Never miss an opening. Get the daily email.
Daily Tech Jobs India

Staff Backend Engineer, Software Supply Chain Security

GitLab · Remote, India

Verified live on July 26, 2026
Get every day's jobs where you already are
GitLab
Remote, IndiaFull-timeYears not stated

About this role

This is the staff counterpart to the senior backend seat on GitLab's software supply chain security add on, and the two are worth reading together: the senior posting says you would work closely with a Staff Backend Engineer on architecture, and this is that engineer. You would define the technical architecture for backend systems that help customers control what software enters their builds, verify the integrity of what they ship, and detect malicious packages before production. Specific work includes leading the design for SLSA Level 2 and Level 3 capabilities inside GitLab CI/CD, architecting Sigstore integrations across Cosign, Fulcio and Rekor including signing workflows and trust boundaries, and designing request paths supporting allow, deny and quarantine package policies under real performance requirements. The primary language is Ruby on Rails with professional Go experience also required. GitLab publishes no years figure on this posting, so we have marked it not stated.

Who this is for

What the posting asks for. As with GitLab's other listings, no years of experience figure is published:
- Strong experience building backend applications with Ruby on Rails in a high scale production environment.
- Professional experience with Go for backend or infrastructure oriented services.
- A track record of leading architecture across multiple systems and influencing technical direction through strong engineering judgement.
- Experience writing clear technical proposals, requests for comments and decision records in an asynchronous, documentation first environment.
- A solid security mindset, and comfort working on products where trust, risk reduction and secure defaults are central requirements.
- Familiarity with software supply chain security concepts such as build provenance, artifact signing, dependency security or software bills of materials.
- Strong teamwork and communication skills across distributed teams and functions.

What the work actually looks like:
- Define and drive the technical architecture for the supply chain security add on, covering package policy enforcement, provenance generation, artifact signing and malicious package detection.
- Lead design and implementation for Supply-chain Levels for Software Artifacts Level 2 and Level 3 capabilities within GitLab CI/CD.
- Architect integrations with Sigstore services including Cosign, Fulcio and Rekor, covering signing workflows, verification and trust boundaries.
- Design backend services and request paths supporting allow, deny and quarantine package policies with strong performance and reliability expectations.
- Review merge requests with a focus on security, architectural consistency, maintainability and test quality.
- Mentor backend engineers across experience levels, including participating in hiring.
- Partner with Product, Infrastructure, Authentication, Authorization and Security counterparts on cross team decisions.
- Contribute to open source and industry conversations, including working groups on software supply chain security.

Example projects named: a Dependency Firewall for package policy enforcement across supported registries, and artifact attestation and signing using supply chain security standards and the Sigstore ecosystem.

Location and working pattern: GitLab states all of its roles are remote, with some carrying location based eligibility requirements. This listing includes India, and the posting describes the environment as remote, asynchronous and values driven, where written communication and ownership are central.

Honest fit guidance: this is a genuine architecture role, so the distinguishing requirement is having defined systems before they were built and written the proposals that got others to agree. Rails at high scale plus real Go experience is the technical floor, and supply chain security familiarity is what will separate applications.
Apply on company site Opens job-boards.greenhouse.io, the employer's own application page. Applying is always free.
More roles like this, every day

Every link is checked live before we post it. Get the day's list in your inbox.

Free · one email a day · unsubscribe anytime

More from July 26, 2026

← Back to all jobs