Security Factory Stage
The Security Factory engineering stage owns the engines that find, explain, and help fix security problems in customer code: the analyzers, the detection rules, the vulnerability management surface, and the research that feeds them.
This stage was formed in the FY27 Sec reorg from the former Application Security Testing stage plus the Security Insights and Security Infrastructure groups.
Leadership
| Role | Person |
|---|---|
| Stage lead | Maw Wildpaner (@maw, interim) |
| Principal Engineer | Isaac Dawson (@idawson) |
| Principal Engineer | Lucas Charles (@theoretick) |
| Principal Engineer | Meir Benayoun (@mbenayoun) |
Teams
| Group | Engineering Manager | Tech Lead | Label |
|---|---|---|---|
| Secret Detection | Amar Patel (@amarpatel) |
Ahmed Hemdan (@ahmed.hemdan) |
group::secret detection |
| Composition Analysis | Ethan Feller (@efeller) |
Nick Ilieskou (@nilieskou) |
group::composition analysis |
| Code Scanning | Ethan Feller (@efeller) |
Yoric Teller (@yteller) |
group::code scanning |
| Code Security | Ethan Feller (@efeller) |
Philip Cunningham (@philipcunningham) |
group::code security |
| AI Security | To be determined | Mher Tolpin (@mtolpin) |
group::ai security |
| Vulnerability Management | AJ Biton (@ajbiton) |
Lorenz van Herwaarden (@lorenzvanherwaarden) |
group::vulnerability management |
| Agentic Security Flows | AJ Biton (@ajbiton) |
Savas Vedova (@svedova) |
group::agentic security flows |
| Threat Research | Daniel Abeles (@dabeles) |
Dinesh Bolkensteyn (@dbolkensteyn) |
group::threat research |
| Security Foundations | Ryan Wells (@ryaanwells) |
Gregory Havenga (@ghavenga) |
group::security foundations |
Group membership is sourced from Workday and published on the product categories page.
Labels
Work in this stage carries the devops::security factory stage label plus the owning
group’s group:: label. Both are scoped labels and exist in the gitlab-org and
gitlab-com top-level groups.
Slack
#sec-security-factory-eng- stage engineering channel.
Per-group channels are listed on each group page. Several channel renames are still in progress, tracked in Sec reorg issue 2.
Stage resources
- Planning
- QA process
- Products and metrics
- Technical documentation
- Tutorial: add observability metrics to a CI-based analyzer
AI Security
Application Security Testing - Planning
Application Security Testing, Composition Analysis
Code Scanning Group
Code Security Group
Secret Detection Group
Secure QA Process
Secure Technical Documentation
Security Foundations
Threat Research Group
Tutorial: Add observability metrics to a CI-based analyzer
Vulnerability Management Group
8e3a4296)
