<?xml version="1.0" encoding="UTF-8"?>
<source>
  <jobs>
    <job>
      <externalid>a3a1df2f-184</externalid>
      <Title>Principal Engineer, Software Supply Chain Security</Title>
      <Description><![CDATA[<p>As the Principal Engineer, Software Supply Chain Security, you&#39;ll own the technical strategy that secures how software is built and delivered on GitLab&#39;s DevSecOps platform. You&#39;ll provide architectural leadership across multiple engineering teams.</p>
<p>Your work will shape GitLab&#39;s enterprise security posture in the rapidly growing software supply chain security market. You&#39;ll focus on SLSA Level 3 compliance, secrets management, CI/CD security hardening, and the foundations of GitLab&#39;s global zero trust architecture.</p>
<p>Some examples of our projects:</p>
<ul>
<li>SLSA Level 3 compliance and provenance attestation across GitLab&#39;s CI/CD platform</li>
<li>Integrated secrets management and runner security for container-isolated, secure pipelines</li>
</ul>
<p>You&#39;ll lead the end-to-end software supply chain security architecture for GitLab&#39;s CI/CD platform, including SLSA Level 3 implementation and CI infrastructure hardening. You&#39;ll drive cross-team technical strategy and decisions across our Software Supply Chain Security (SSCS) stage teams, aligning engineering work to SSCS strategic plans.</p>
<p>You&#39;ll collaborate with infrastructure and CI/CD teams to design and land long-term initiatives for secure, scalable runner architecture, container isolation, and pipeline security at scale. You&#39;ll propose and validate technical implementations that support architectural changes to improve CI/CD scaling and performance on critical paths.</p>
<p>You&#39;ll teach, mentor, and coach Staff Engineers and individual contributors, raising the bar on supply chain threat modeling, secrets management, artifact signing, and SBOM lifecycle practices.</p>
<p>You&#39;ll partner with Engineering Managers and senior leadership to define roadmaps, break down complex initiatives, and enable Staff Engineers to lead sub-department-wide efforts.</p>
<p>You&#39;ll engage with customers and external stakeholders as a technical consultant and spokesperson for GitLab&#39;s software supply chain security capabilities and roadmap.</p>
<p>You&#39;ll collaborate with product, security, and compliance stakeholders to ensure features meet enterprise security, governance, and regulatory expectations in the software supply chain security market.</p>
<p>Key responsibilities include:</p>
<ul>
<li>Providing architectural leadership across multiple engineering teams</li>
<li>Shaping GitLab&#39;s enterprise security posture in the rapidly growing software supply chain security market</li>
<li>Focusing on SLSA Level 3 compliance, secrets management, CI/CD security hardening, and the foundations of GitLab&#39;s global zero trust architecture</li>
</ul>
<p>Key requirements include:</p>
<ul>
<li>Deep expertise in software supply chain security, including threat modeling for supply chain attack vectors, SLSA implementation and attestation systems, and SBOM generation and lifecycle management</li>
<li>Strong knowledge of artifact signing and verification using the Sigstore ecosystem, including Cosign, Fulcio, Rekor, and in-toto attestations</li>
<li>Experience designing and hardening CI/CD security, such as runner isolation, pipeline security controls, and secrets management in large-scale environments</li>
</ul>
<p>Preferred qualifications include:</p>
<ul>
<li>Background in distributed systems and infrastructure, including building resilient CI/CD platforms that process high pipeline volumes and optimizing performance for critical paths</li>
<li>Practical experience with container security and Kubernetes security, including admission controllers, policy controllers, workload isolation, and registry hardening</li>
<li>Proficiency in Go or Rust in a production environment, combined with expert-level understanding of CI/CD workflows and DevSecOps best practices</li>
<li>Experience operating as a Principal or Staff Engineer across multiple development teams, providing architectural leadership and partnering with Engineering Managers and senior leaders</li>
<li>Demonstrated capacity to clearly communicate complex problems and solutions</li>
</ul>
<p>Our Software Supply Chain Security stage engineering teams are responsible for authentication and access within GitLab. We also build features that help customers manage vulnerabilities, dependencies, security policies, and compliance frameworks across their organizations.</p>
<p>The base salary range for this role&#39;s listed level is currently for residents of the United States only. This range is intended to reflect the role&#39;s base salary rate in locations throughout the US. Grade level and salary ranges are determined through interviews and a review of education, experience, knowledge, skills, abilities of the applicant, equity with other team members, alignment with market data, and geographic location. The base salary range does not include any bonuses, equity, or benefits.</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>staff</Experiencelevel>
      <Workarrangement>remote</Workarrangement>
      <Salaryrange>$157,900-$338,400 USD</Salaryrange>
