Software Engineering Manager, Application Security Testing: Composition Analysis & Dynamic Analysis

GitLab
San Francisco, United States of America
2 days ago

Role details

Contract type
Internship / Graduate position
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Intermediate
Compensation
€ 11K

Job location

Remote
Amsterdam, Netherlands

Tech stack

API
Agile Methodologies
Burp Suite
C++
Dynamic Program Analysis
Fuzz Testing
Open Source Technology
Web Application Security
Software Engineering
Tripwire
Software Vulnerability Management
Web Applications
Enterprise Software Applications
Software Security
Devsecops
Dynamic Application Security Testing

Job description

The Composition Analysis group is responsible for:

  • Software Composition Analysis
  • Container Scanning

Dynamic Analysis

The Dynamic Analysis group is responsible for:

  • API Security
  • Dynamic Analysis Security Testing (DAST)
  • Fuzz Testing

What You'll Do

  • Manage engineers across both the Composition Analysis and Dynamic Analysis groups
  • Drive key initiatives including:
  • Auto-remediation of vulnerable software packages
  • Scanning of unmanaged dependencies in C/C++
  • Static reachability analysis with function-level granularity
  • Snippet detection for open source dependencies
  • Improve the DAST crawler for efficiency, stability, and consistent web application traversal
  • Balance priorities across multiple security-focused engineering teams
  • Author project plans for epics across both groups, ensuring alignment and avoiding duplication of effort
  • Run agile project management processes for multiple teams
  • Provide guidance on security product architecture
  • Coordinate between Composition Analysis and Dynamic Analysis teams to ensure consistent and complementary approaches to application security

Requirements

  • In-depth understanding of application security concepts, particularly in software composition analysis techniques to evaluate the security risks associated with application dependencies and dynamic analysis security testing (DAST) tools.
  • Understanding of the challenges in developing and maintaining security scanning tools
  • Experience managing multiple technical teams simultaneously
  • Familiarity with containerization technologies and dependency management systems
  • Knowledge of web application security testing techniques and tools
  • Experience with open source security tooling (such as OWASP ZAP, Trivy, or similar)
  • Experience in DevSecOps practices and implementation
  • Experience in vulnerability management and remediation

Benefits & conditions

  • All remote, asynchronous work environment
  • Flexible Paid Time Off
  • Team Member Resource Groups
  • Equity Compensation & Employee Stock Purchase Plan
  • Growth and Development Fund
  • Parental leave
  • Home office support

About the company

GitLab is the most comprehensive AI-powered DevSecOps platform for software innovation. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. 

More than 50 million registered users and more than 50% of the Fortune 100 trust GitLab to ship better, more secure software faster.

Apply for this position