Director of Engineering, Security Factory

Company: GitLab
Apply for the Director of Engineering, Security Factory
Location:
Job Description:

Overview

In this role you lead the Security Factory, shaping the engineering vision for GitLab’s customer-facing security capabilities within an AI-powered DevSecOps platform. You guide nine teams to deliver proprietary scanners, AI-driven detection, and agentic remediation while strengthening security foundations. You’ll partner with product to align roadmaps in regulated environments and drive scalable, high-quality delivery. The position offers strategic influence on security tooling and AI research that impacts how customers secure the software supply chain.

Pay / Benefits

  • Flexible Paid Time Off
  • Team Member Resource Groups
  • Equity Compensation & Employee Stock Purchase Plan
  • Growth and Development Fund
  • Parental Leave

Responsibilities

  • Set the engineering vision and multi-quarter roadmap across teams including scanners, AI-driven security workflows, research, vulnerability management, and security foundations
  • Lead a distributed engineering organization of managers and ICs with focus on performance, engagement, and career development
  • Drive architectural decisions for AI and ML detection engines, agentic remediation flows, and scalable scanning infrastructure
  • Partner with product management to define priorities, shape requirements, and deliver security capabilities for customers in regulated environments
  • Own the engineering delivery of proprietary application security scanners, agentic remediation workflows, and AI Security Research efforts
  • Represent the Security Factory stage in cross-functional planning, executive reviews, security disclosures, and customer conversations
  • Establish engineering standards for delivery, observability, incident response, scanner quality, and code quality
  • Contribute to GitLab’s transparent, async-first way of working through issues, merge requests, and the GitLab handbook

Key requirements

  • Experience leading engineering organizations with multiple teams and managers in a distributed environment
  • Strong understanding of application security fundamentals (SAST, SCA, secret detection, vulnerability management, software supply chain security)
  • Experience shipping detection/scanning systems in SaaS/DevSecOps with trade-offs across precision, recall, latency, scale
  • Direct experience shipping customer-facing AI/ML product features tied to detection or remediation quality outcomes
  • Ability to partner with product management on roadmap planning in a product-led context
  • Strong written communication and comfort with remote, async work
  • Collaborative leadership style aligned with GitLab values
  • Familiarity with agentic AI, AI orchestration, threat intelligence research, or open source security tooling (useful)
  • Strong communication
  • Collaborative leadership
  • Ownership and accountability
  • AI/ML detection engines
  • Agentic remediation flows
  • Security foundations

…

Posted: October 1st, 2026