About The Position

As a Backend Engineer on the Secret Detection team, you'll help protect sensitive data by building the services, scanning workflows, and remediation paths that prevent leaked secrets from reaching production. Your work will contribute to the full secret management lifecycle, from push protection to pipeline-based scanning, validation, and auditability, so developers can move quickly without taking on avoidable security risk. This is a strong opportunity if you want to work on security features with clear customer impact, improve detection quality, and help teams act when credentials, API keys, or other secrets are exposed. You'll focus on backend systems that power Secret Detection across GitLab's DevSecOps platform, working closely with product management and engineering peers in an async-first environment. In your first year, you'll contribute to core product capabilities, improve performance and result quality, and help shape technical direction through code reviews, RFCs, and proof of concepts. Some examples of our projects: Prevent secret leaks in source code with GitLab Secret Push Protection Verify validity of secret detection findings

Requirements

  • Experience building backend applications and services using Ruby on Rails, with working knowledge of GraphQL and interest in backend-focused product development.
  • Experience designing and delivering secure, maintainable systems that power production web applications at scale.
  • Knowledge of security concepts, common vulnerabilities, mitigation techniques, and secure coding practices.
  • Background developing or working with security tools or products, especially in areas related to code scanning or secret detection.
  • Experience investigating performance issues and improving backend reliability, efficiency, and maintainability.
  • Ability to work closely with cross-functional partners, including product, design, and technical writing, to deliver useful product outcomes.
  • Communicate clearly in writing and in conversation, especially in remote, async-first environments with distributed teams.
  • Bring transferable experience and a willingness to grow into parts of the security or Go stack.

Responsibilities

  • Guide the design and implementation of backend features for GitLab Secret Detection in Ruby on Rails, GraphQL, and Go, delivering capabilities that improve coverage, reliability, or response time for secret detection workflows.
  • Build clean, well-tested, maintainable code that meets GitLab standards for reliability and performance, helping reduce regressions and maintain backend systems at scale.
  • Partner with product management and engineering peers to deliver backend capabilities that improve detection, validation, remediation, and audit trail coverage across the secret management lifecycle.
  • Improve detection quality by reducing false positives, strengthening secret validation workflows, and enabling faster, more effective remediation paths.
  • Contribute to code reviews, RFCs, and proof-of-concept work that guide technical approaches across the Secret Detection category.
  • Identify technical debt and operational inefficiencies, then propose and implement practical improvements.
  • Diagnose performance and optimization issues in backend systems and implement improvements that increase efficiency, scalability, and service reliability.
  • Work effectively in a globally distributed, async-first team while participating in planning, engineering discussions, and pairing when needed.

Benefits

  • Benefits to support your health, finances, and well-being
  • Flexible Paid Time Off
  • Team Member Resource Groups
  • Equity Compensation & Employee Stock Purchase Plan
  • Growth and Development Fund
  • Parental leave
  • Home office support

Stand Out From the Crowd

Upload your resume and get instant feedback on how well it matches this job.

Upload and Match Resume

What This Job Offers

Job Type

Full-time

Career Level

Senior

Education Level

No Education Listed

Number of Employees

501-1,000 employees

© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service