Job Closed
This listing is no longer active.
Build software faster. The One DevOps Platform enables your entire org to collaborate around your code. We're hiring.
Engineering Manager, AST: Composition Analysis
Location
United States
Posted
77 days ago
Salary
$131.6K - $282K / year
Seniority
Lead
Job Description
Engineering Manager, AST: Composition Analysis
GitLab
This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description As an Engineering Manager for Composition Analysis, you'll lead a team building the software composition analysis capabilities that help GitLab customers find and fix vulnerabilities in their application dependencies and software supply chain. You'll guide engineers working on software composition analysis and container scanning, and you'll be responsible for setting priorities, shaping product architecture, and running agile processes so that our security offerings stay effective, reliable, and easy to use in real DevSecOps environments. You'll balance complex, security-focused roadmaps and author project plans so that customers get a robust composition analysis experience within GitLab. In your first year, you'll drive key initiatives like: - Auto-remediation of vulnerable packages - Auto-fix breaking changes with AI - Scanning unmanaged C/C++ dependencies - Static reachability analysis - Snippet detection for open source dependencies Some examples of our projects: - Building hyper-scale vulnerability detection engines for millions of GitLab users around the world - Designing auto-remediation workflows for vulnerable open source and third-party dependencies - Auto AI fixes for breaking changes that happen following dependency bumps What you’ll do: - Lead engineers across the Composition Analysis team, setting clear priorities and expectations. - Drive key security initiatives, including auto-remediation of vulnerable software packages, scanning unmanaged C/C++ dependencies, static reachability analysis, and snippet detection for open source dependencies. - Balance priorities and resources across the Composition Analysis team to ensure sustainable delivery and high-quality outcomes. - Author and maintain project plans for epics within the Composition Analysis team, aligning work, identifying dependencies, and ensuring quality delivery. - Run agile project management processes for the Composition Analysis team, including planning, estimation, and continuous improvement of delivery practices. - Provide guidance on the architecture of software composition analysis solutions, ensuring they are robust, scalable, and effective. - Collaborate closely with the Composition Analysis team to ensure consistent, high-quality approaches to application security across GitLab's platform. Qualifications - Background leading multiple technical teams or groups, ideally in application security or cloud security - Practical understanding of software composition analysis, including how to assess and manage risks in application dependencies - Familiarity with containerization technologies, package managers, and dependency management systems - Experience working with or around open source security tooling (for example, Syft, Grype, Trivy, or similar tools) - Ability to plan and run agile project management processes for the Composition Analysis team, including coordinating priorities and dependencies. - Skill in guiding product and architecture decisions for security scanning tools, balancing technical constraints with customer needs - Openness to candidates with transferable experience in security engineering, DevSecOps, or vulnerability management who are motivated to grow in application security leadership About the team The Composition Analysis team at GitLab sits within our security product area and focuses on building and improving our software composition analysis capabilities across the DevSecOps platform. We own core features such as software composition analysis, container scanning, and related remediation workflows. You'll lead our distributed group of security-focused engineers as we collaborate asynchronously across time zones using GitLab itself for planning, code review, and delivery. Right now, we're focused on advancing capabilities like: - Auto-remediation of vulnerable packages - Scanning unmanaged C/C++ dependencies - Static reachability analysis at the function level - Snippet detection for open source dependencies Benefits - Flexible Paid Time Off - Team Member Resource Groups - Equity Compensation & Employee Stock Purchase Plan - Growth and Development Fund - Parental leave - Home office support
Job Requirements
- Background leading multiple technical teams or groups, ideally in application security or cloud security
- Practical understanding of software composition analysis, including how to assess and manage risks in application dependencies
- Familiarity with containerization technologies, package managers, and dependency management systems
- Experience working with or around open source security tooling (for example, Syft, Grype, Trivy, or similar tools)
- Ability to plan and run agile project management processes for the Composition Analysis team, including coordinating priorities and dependencies.