      <Skills>software supply chain security, threat modeling, SLSA implementation, attestation systems, SBOM generation, lifecycle management, artifact signing, verification, Sigstore ecosystem, Cosign, Fulcio, Rekor, in-toto attestations, CI/CD security, runner isolation, pipeline security controls, secrets management, distributed systems, infrastructure, container security, Kubernetes security, admission controllers, policy controllers, workload isolation, registry hardening, Go, Rust, CI/CD workflows, DevSecOps best practices, background in distributed systems and infrastructure, practical experience with container security and Kubernetes security, proficiency in Go or Rust in a production environment, expert-level understanding of CI/CD workflows and DevSecOps best practices, experience operating as a Principal or Staff Engineer across multiple development teams</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>GitLab</Employername>
      <Employerlogo>https://logos.yubhub.co/about.gitlab.com.png</Employerlogo>
      <Employerdescription>GitLab is a software development platform that provides tools for version control, project management, and collaboration. It has over 50 million registered users and is trusted by more than 50% of the Fortune 100.</Employerdescription>
      <Employerwebsite>https://about.gitlab.com/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/gitlab/jobs/8373553002</Applyto>
      <Location>Remote, Canada; Remote, Israel; Remote, Netherlands; Remote, United Kingdom; Remote, US</Location>
      <Country></Country>
      <Postedate>2026-04-18</Postedate>
    </job>
    <job>
      <externalid>50f687cf-610</externalid>
      <Title>Cloud Security Software Engineer</Title>
      <Description><![CDATA[<p>As a Cloud Security Software Engineer at Engine by Starling, you will be a hands-on builder responsible for the security architecture of our multi-tenant core banking platform. You&#39;ll spend your days architecting and writing Go-based tooling, automating defenses, and ensuring our infrastructure across AWS and GCP is secure by design and compliant by default.</p>
<p>Your mission is to solve complex security problems through software engineering, focusing on three core pillars:</p>
<ul>
<li>Identity &amp; Network Security: Engineering high-performance IAM controls and zero-trust network architectures.</li>
<li>Unified Vulnerability Orchestration: Architecting a custom &#39;single pane of glass&#39; for security data.</li>
<li>Compliance as Code: Building the automated systems that provide real-time evidence for frameworks like SOC 2, ISO 27001 &amp; PCI.</li>
</ul>
<p>You will be a key member of our growing Security Engineering team, working at the intersection of Infrastructure, Cross-Cutting, and GRC. We operate like a specialized product team: we identify security friction and build the software to eliminate it.</p>
<p>You will lead the design and maintenance of our internal security tool suite, written primarily in Go, to automate evidence collection and real-time remediation of security alerts. You will also write and peer-review Terraform and custom providers to manage identity and core infrastructure across AWS and GCP.</p>
<p>The team supports the use of Go, Terraform, Kubernetes, and Cilium. Experience with eBPF, Sigstore/Cosign, image provenance, and SBOMs is desirable.</p>
<p>Engine by Starling offers a range of benefits, including 33 days holiday, an extra day&#39;s holiday for your birthday, annual leave increased with length of service, and a company-enhanced pension scheme.</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>mid</Experiencelevel>
      <Workarrangement>remote</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>Go, Cloud Native, Container Expertise, Identity &amp; Networking, Cloud Native Defense, Cilium, eBPF, Sigstore/Cosign, image provenance, SBOMs</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Engine by Starling</Employername>
      <Employerlogo>https://logos.yubhub.co/enginebystarling.com.png</Employerlogo>
      <Employerdescription>Engine by Starling provides security software solutions. It operates as a subsidiary of Starling.</Employerdescription>
      <Employerwebsite>https://www.enginebystarling.com/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://apply.workable.com/j/04657FA2B4</Applyto>
      <Location>London</Location>
      <Country></Country>
      <Postedate>2026-03-20</Postedate>
    </job>
    <job>
      <externalid>ee9f5559-165</externalid>
      <Title>Cloud Security Software Engineer</Title>
      <Description><![CDATA[<p>Job Description:</p>
<p>About Engineering at Engine by Starling</p>
<p>At Engine by Starling, we don&#39;t do &#39;checkbox security&#39;,we build security software. We treat security as a first-class engineering discipline, where the solution to a threat isn&#39;t a policy, but a robust, concurrent system written in Go.</p>
<p>As a Cloud Security Software Engineer, you will be a hands-on builder responsible for the security architecture of our multi-tenant core banking platform. You&#39;ll spend your days architecting and writing Go-based tooling, automating defenses, and ensuring our infrastructure across AWS and GCP is secure by design and compliant by default.</p>
<p>The Mission</p>
<p>Your mission is to solve complex security problems through software engineering, focusing on three core pillars:</p>
<ul>
