Software Engineering Manager, Application Security Testing: Composition Analysis & Dynamic Analysis
GitLab
San Francisco, United States of America
2 days ago
Role details
Contract type
Internship / Graduate position Employment type
Full-time (> 32 hours) Working hours
Regular working hours Languages
English Experience level
Intermediate Compensation
€ 11KJob location
Remote
Amsterdam, Netherlands
Tech stack
API
Agile Methodologies
Burp Suite
C++
Dynamic Program Analysis
Fuzz Testing
Open Source Technology
Web Application Security
Software Engineering
Tripwire
Software Vulnerability Management
Web Applications
Enterprise Software Applications
Software Security
Devsecops
Dynamic Application Security Testing
Job description
The Composition Analysis group is responsible for:
- Software Composition Analysis
- Container Scanning
Dynamic Analysis
The Dynamic Analysis group is responsible for:
- API Security
- Dynamic Analysis Security Testing (DAST)
- Fuzz Testing
What You'll Do
- Manage engineers across both the Composition Analysis and Dynamic Analysis groups
- Drive key initiatives including:
- Auto-remediation of vulnerable software packages
- Scanning of unmanaged dependencies in C/C++
- Static reachability analysis with function-level granularity
- Snippet detection for open source dependencies
- Improve the DAST crawler for efficiency, stability, and consistent web application traversal
- Balance priorities across multiple security-focused engineering teams
- Author project plans for epics across both groups, ensuring alignment and avoiding duplication of effort
- Run agile project management processes for multiple teams
- Provide guidance on security product architecture
- Coordinate between Composition Analysis and Dynamic Analysis teams to ensure consistent and complementary approaches to application security
Requirements
- In-depth understanding of application security concepts, particularly in software composition analysis techniques to evaluate the security risks associated with application dependencies and dynamic analysis security testing (DAST) tools.
- Understanding of the challenges in developing and maintaining security scanning tools
- Experience managing multiple technical teams simultaneously
- Familiarity with containerization technologies and dependency management systems
- Knowledge of web application security testing techniques and tools
- Experience with open source security tooling (such as OWASP ZAP, Trivy, or similar)
- Experience in DevSecOps practices and implementation
- Experience in vulnerability management and remediation
Benefits & conditions
- All remote, asynchronous work environment
- Flexible Paid Time Off
- Team Member Resource Groups
- Equity Compensation & Employee Stock Purchase Plan
- Growth and Development Fund
- Parental leave
- Home office support
About the company
GitLab is the most comprehensive AI-powered DevSecOps platform for software innovation. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation.
More than 50 million registered users and more than 50% of the Fortune 100 trust GitLab to ship better, more secure software faster.