- Skill in guiding product and architecture decisions for security scanning tools, balancing technical constraints with customer needs
- Openness to candidates with transferable experience in security engineering, DevSecOps, or vulnerability management who are motivated to grow in application security leadership
- About the team
- The Composition Analysis team at GitLab sits within our security product area and focuses on building and improving our software composition analysis capabilities across the DevSecOps platform. We own core features such as software composition analysis, container scanning, and related remediation workflows. You'll lead our distributed group of security-focused engineers as we collaborate asynchronously across time zones using GitLab itself for planning, code review, and delivery. Right now, we're focused on advancing capabilities like:
- Auto-remediation of vulnerable packages
- Scanning unmanaged C/C++ dependencies
- Static reachability analysis at the function level
- Snippet detection for open source dependencies
Benefits
- Flexible Paid Time Off
- Team Member Resource Groups
- Equity Compensation & Employee Stock Purchase Plan
- Growth and Development Fund
- Parental leave
- Home office support
Related Guides
Related Categories
Related Job Pages
More Engineering Manager Jobs
Engineering Manager
InspirenInspiren offers the most complete and connected ecosystem in senior living. Founded by Michael Wang, a former Green Beret turned cardiothoracic nurse, Inspiren proves that compassionate care and technology can coexist - bringing peace of mind to residents, families, and staff. Our integrated solutions seamlessly fit into existing workflows, capturing everything happening within a community. Backed by nurse specialists and powerful analytics, we provide the data operators need to make informed clinical and operational decisions - driving efficiency, profitability, and better care outcomes.
This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description We are looking for an Engineering Manager to lead our Intelligence & Integrations team. This team sits at the intersection of our hardware ecosystem and our customers' operational reality, responsible for transforming the raw behavioral data captured by AUGi into actionable insights that drive resident safety and operational efficiency. - You will lead the team responsible for Inspiren’s key platform capabilities, including our Intelligence product with an analytics engine powered by our Databricks lakehouse, as well as our critical EHR integrations. - You will ensure our Intelligence and Integrations systems scale reliably to meet the needs of communities nationwide. - This role is highly cross-functional, collaborating closely with Product, Data Science, and Implementation teams. We can count on you to… - Own: - Team health and delivery: Manage, mentor, and hire for a high-performing team of engineers, responsible for their professional growth and maintaining a culture of technical excellence and psychological safety. - Roadmap: Partner with your Product Manager to own your team’s roadmap and deliver high-value functionality. - Teach: - Operational Excellence: Instill best practices for monitoring, alerting, and incident response, particularly for serverless data pipelines and third-party integrations. - Cross-Functional Translation: Help engineers understand the "why" behind the product and assist non-technical stakeholders in understanding data synchronization and analytics complexity. - Improve: - Integration Velocity: Work with your team to streamline how we build and maintain integrations with external systems, reducing onboarding friction for new customer communities. Qualifications - 3+ years of Engineering Management experience, managing full-stack or backend-focused teams in a product-led environment. - 6+ years of hands-on software engineering experience, with a strong background in data-intensive applications or distributed systems. - Deep understanding of integrations and experience managing complex sets of integrations. - User-Centric Leadership: Care deeply about the end-user experience. - Empathy and Values: Align with Inspiren’s "humanity first" approach. - AI Adoption: Actively use AI coding tools as a core part of your work. - Programming and Technical Skills: Familiarity with AWS ecosystems, TypeScript, Node.js, PostgreSQL, NoSQL patterns, and sufficient knowledge of React. Requirements - Experience with HL7, FHIR, or integrating with major EHR platforms. - Experience managing data pipelines that ingest high-frequency telemetry from hardware/IoT devices. Benefits - The annual salary for this role is $200,000-$230,000 + equity + benefits (including medical, dental, and vision). - Flexible PTO. - Location: Remote, US or Canada. NYC preferred.
Area Automation Manager
Waste Management, Inc.WM is North America's leading provider of comprehensive environmental solutions. Previously known as Waste Management and based in Houston, Texas, WM is driven by commitments to put people first and achieve success with integrity. The company, through its subsidiaries, provides collection, recycling, and disposal services to millions of residential, commercial, industrial, medical, and municipal customers throughout the U.S. and Canada.
