Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Audit @ 4
Compliance
OWASP
Security @ 4
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
The Principal Security Awareness & Human Risk Engineer is a strategic individual contributor role within GitLab's Security Assurance team. The role owns GitLab's global security awareness and education program and drives measurable reduction in human-related security risk, moving the program beyond completion-rate compliance toward sustained behavior change and embedded security culture.
Responsibilities
- Own and evolve the global security awareness and education program, including annual, new-hire, role-based, targeted, executive, and microlearning content.
- Lead the phishing simulation program end to end, including design, deployment, analysis, and targeted follow-up.
- Apply behavior change principles to reinforce secure habits and address priority risk behaviors.
- Build and sustain security culture through learning campaigns, Security Awareness Month, and ongoing engagement.
- Produce multimedia awareness and education content, including video.
- Administer training and phishing platforms, owning program data and reporting end to end.
- Define and report performance indicators to Security Assurance leadership.
- Own vendor relationships for phishing, secure coding (OWASP) training, and video production.
- Lead market and competitor evaluations, renewal decisions, and cost negotiation, recommending in-house builds where commercial options underperform.
- Collaborate on and maintain security policies, standards, and procedures.
- Coordinate audit evidence and demonstrate control effectiveness.
- Track remediation of identified gaps to closure.
Requirements
- At least 10 years of experience building or scaling global awareness and human-risk programs in a large, globally distributed enterprise, with measurable outcomes. Regulated-industry experience is preferred.
- SANS Security Awareness Professional (SSAP) certification or equivalent demonstrated expertise in building, maintaining, and measuring a mature awareness program.
- Demonstrated experience running enterprise-scale phishing programs and organization-wide awareness campaigns.
- Experience evaluating, selecting, consolidating, or replacing security training vendors, including cost and value analysis.
- Instructional design capability.
- Working knowledge of security policy development, audit support, and control evidence.
- Ability to influence enterprise strategy across technical and non-technical teams without formal authority.
- Ability to make complex security topics practical and engaging in an all-remote organization.
- Experience onboarding, managing, and negotiating with third-party vendors.
Team
The Security Assurance organization helps GitLab build and maintain trust by strengthening how the company approaches security, compliance, and risk. The Security Risk team owns third-party risk management, security risk assessments, and remediation of security findings. Related functions include Security Compliance, Security Governance, and Security Enablement.
Compensation and Benefits
- United States salary range: $203,200–$275,000 USD per year.
- Benefits supporting health, finances, and well-being.
- Flexible paid time off.
- Team Member Resource Groups.
- Equity compensation and Employee Stock Purchase Plan.
- Growth and Development Fund.
- Parental leave.
All GitLab roles are remote, though some roles may have specific location-based eligibility requirements.