Principal Security Awareness & Human Risk Engineer

at GitLab
USD 203,200-275,000 per year
SENIOR
✅ Remote

Tech Stack

Audit @ 4 Compliance OWASP Security @ 4

Details

The Principal Security Awareness & Human Risk Engineer is a strategic individual contributor role within GitLab's Security Assurance team. The role owns GitLab's global security awareness and education program and drives measurable reduction in human-related security risk, moving the program beyond completion-rate compliance toward sustained behavior change and embedded security culture.

Responsibilities

  • Own and evolve the global security awareness and education program, including annual, new-hire, role-based, targeted, executive, and microlearning content.
  • Lead the phishing simulation program end to end, including design, deployment, analysis, and targeted follow-up.
  • Apply behavior change principles to reinforce secure habits and address priority risk behaviors.
  • Build and sustain security culture through learning campaigns, Security Awareness Month, and ongoing engagement.
  • Produce multimedia awareness and education content, including video.
  • Administer training and phishing platforms, owning program data and reporting end to end.
  • Define and report performance indicators to Security Assurance leadership.
  • Own vendor relationships for phishing, secure coding (OWASP) training, and video production.
  • Lead market and competitor evaluations, renewal decisions, and cost negotiation, recommending in-house builds where commercial options underperform.
  • Collaborate on and maintain security policies, standards, and procedures.
  • Coordinate audit evidence and demonstrate control effectiveness.
  • Track remediation of identified gaps to closure.

Requirements

  • At least 10 years of experience building or scaling global awareness and human-risk programs in a large, globally distributed enterprise, with measurable outcomes. Regulated-industry experience is preferred.
  • SANS Security Awareness Professional (SSAP) certification or equivalent demonstrated expertise in building, maintaining, and measuring a mature awareness program.
  • Demonstrated experience running enterprise-scale phishing programs and organization-wide awareness campaigns.
  • Experience evaluating, selecting, consolidating, or replacing security training vendors, including cost and value analysis.
  • Instructional design capability.
  • Working knowledge of security policy development, audit support, and control evidence.
  • Ability to influence enterprise strategy across technical and non-technical teams without formal authority.
  • Ability to make complex security topics practical and engaging in an all-remote organization.
  • Experience onboarding, managing, and negotiating with third-party vendors.

Team

The Security Assurance organization helps GitLab build and maintain trust by strengthening how the company approaches security, compliance, and risk. The Security Risk team owns third-party risk management, security risk assessments, and remediation of security findings. Related functions include Security Compliance, Security Governance, and Security Enablement.

Compensation and Benefits

  • United States salary range: $203,200–$275,000 USD per year.
  • Benefits supporting health, finances, and well-being.
  • Flexible paid time off.
  • Team Member Resource Groups.
  • Equity compensation and Employee Stock Purchase Plan.
  • Growth and Development Fund.
  • Parental leave.

All GitLab roles are remote, though some roles may have specific location-based eligibility requirements.

More jobs at GitLab

Similar jobs