This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description The Area Automation Manager plays a critical role in overseeing and managing the automation systems and technologies within the Missouri and the surrounding states. This role typically involves a combination of technical expertise, management skills, and strategic planning to ensure the effective operation and optimization of automated processes. This role will work with WM's Automation Group to help lead automation activities for all lines of businesses within the company and ensure the automation/controls engineering activities meet the company's objectives. - Responsible for managing automation systems and assisting with control system troubleshooting, process modifications, system designs, specifications, and commissioning. - Act as the local liaison between the Automation Group and site contacts, being the first point of contact for any automation issues that may arise. - Develop and improve new and existing equipment used in landfills, wastewater treatment plants, bio-gas extraction systems, renewable energy plants, recycling technology, telematics, fleet, and organics processing. - Work in a fast-paced environment and resolve issues independently. - Knowledge of industrial control wiring, industrial equipment, PLC/HMI programming, and process design is necessary. Qualifications - High School Diploma or GED (accredited) and 4 years of relevant work experience with industrial electrical controls, automation, control systems, instrumentation, and process design required. - 4 years relevant work experience with industrial electrical controls, automation, control systems, instrumentation, and process design in addition to education requirements. - Bachelor's Degree (accredited) in relevant discipline or in lieu of degree preferred. - ISA Certified Control Systems Technician (CCST) preferred. - Certified Automation Professional (CAP) preferred. - Candidate must live near a major airport in Oregon, Washington, or Idaho. Requirements - Provide Subject Matter Expert (SME) level day-to-day support of all automated and electro-mechanical process control systems used in various operations. - Lead and coordinate efforts to secure all automation technologies used in waste processing and logistics. - Oversee lifecycle management of all operational technology (OT) assets, including SCADA and automation equipment. - Implement a roadmap for OT maturity, including technology assessments, gap analysis, and improvement plans. - Drive the adoption of emerging OT technologies to enhance operational efficiency and reliability. - Collaborate with IT and OT teams to ensure alignment and effective integration of systems. - Develop and execute a comprehensive automation strategy aligned with business objectives. - Provide automation site support interface with operations personnel, compliance, information systems, engineering, and maintenance. - Exhibit strong customer communication skills and have technical knowledge of automated and electromechanical process control systems and equipment. - Train local operators and managers on the proper operation of their respective equipment and SCADA system(s). - Oversee the selection, onboarding, and management of external contractors supporting automation initiatives. - Monitor contractor performance, provide feedback, and address any performance issues. - Conduct cost-benefit analysis and ROI assessments for automation projects. - Travel up to 40% is required. Benefits - Competitive total compensation package including Medical, Dental, Vision, Life Insurance, and Short Term Disability. - Stock Purchase Plan and Company match on 401K. - Paid Vacation, Holidays, and Personal Days. - Benefits may vary by site.
Engineering Manager, Native Apps
ezCater, IncezCater is the leading food for work technology company in the US, connecting anyone who needs food for their workplace to over 100,000 restaurants nationwide. For workplaces, ezCater provides flexible and scalable solutions for everything from recurring employee meals to one-off meetings, all backed by 24/7 customer service with real humans. ezCater also enables companies to manage their food spend in a single, customizable platform. For restaurant partners, ezCater helps them grow their business by bringing them more orders and new high-value customers. We're backed by top investors including Insight, Iconiq, Lightspeed, GIC, SoftBank, and Quadrille.
