams across multiple time zones
  • Experience explaining complex technical and security concepts to engineers and stakeholders

About the team

The Software Composition Analysis team is part of GitLab's Sec Engineering group and we focus on building capabilities that help customers identify and manage risks in their software supply chain. We work across areas including dependency scanning container scanning and license scanning and we work closely with product UX security and adjacent engineering teams to close important feature gaps in GitLab's platform. Our team members are distributed across regions including Europe and North America so we rely on clear documentation asynchronous communication and thoughtful coordination across time zones. This opportunity is centered on helping us deliver complex security features while balancing hands-on technical progress with strong team execution.

The base salary range for this role’s listed level is currently for residents of the United States only. This range is intended to reflect the role's base salary rate in locations throughout the US. Grade level and salary ranges are determined through interviews and a review of education experience knowledge skills abilities of the applicant equity with other team members alignment with market data and geographic location. The base salary range does not include any bonuses equity or benefits. See more information on our benefits and equity. Sales roles are also eligible for incentive pay targeted at up to 100% of the offered base salary.

United States Salary Range
$131600$282000 USD
How GitLab Supports Full-Time Employees
  • Benefits to support your health finances and well-being
  • Flexible Paid Time Off 
  • Team Member Resource Groups
  • Equity Compensation & Employee Stock Purchase Plan
  • Growth and Development Fund
  • Parental Leave 

Please note that we welcome interest from candidates with varying levels of experience; many successful candidates do not meet every single requirement. Additionally studies have shown that people from underrepresented groups are less likely to apply to a job unless they meet every single qualification. If you're excited about this role please apply and allow our recruiters to assess your application.

Country Hiring Guidelines: GitLab hires new team members in countries around the world. All of our roles are remote however some roles may carry specific location-based eligibility requirements. Our Talent Acquisition team can help answer any questions about location after starting the recruiting process.  

Privacy Policy: Please review our Recruitment Privacy Policy. Your privacy is important to us.

GitLab is proud to be an equal opportunity workplace and is an affirmative action employer. GitLab’s policies and practices relating to recruitment employment career development and advancement promotion and retirement are based solely on merit regardless of race color religion ancestry sex (including pregnancy lactation sexual orientation gender identity or gender expression) national origin age citizenship marital status mental or physical disability genetic information (including family medical history) discharge status from the military protected veteran status (which includes disabled veterans recently separated veterans active duty wartime or campaign badge veterans and Armed Forces service medal veterans) or any other basis protected by law. GitLab will not tolerate discrimination or harassment based on any of these characteristics. See also GitLab’s EEO Policy and EEO is the Law. If you have a disability or special need that requires accommodation please let us know during the recruiting process.

Skills Required

  • Hands-on experience in Software Composition Analysis
  • Deep hands-on expertise in building and evolving dependency scanning and container scanning analyzers
  • Demonstrated ability to design solutions balancing complexity performance and maintainability
  • Expertise with backend technologies particularly Go and/or Ruby on Rails
  • Familiarity with cloud providers like GCP CloudFlare or AWS
  • Ability to evaluate technical tradeoffs in SCA and security tooling
  • Ability to work effectively in distributed async-first teams
  • Experience explaining complex technical and security concepts

What the Team is Saying

Cynthia
Austin
Panos
Alana
Chloe
Reshmi

GitLab Compensation & Benefits Highlights

  • Leave & Time Off BreadthFlexible PTO has no set annual cap and encourages roughly 25 days per year and at least two consecutive weeks with clear guidance for coordination and coverage. Longer stretches are allowed within documented guardrails supporting extended rest while maintaining team continuity.
  • Parental & Family SupportPaid parental leave is set at 16 weeks globally at full pay with a toolkit and re‑entry support that ease transitions. Policies explain coordination with statutory programs where applicable to keep pay whole.
  • Healthcare StrengthU.S. offerings include multiple medical options (Cigna nationwide and Kaiser in select states) plus dental vision EAP Modern Health HSAs/FSAs with employer contributions and a travel HRA. Benefits are organized for an all‑remote workforce with clear self‑serve handbook guidance.

GitLab Insights

Am I A Good Fit?
beta
Expert contributor network
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
San Francisco CA
2500 Employees
Year Founded: 2014

What We Do

GitLab is the Intelligent Orchestration Platform where software teams and their AI agents stay in flow to amplify their capacity for innovation. Together they automate repetitive tasks to plan build secure test deploy and maintain software. With GitLab software teams spend less time on coordination overhead and more time on the next big idea.What started in 2011 as an open source project to help one team of programmers collaborate is now the intelligent orchestration platform millions of people use to deliver software faster more efficiently while strengthening security and compliance.Since the beginning we've been firm believers in remote work open source DevSecOps and iteration. We get up and log on in the morning to work alongside the GitLab community to deliver new innovations every month that help teams and their AI agents ship great code faster.

Why Work With Us

GitLab is where careers accelerate innovation flourishes and every voice is valued. Co-create the future with us as we build technology that transforms how the world develops software.

Gallery

GitLab Teams

Team
Sales & Customer Success
About our Teams

GitLab Offices

Remote Workspace

Employees work remotely.

All-remote means that each individual in the organization is empowered to work and live where they are most fulfilled; it makes it clear that every team member is equal. No one not even the executive team meets in-person on a daily basis.

Typical time on-site: None
San Francisco CA

Similar Jobs

GitLab

Lead Global Marketing Campaigns Manager

Cloud • Security • Software • Cybersecurity • Automation
Easy Apply
In-Office or Remote
2 Locations
2500 Employees
139K-235K Annually

GitLab

Manager Solutions Architects - Commercial

Cloud • Security • Software • Cybersecurity • Automation
Easy Apply
Remote
3 Locations
2500 Employees
116K-248K Annually

GitLab

Solutions Architect

Cloud • Security • Software • Cybersecurity • Automation
Easy Apply
Remote
3 Locations
2500 Employees
90K-194K Annually

GitLab

Engineering Manager

Cloud • Security • Software • Cybersecurity • Automation
Easy Apply
In-Office or Remote
4 Locations
2500 Employees
132K-282K Annually
Apply Now

Date Posted

05/21/2026

Views

0

Back to Job Listings Add To Job List Company Profile View Company Reviews
Neutral
Subjectivity Score: 0

© 2026 Job Transparency. All rights reserved.