Overview
In this role you lead the Security Factory, shaping the engineering vision for GitLab’s customer-facing security capabilities within an AI-powered DevSecOps platform. You guide nine teams to deliver proprietary scanners, AI-driven detection, and agentic remediation while strengthening security foundations. You’ll partner with product to align roadmaps in regulated environments and drive scalable, high-quality delivery. The position offers strategic influence on security tooling and AI research that impacts how customers secure the software supply chain.
Pay / Benefits
- Flexible Paid Time Off
- Team Member Resource Groups
- Equity Compensation & Employee Stock Purchase Plan
- Growth and Development Fund
- Parental Leave
Responsibilities
- Set the engineering vision and multi-quarter roadmap across teams including scanners, AI-driven security workflows, research, vulnerability management, and security foundations
- Lead a distributed engineering organization of managers and ICs with focus on performance, engagement, and career development
- Drive architectural decisions for AI and ML detection engines, agentic remediation flows, and scalable scanning infrastructure
- Partner with product management to define priorities, shape requirements, and deliver security capabilities for customers in regulated environments
- Own the engineering delivery of proprietary application security scanners, agentic remediation workflows, and AI Security Research efforts
- Represent the Security Factory stage in cross-functional planning, executive reviews, security disclosures, and customer conversations
- Establish engineering standards for delivery, observability, incident response, scanner quality, and code quality
- Contribute to GitLab’s transparent, async-first way of working through issues, merge requests, and the GitLab handbook
Key requirements
- Experience leading engineering organizations with multiple teams and managers in a distributed environment
- Strong understanding of application security fundamentals (SAST, SCA, secret detection, vulnerability management, software supply chain security)
- Experience shipping detection/scanning systems in SaaS/DevSecOps with trade-offs across precision, recall, latency, scale
- Direct experience shipping customer-facing AI/ML product features tied to detection or remediation quality outcomes
- Ability to partner with product management on roadmap planning in a product-led context
- Strong written communication and comfort with remote, async work
- Collaborative leadership style aligned with GitLab values
- Familiarity with agentic AI, AI orchestration, threat intelligence research, or open source security tooling (useful)
- Strong communication
- Collaborative leadership
- Ownership and accountability
- AI/ML detection engines
- Agentic remediation flows
- Security foundations
…
