Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
AI @ 3
Audit @ 6
Change Management
Communication @ 9
Compliance @ 6
Leadership @ 9
Reporting @ 6
Security @ 6
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
GitLab’s Security Assurance organization is responsible for designing, testing, and evidencing the controls that protect the business. This role operates the technology compliance program across IT-owned corporate applications and identity infrastructure, Corporate Security tooling, Engineering-owned applications supporting business operations such as billing, subscription and entitlement tracking, metering and provisioning, and third-party SaaS.
The role covers SOX ITGC as well as broader security, compliance, contractual, and regulatory obligations. It involves designing controls that satisfy multiple assurance requirements from a shared evidence base, supporting corporate security policy work, and helping establish standards for the governed use of AI across corporate and business systems.
Responsibilities
- Design, document, maintain, and test IT General Controls and security controls for design and operating effectiveness.
- Map and test shared controls across SOX, SOC 2, ISO 27001, ISO 42001, NIST CSF, PCI-DSS, privacy regulations, and customer contractual commitments.
- Serve as the compliance point of contact for IT, Corporate Security, Engineering, and Finance teams responsible for in-scope systems.
- Help establish standards and control expectations for AI tools, agents, and integrations, including data handling, access scope, human review, logging, evidence requirements, and escalation criteria.
- Partner with Security Governance on corporate security policies, standards, procedures, policy review, attestation, and Acceptable Use Policy adherence.
- Run recurring compliance monitoring, including user access reviews, privileged access, segregation of duties, change management, and configuration baselines.
- Assess system implementations, migrations, and significant changes for control readiness before go-live.
- Manage SOX ITGC testing and certification requests from internal and external auditors, and direct evidence collection for external audits.
- Identify, track, and lead remediation of control deficiencies and risks.
- Recommend improvements to compliance processes, metrics, and reporting.
Requirements
- 5+ years of experience in IT compliance, security compliance, IT audit, information security, or information technology.
- Bachelor’s degree in a business or technology field, or equivalent experience.
- Experience testing controls and documenting tests against frameworks such as COSO, COBIT, NIST CSF, ISO 27001, SOC 2, and SOX ITGC.
- Experience working directly with internal or external auditors.
- Experience assessing controls in SaaS and cloud-native application stacks.
- Working knowledge of identity and access management, including SSO, SCIM, RBAC, privileged access, and joiner/mover/leaver processes.
- Familiarity with AI governance concepts and control considerations for AI tools, agents, and integrations.
- Experience contributing to security policies and standards and supporting policy adherence or attestation processes.
- Ability to analyze data flows between product usage, billing, subscription, and financial reporting systems and identify control risks.
- Exceptional written and verbal communication skills, with credibility across senior leadership, engineering teams, auditors, and legal stakeholders.
- Ability to use GitLab, or willingness to learn.
Nice to Have
- CISA, CISSP, CRISC, CISM, or other relevant certifications.
- Experience with usage-based or consumption billing platforms, subscription management systems, or in-house metering and entitlement services.
- Experience with compliance automation and continuous control monitoring.
- Experience setting enterprise standards for AI use, including ISO 42001 or NIST AI RMF.
- Prior experience in a Security Assurance or GRC function supporting both corporate IT and product engineering.
- Big Four or external audit experience.
Team
The Security Assurance organization helps GitLab strengthen security, compliance, and risk management across the company. This role sits within Security Compliance and owns the control framework for the systems that run the business, partnering with Security Governance, Security Risk, Security Enablement, the SOX PMO, Internal Audit, Legal, and Privacy.
Benefits
- Benefits supporting health, finances, and well-being.
- Flexible paid time off.
- Team member resource groups.
- Equity compensation and employee stock purchase plan.
- Growth and development fund.
- Parental leave.
GitLab’s roles are remote, although some roles may have location-based eligibility requirements. The base salary range applies to residents of the United States and excludes bonuses, equity, and benefits.