This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description As an Engineering Manager of ezCater’s Native Apps team, you will focus on leading the team that is building ways for partners and customers to experience ezCater’s platform through ezCater’s suite of native applications. This will include building new capabilities for our catering partner tools, and continuous iterations and support of the ezCater Marketplace for both Android and iOS. Your immediate scope of responsibility includes overseeing our Native team and working with Product and Marketing on creating robust native application strategies that will scale ezCater’s growth. You’ll report to the Senior Engineering Manager within the ezCater Engineering organization. What You'll Do: - Build, lead, and mentor exceptional teams of software engineers, leading conversations, and cultivating execution and decision-making; all while delighting our customers and propelling our team of engineers to execute on projects. - Drive the execution of our vision by translating business requirements into technical solutions, ensuring our products are robust and adhere to engineering standards while meeting our goals. - Leverage your technical expertise and communication skills to collaborate with product managers and other engineering teams in the organization to influence our systems and roadmaps. - Operate with scale and speed determining the ideal development lifecycle and approach for new and existing solutions. - Build a healthy, supportive and inclusive work environment across the entire team, while having an unrelenting focus on maturing the practice of giving and receiving feedback. - Educate the team on the meaning of each goal and objective, and ensure each can be measured. When appropriate, re-negotiate success metrics with stakeholders as information emerges to ensure teams are set up for success. - Have fun building meaningful software with awesome people. Qualifications - A passion for building and growing high-performing teams, prior management experience, and a desire to be an impactful leader. - Proficiency in documenting processes and monitoring the performance metrics for our applications and systems. - Extensive experience building and launching native mobile applications for both Android and iOS. - Working knowledge of the mobile development ecosystem and proficiency in languages like Kotlin/Java (Android) and Swift/Objective-C (iOS). - Experience with cross-platform frameworks (e.g., React Native, Flutter) is a plus. - Deep understanding of mobile architecture, performance optimization, and best practices. - Knowledge of the AI ecosystem and experience introducing AI tools into enterprise-facing products in a thoughtful way is a huge plus. - Flexible growth mindset, you’re willing to do what it takes to adapt your team and power them for success. - Goal orientation and a record of success leading leaders and engineers. - A desire to collaborate with strong engineers and engineering leaders to continually improve a mature engineering team. - A sharp mind, a soft heart, and a large funny bone. Requirements - The national total target cash compensation range for this position, including base salary and bonus target, is $195,000–$255,000 annually. - Final offer amounts are determined by multiple factors, including prior experience, expertise and region & may vary from the amount above. - This range does not represent additional compensation benefits (such as equity, 401K or medical, dental or vision insurance). Benefits - Market competitive salary. - Stock options that you’ll help make worth a lot. - 12 paid holidays. - Flexible PTO. - 401K with ezCater match. - Health/dental/FSA. - Long-term disability insurance. - Mental health and family planning resources. - Remote-hybrid work from our awesome Boston office OR your home OR a mixture of both home and office. - A tremendous amount of responsibility and autonomy. - Wicked awesome co-workers. - Relish (and many more goodies) when you’re in our office. - Knowing that you helped transform the food for work space. Company Description ezCater is the leading food for work technology company in the US, connecting anyone who needs food for their workplace to over 100,000 restaurants nationwide. For workplaces, ezCater provides flexible and scalable solutions for everything from recurring employee meals to one-off meetings, all backed by 24/7 customer service with real humans. ezCater also enables companies to manage their food spend in a single, customizable platform. For restaurant partners, ezCater helps them grow their business by bringing them more orders and new high-value customers. We're backed by top investors including Insight, Iconiq, Lightspeed, GIC, SoftBank, and Quadrille.
Senior Engineering Manager, Platform Engineering
ezCater, IncezCater is the leading food for work technology company in the US, connecting anyone who needs food for their workplace to over 100,000 restaurants nationwide. For workplaces, ezCater provides flexible and scalable solutions for everything from recurring employee meals to one-off meetings, all backed by 24/7 customer service with real humans. ezCater also enables companies to manage their food spend in a single, customizable platform. For restaurant partners, ezCater helps them grow their business by bringing them more orders and new high-value customers. We're backed by top investors including Insight, Iconiq, Lightspeed, GIC, SoftBank, and Quadrille.
