About the job
At GitLab, we are not just an open-core software company; we are pioneers in developing the most advanced AI-powered DevSecOps Platform that serves over 100,000 organizations worldwide. Our mission is to empower individuals to contribute to and co-create the software that drives our modern world. By transforming consumers into contributors, we significantly accelerate human progress. Our platform bridges the gaps between teams and organizations, revolutionizing the possibilities in software development. Our innovative products, including Duo Enterprise and Duo Agent Platform, provide AI advantages at every phase of the Software Development Life Cycle (SDLC).
We embrace AI as an essential productivity enhancer, encouraging all team members to integrate AI into their daily tasks to boost efficiency, foster innovation, and make a substantial impact. At GitLab, you will find a culture where careers thrive, innovation is celebrated, and every voice is heard. Our commitment to high performance is aligned with our core values and continuous knowledge sharing, allowing our team to reach their full potential while collaborating with industry experts to tackle complex challenges. Join us in co-creating the future as we develop technology that reshapes how software is created around the globe.
Role Overview
As the Principal Engineer for Software Supply Chain Security, you will be at the forefront of defining and executing the technical strategy that secures the construction and delivery of software on GitLab’s DevSecOps platform. You will provide architectural direction across multiple engineering teams, collaborating closely with infrastructure and CI/CD teams to fortify our pipelines, infrastructure, and access layers. Your contributions will play a critical role in shaping GitLab’s enterprise security framework within the rapidly evolving software supply chain security landscape. You will prioritize SLSA Level 3 compliance, secrets management, CI/CD security enhancements, and the foundational elements of GitLab’s global zero trust architecture. Additionally, you will mentor Staff Engineers and individual contributors, guiding essential technical decisions while acting as a key spokesperson for GitLab’s secure, mission-critical SaaS that supports millions of pipelines.
Examples of our ongoing projects include:
- Achieving SLSA Level 3 compliance and provenance attestation across GitLab's offerings...

