Remote
84 days ago
Engineering Manager, Application Security Testing: Composition & Dynamic Analysis

The Engineering Manager for Composition Analysis and Dynamic Analysis specializes in leading teams focused on application security scanning technologies. This role oversees multiple security-focused engineering groups and is responsible for balancing priorities across these specialized teams.

This role is an extension of the Engineering Manager position.

Groups Overview

Composition Analysis -The Composition Analysis group is responsible for: Software Composition Analysis Container Scanning Dynamic Analysis - The Dynamic Analysis group is responsible for: API Security Dynamic Analysis Security Testing (DAST) Fuzz Testing

What you’ll do

Manage engineers across both the Composition Analysis and Dynamic Analysis groups Drive key initiatives including: Auto-remediation of vulnerable software packages Scanning of unmanaged dependencies in C/C++ Static reachability analysis with function-level granularity Snippet detection for open source dependencies Improve the DAST crawler for efficiency, stability, and consistent web application traversal Balance priorities across multiple security-focused engineering teams Author project plans for epics across both groups, ensuring alignment and avoiding duplication of effort Run agile project management processes for multiple teams Provide guidance on security product architecture Coordinate between Composition Analysis and Dynamic Analysis teams to ensure consistent and complementary approaches to application security

What you’ll bring

In-depth understanding of application security concepts, particularly in software composition analysis techniques to evaluate the security risks associated with application dependencies and dynamic analysis security testing (DAST) tools. Understanding of the challenges in developing and maintaining security scanning tools Experience managing multiple technical teams simultaneously Familiarity with containerization technologies and dependency management systems Knowledge of web application security testing techniques and tools Experience with open source security tooling (such as OWASP ZAP, Trivy, or similar) Experience in DevSecOps practices and implementation Experience in vulnerability management and remediation How GitLab will support you Benefits to support your health, finances, and well-being All remote, asynchronous work environment Flexible Paid Time Off  Team Member Resource Groups Equity Compensation & Employee Stock Purchase Plan Growth and Development Fund Parental leave  Home office support

Please note that we welcome interest from candidates with varying levels of experience; many successful candidates do not meet every single requirement. Additionally, studies have shown that people from underrepresented groups are less likely to apply to a job unless they meet every single qualification. If you're excited about this role, please apply and allow our recruiters to assess your application.

Confirmar seu email: Enviar Email
Todos os Empregos de Gitlab