This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description As Senior Engineering Manager, Platform Engineering, you will lead the teams responsible for the foundation that every engineering team builds on: infrastructure, developer experience, shared libraries, CI/CD, observability, and governance. You will own delivery across developer experience, core platform tooling, and platform infrastructure -- ensuring that domain teams building on the platform have an opinionated, supported path that lets them focus on their domain instead of infrastructure decisions. This is a hands-on engineering management role. You are close to the work -- reviewing technical designs, pairing with engineers on hard problems, and making informed tradeoff calls across infrastructure, tooling, and developer experience. What You’ll Own: - Delivery across platform engineering: developer experience, core platform tooling (shared libraries, event streaming clients, auth middleware), and platform infrastructure (compute clusters, networking, infrastructure-as-code, observability) - The opinionated path for building and operating services: language, frameworks, CI/CD, deployment, observability, and governance -- the defaults that come with support out of the box - Milestone delivery for the platform foundation on a timeline that unblocks domain teams building search, identity, payments, and other capabilities - Day-to-day engineering management: hiring, developing, and retaining strong engineers across the platform teams - Cross-team coordination: when domain teams need something from the platform, you own prioritization and delivery What Your Teams Will Build: - A fresh compute cluster for new platform services, with namespace isolation, modern autoscaling, and clean networking - CI/CD pipelines (build, test, contract validation, GitOps deployment) that are the single supported path for all new services - A service template that gives domain teams a working, observable, deployable service in minutes - Shared libraries and building blocks: event streaming clients, HTTP clients, auth middleware, instrumentation - Infrastructure modules: reusable, versioned modules for databases, event streaming topics, caching, secrets -- provisioned via infrastructure-as-code - An observability stack (APM, logging, tracing, alerting) that ships by default with every service. What Success Looks Like (12-18 Months): - Domain teams can scaffold, build, deploy, and observe a new service using the platform path without making infrastructure decisions or filing tickets - The platform foundation is delivered on the milestone timeline, unblocking the first wave of domain services - Every new service is deployed through the same CI/CD pipeline with consistent observability and operational standards - Infrastructure provisioning is self-service via versioned modules -- no manual work or ad-hoc configuration - The platform teams are well-staffed, well-organized, and operating with clear ownership - Engineering teams view the platform path as the easiest way to ship -- not a constraint to work around. How You'll Lead: - Stay close to the technical work: review designs, participate in architecture discussions, and maintain the judgment to evaluate proposals and recognize when something needs a different approach - Manage and develop engineers directly, with the potential to grow into managing team leads as the organization scales - Prioritize ruthlessly: the platform backlog will always be larger than the team. Sequence work so that domain teams are never blocked on capabilities they need. - Drive execution with clear milestones, deliverables, and accountability -- without micromanaging how engineers do their work - Partner with domain engineering leaders to understand their needs and ensure the platform meets them - Build a culture of clear ownership, operational excellence, and developer empathy What You Have: - 8+ years of professional software engineering experience, with at least 2 years in engineering management or technical team leadership - A strong technical foundation: you have built and operated distributed systems, cloud-native infrastructure, or platform tooling - Experience with cloud-native infrastructure (Kubernetes/EKS, infrastructure-as-code, container orchestration, service networking) - Experience establishing engineering standards: CI/CD pipelines, service templates, observability defaults, deployment patterns - Demonstrated ability to hire, develop, and retain strong engineers - Strong communication skills: you can translate between infrastructure complexity and team priorities, and represent the platform in cross-team discussions - A pragmatic, service-oriented mindset: you understand that the platform team's success is measured by how effectively other teams can build on it Role Scope & Focus: - This is an engineering management role with strong technical expectations. You manage engineers directly and are accountable for the technical quality and delivery of the platform. - You report to the VP of Engineering and partner closely on platform strategy, milestone planning, and team structure - You partner with domain engineering leaders (search, identity, commerce, menus) to ensure the platform meets their needs without becoming a bottleneck - You do not own application-level domain services. You own the foundation they build on. - As the platform organization grows, this role has a clear path to Director scope - The platform is the foundation for a multi-year re-architecture of ezCater's technology stack. Compensation The national total target cash compensation range for this position, including base salary and bonus target, is $218,000 - $280,000 annually. Please note: Final offer amounts are determined by multiple factors, including prior experience, expertise and region & may vary from the amount above. What You’ll Get from Us: - Market competitive salary - Stock options - 12 paid holidays - Flexible PTO - 401K with ezCater match - Health/dental/FSA - Long-term disability insurance - Mental health and family planning resources - Remote-hybrid work from our awesome Boston office OR your home OR a mixture of both home and office - A tremendous amount of responsibility and autonomy - Wicked awesome co-workers Equal Opportunity Employer ezCater is an equal opportunity employer. We embrace humans of every background, appearance, race, religion, color, national origin, gender, gender identity, sexual orientation, age, marital status, veteran status, and disability status. At the same time, we do not employ jerks, even brilliant ones.

