Security Factory Stage

The Security Factory stage builds the scanning, detection, and remediation engines of the GitLab security portfolio, from analyzers through vulnerability management and threat research.

The Security Factory engineering stage owns the engines that find, explain, and help fix security problems in customer code: the analyzers, the detection rules, the vulnerability management surface, and the research that feeds them.

This stage was formed in the FY27 Sec reorg from the former Application Security Testing stage plus the Security Insights and Security Infrastructure groups.

Leadership

Role Person
Stage lead Maw Wildpaner (@maw, interim)
Principal Engineer Isaac Dawson (@idawson)
Principal Engineer Lucas Charles (@theoretick)
Principal Engineer Meir Benayoun (@mbenayoun)

Teams

Group Engineering Manager Tech Lead Label
Secret Detection Amar Patel (@amarpatel) Ahmed Hemdan (@ahmed.hemdan) group::secret detection
Composition Analysis Ethan Feller (@efeller) Nick Ilieskou (@nilieskou) group::composition analysis
Code Scanning Ethan Feller (@efeller) Yoric Teller (@yteller) group::code scanning
Code Security Ethan Feller (@efeller) Philip Cunningham (@philipcunningham) group::code security
AI Security To be determined Mher Tolpin (@mtolpin) group::ai security
Vulnerability Management AJ Biton (@ajbiton) Lorenz van Herwaarden (@lorenzvanherwaarden) group::vulnerability management
Agentic Security Flows AJ Biton (@ajbiton) Savas Vedova (@svedova) group::agentic security flows
Threat Research Daniel Abeles (@dabeles) Dinesh Bolkensteyn (@dbolkensteyn) group::threat research
Security Foundations Ryan Wells (@ryaanwells) Gregory Havenga (@ghavenga) group::security foundations

Group membership is sourced from Workday and published on the product categories page.

Labels

Work in this stage carries the devops::security factory stage label plus the owning group’s group:: label. Both are scoped labels and exist in the gitlab-org and gitlab-com top-level groups.

Slack

Per-group channels are listed on each group page. Several channel renames are still in progress, tracked in Sec reorg issue 2.

Stage resources

  1. Planning
  2. QA process
  3. Products and metrics
  4. Technical documentation
  5. Tutorial: add observability metrics to a CI-based analyzer

Agentic Security Flows Group
The Agentic Security Flows group builds the user flows that remediate vulnerabilities.
AI Security
The AI Security group secures the AI working environment, from endpoint to model.
Application Security Testing - Planning
Overview Our stage follows the product development flow process, including the workflow labels. This …
Application Security Testing, Composition Analysis
The Composition Analysis group at GitLab is charged with developing solutions which perform Container and Dependency Scanning and License Compliance.
Code Scanning Group
The Code Scanning group develops GitLab's Static Application Security Testing (SAST) capabilities for customer software repositories.
Code Security Group
The Code Security group owns scanning rules and the AI prompts and skills behind the Secure Software Factory.
Products
Secret Detection Group
The Secret Detection group protects you against leaking credentials, tokens, or other secrets on GitLab.
Secure QA Process
Everything starts with a Merge Request We expect and require all contributions to our products to go …
Secure Technical Documentation
Architecture Overview Severity Levels Feedback(Dismiss, create an issue or a Merge Request) Overview …
Security Foundations
Provide the required infrastructure and database resources to meet enterprise customer demand and required functionalities as a competitive application security platform.
Threat Research Group
The Threat Research group performs security research to improve the efficacy of GitLab's security capabilities and maintains the GitLab Advisory Database.
Tutorial: Add observability metrics to a CI-based analyzer
Observability metrics help you understand how CI-based security analyzers perform in production. …
Vulnerability Management Group
The Vulnerability Management group at GitLab is charged with developing solutions to enable customers to manage their security risks effectively and efficiently.