Never miss an opening. Get the daily email.
Daily Tech Jobs India

Senior Backend Engineer, Software Supply Chain Security (Rails)

GitLab · Remote, India

Verified live on July 25, 2026
Get every day's jobs where you already are
GitLab
Remote, IndiaFull-timeYears not stated

About this role

This is the second remote GitLab backend role on today's board, and it is a founding seat on a small team building GitLab's software supply chain security add on. The product problem is concrete: helping organisations control which software enters their builds, verify the integrity of what they ship, and identify malicious packages before they reach production. You would work across connected backend systems for package policy enforcement, artifact signing and verification, provenance attestation and malicious package intelligence, including a policy evaluation engine with performance sensitive execution paths tied to GitLab's Dependency Firewall. Signing work uses the Sigstore ecosystem, including Cosign, keyless signing with OpenID Connect and policy based promotion gates. The primary language is Ruby on Rails with Go useful alongside. The posting says openly that this is a founding role with high responsibility, working with a Staff Backend Engineer on architecture, and GitLab publishes no years figure.

Who this is for

What the posting asks for. GitLab publishes no years of experience figure on this role, so measure yourself against the skills:
- Proven backend engineering experience, including production Ruby on Rails expertise, since Rails is the team's primary language.
- Working knowledge of Go, or a clear willingness and ability to ramp up quickly in it.
- Solid API design skills, including REST, GraphQL and defining clear internal service boundaries.
- Solid PostgreSQL fundamentals including schema design, query optimisation and indexing strategies.
- Experience with Redis for caching and distributed coordination patterns.
- A security aware engineering mindset.

What the work actually looks like:
- Design and implement backend features across the add on's supply chain security surface: policy enforcement, artifact signing and verification, provenance attestation APIs and malicious package detection integrations.
- Build and improve the package policy evaluation engine, covering rule compilation, request matching, enforcement decisions and performance sensitive execution paths tied to GitLab's Dependency Firewall.
- Develop artifact signing and verification workflows using Sigstore and Cosign, including signing key lifecycle management, keyless signing with OpenID Connect, and policy based promotion gates.
- Create and evolve the configuration interfaces enterprise security teams use, including backend APIs and the GraphQL surface.
- Integrate the add on with GitLab's existing security policy framework, including policy inheritance and policy as code through YAML.
- Write and maintain comprehensive RSpec and integration test coverage, and improve test reliability across the team.
- Review merge requests with a security first mindset, with substantial decision making scope in partnership with the Staff Backend Engineer.

What kind of team this is: the posting describes a founding role on a small team with a high level of responsibility, and says the engineering choices made in API design, testing, performance and security will shape how the product grows.

Location and working pattern: GitLab states that all of its roles are remote, with some carrying location based eligibility requirements that its talent acquisition team can clarify. This listing is open to India. The posting also describes GitLab's all remote, asynchronous environment as part of what the role is suited to.

One more thing worth knowing: GitLab expects team members to incorporate AI into their daily workflows, stating it treats AI as a core productivity multiplier.

Honest fit guidance: the Rails requirement is primary and explicit, so this is a fit for a Rails backend engineer with security interest rather than a security specialist looking to learn Rails. Founding team means less process and more ambiguity than a mature team.
Apply on company site Opens job-boards.greenhouse.io, the employer's own application page. Applying is always free.
More roles like this, every day

Every link is checked live before we post it. Get the day's list in your inbox.

Free · one email a day · unsubscribe anytime

More from July 25, 2026

← Back to all jobs