Security Platform Stage

The Security Platform stage builds the authentication, authorization, abuse prevention, secrets management, and software supply chain foundations of the GitLab platform.

The Security Platform engineering stage owns the platform primitives that every other part of GitLab depends on for identity and trust: authentication, authorization, abuse prevention, secrets management, and the software supply chain.

This stage was formed in the FY27 Sec reorg from the former Software Supply Chain Security stage plus the Dynamic Analysis group.

Leadership

Role Person
Stage lead Mark Mishaev (@mmishaev)
Senior Staff Engineer James Hebden (@jhebden)

Teams

Group Engineering Manager Tech Lead Label
Authentication Adil Farrukh (@adil.farrukh) Smriti Garg (@sgarg_gitlab) group::authentication
GATE Infra Adil Farrukh (@adil.farrukh) Matthias Käppler (@mkaeppler) group::gate infra
GATE Core Adil Farrukh (@adil.farrukh) Shilpa Kundapur (@skundapur) group::gate core
Authorization Jordon Proctor (@jpr0c) Ian Anderson (@imand3r) group::authorization
Abuse Engineering Jordon Proctor (@jpr0c) Jay Swain (@jayswain) group::abuse engineering
Build Security Mark Mishaev (@mmishaev, interim) To be hired group::build security
Dependency Firewall Mike Eddington (@mikeeddington) Mike Eddington (@mikeeddington) group::dependency firewall
Secrets Manager (Application) Connor Fleming (@cfleming3) Erick Bajao (@iamricecake) group::secrets manager application
Secrets Manager (OpenBAO) Connor Fleming (@cfleming3) Fabien Catteau (@fcatteau) group::secrets manager openbao

Group membership is sourced from Workday and published on the product categories page.

Labels

Work in this stage carries the devops::security platform stage label plus the owning group’s group:: label. Both are scoped labels and exist in the gitlab-org and gitlab-com top-level groups.

Slack

Per-group channels are listed on each group page. Several channel renames are still in progress, tracked in Sec reorg issue 2.

On-call

Teams in this stage participate in the Sec on-call rotation. See the Sec on-call handbook.


Abuse Engineering Group
The Abuse Engineering group creates controls to prevent abuse of the GitLab product
Authentication Group
The Authentication group is part of the Security Platform stage. Work is tracked with the …
Authorization Group
The Authorization group is part of the Security Platform stage. Work is tracked with the …
Build Security Group
The Build Security group owns SLSA, malicious package detection, and hardened build pipelines.
Dependency Firewall Group
The Dependency Firewall group owns the user experience for software supply chain security and the Dependency Firewall product.
GATE Core Group
The GATE Core group owns the GATE layers, authentication flows, authorization policies, and the Policy Decision Point.
GATE Infra Group
The GATE Infra group builds and operates the GitLab Adaptive Trust Environment infrastructure and Cloud Connector v2.
Secrets Manager Group
The GitLab Secrets Manager group handbook page, covering the Application and OpenBAO teams