About the Role
Role details below.
Responsibilities
- Lead the product strategy for GitLab's Software Supply Chain Security offering, setting direction across key pillars such as dependency firewall, software bill of materials (SBOM), malicious package detection, and provenance and attestation.
- Drive product discovery, prioritization, and delivery by partnering with Engineering and User Experience to break down complex security problems into clear requirements and iterative roadmap decisions.
- Work directly with customers and prospects to understand supply chain security challenges, gather feedback, and translate that input into product improvements and roadmap priorities.
- Partner with teams across Sales, Customer Success, Support, and Marketing to validate demand, improve adoption, and make sure the product meets real customer and business needs.
- Analyze market trends, customer workflows, and competitive offerings in software composition analysis, software supply chain security, and related categories to inform product decisions.
- Define success measures for the SSCS product area, using qualitative and quantitative signals to evaluate outcomes, guide trade-offs, and communicate progress.
- Represent the SSCS domain internally as a subject matter expert by creating clear narratives, documentation, and artifacts that help teams understand the product vision and value.
- Contribute to a high-performing, all-remote product organization by collaborating asynchronously, sharing context transparently, and driving decisions that support GitLab's broader product strategy.
Requirements
- Product management experience owning complex technical products, ideally in security, DevSecOps, or developer-focused business-to-business software as a service (B2B SaaS) environments.
- Knowledge of software supply chain security concepts such as provenance, attestation, signing, verification, and software bill of materials (SBOM), along with familiarity with frameworks like Supply-chain Levels for Software Artifacts (SLSA).
- Experience with dependency risk and software composition analysis, including working with or near dependency scanning, package security, or related tooling.
- Ability to turn highly technical concepts into clear product direction, customer value, and straightforward communication for both technical and non-technical audiences.
- Experienc
Work Arrangement
Remote (Worldwide)