<li>Identity &amp; Network Security: Engineering high-performance IAM controls and zero-trust network architectures. You will lead the way in refining edge-defense strategies and trust redirection, ensuring every request is verified and encrypted at scale.</li>
<li>Unified Vulnerability Orchestration: Architecting a custom &#39;single pane of glass&#39; for security data. You will build Go-based API integrations and microservices that bridge scanning engines, dependency trackers, and internal portals into a seamless, automated ecosystem.</li>
<li>Compliance as Code: Building the automated systems that provide real-time evidence for frameworks like SOC 2, ISO 27001 &amp; PCI. You’ll ensure we stay compliant through continuous, automated validation rather than manual overhead.</li>
</ul>
<p>The Team</p>
<p>You will be a key member of our growing Security Engineering team, working at the intersection of Infrastructure, Cross-Cutting, and GRC. We operate like a specialized product team: we identify security friction and build the software to eliminate it. You won’t work in a silo; you’ll collaborate with engineers across the business to deliver a platform that is resilient by default.</p>
<p>About You</p>
<p>We are looking for Software Engineers who are passionate about the Go ecosystem and want to apply those skills to mission-critical security challenges. Whether you come from a Security Engineering background or you are a Backend Engineer with a &#39;security-first&#39; mindset, we value your ability to write clean, maintainable, and efficient code.</p>
<p>What you’ll get to do</p>
<ul>
<li>Engineering Security Tooling: Lead the design and maintenance of our internal security tool suite, written primarily in Go, to automate evidence collection and real-time remediation of security alerts.</li>
<li>Infrastructure as Code: Write and peer-review Terraform and custom providers to manage identity and core infrastructure across AWS and GCP.</li>
<li>Supply Chain Security: Build automated systems to manage container provenance and integrate security analysis into our CI/CD pipelines (GitHub Actions/TeamCity).</li>
<li>Cloud Native Defense: Engineer Kubernetes security solutions leveraging Cilium, eBPF, and custom controllers to protect our microservices.</li>
<li>Cryptographic Engineering (PKI): Build and maintain our Go-based Certificate Authority (CA) tooling and internal PKI infrastructure.</li>
<li>Incident Response: Support the team in automated incident response, building the tools that help us investigate and mitigate threats faster.</li>
</ul>
<p>Requirements</p>
<p>What skills are essential:</p>
<ul>
<li>Go Specialist: You are proficient in Go. You understand its concurrency models, testing patterns, and how to build idiomatic, performant services.</li>
<li>The Builder Mindset: You find manual work a personal affront. If a task needs to be done twice, you’ve already started planning the automation for it.</li>
<li>Cloud Native: Practical experience with AWS or GCP, ideally managed through Terraform.</li>
<li>Container Expertise: You understand Kubernetes internals,from the runtime security to the service mesh.</li>
<li>Identity &amp; Networking: Strong understanding of cloud identity models and network protocols.</li>
</ul>
<p>What skills are desirable:</p>
<ul>
<li>Experience with Cilium or eBPF-based security monitoring.</li>
<li>Knowledge of Sigstore/Cosign, image provenance, and SBOMs.</li>
<li>Familiarity with hardware security modules (HSMs) or advanced cryptography.</li>
<li>Cloud-native security certifications (AWS/GCP).</li>
</ul>
<p>Benefits</p>
<ul>
<li>33 days holiday (including public holidays, which you can take when it works best for you)</li>
<li>An extra day’s holiday for your birthday</li>
<li>Annual leave is increased with length of service, and you can choose to buy or sell up to five extra days off</li>
<li>16 hours paid volunteering time a year</li>
<li>Salary sacrifice, company enhanced pension scheme</li>
<li>Life insurance at 4x your salary &amp; group income protection</li>
<li>Private Medical Insurance with VitalityHealth including mental health support and cancer care. Partner benefits include discounts with Waitrose, Mr&amp;Mrs Smith and Peloton</li>
<li>Generous family-friendly policies</li>
<li>Incentives refer a friend scheme</li>
<li>Perkbox membership giving access to retail discounts, a wellness platform for physical and mental health, and weekly free and boosted perks</li>
<li>Access to initiatives like Cycle to Work, Salary Sacrificed Gym partnerships and Electric Vehicle (EV) leasing</li>
</ul>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>mid</Experiencelevel>
      <Workarrangement>hybrid</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>Go, Terraform, Kubernetes, Cilium, eBPF, Sigstore, Cosign, image provenance, SBOMs, hardware security modules, advanced cryptography, cloud-native security certifications</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Engine by Starling</Employername>
      <Employerlogo>https://logos.yubhub.co/enginebystarling.com.png</Employerlogo>
      <Employerdescription>Engine by Starling builds security software for core banking platforms.</Employerdescription>
      <Employerwebsite>https://www.enginebystarling.com/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://apply.workable.com/j/094F13AD03</Applyto>
      <Location>London</Location>
      <Country></Country>
      <Postedate>2026-03-20</Postedate>
    </job>
  </jobs>
</source>