Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
AWS @ 3
Communication @ 7
Compliance @ 4
GCP @ 3
Project Management @ 6
Security @ 4
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
GitLab is seeking a highly skilled and experienced Senior Security Compliance Engineer to support its Public Sector Compliance team. The role focuses on advancing customer trust and executing the Public Sector Compliance roadmap for GitLab Dedicated, GitLab Dedicated for Government, self-managed offerings, and GitLab Inc. Due to government requirements, candidates must be United States citizens and based in the United States.
Responsibilities
- Develop, implement, and manage Governance, Risk, and Compliance (GRC) strategies and processes supporting FedRAMP, IRAP, and other regulatory and industry standards.
- Work with highly regulated customers to understand compliance requirements and provide tailored solutions supporting relevant frameworks and certifications.
- Lead security assessments, audits, and certification processes through timely and successful completion.
- Support GitLab Dedicated for Government's ongoing FedRAMP continuous monitoring commitments.
- Collaborate with IT, Product, Engineering, Security, and Legal teams to integrate GRC requirements into operations and the technology stack.
- Develop and maintain policies, procedures, controls, and other compliance documentation.
- Use scripting and coding skills to automate GRC processes and implement compliance-as-code or policy-as-code solutions.
- Monitor regulatory changes and industry trends to continuously improve the GRC program and maintain current compliance.
- Provide training and guidance to internal teams and customers on GRC topics.
- Serve as a subject matter expert on GRC issues and provide strategic advice to senior management and stakeholders.
Requirements
- Valid proof of United States citizenship and residency.
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field, or equivalent experience.
- At least 5 years of experience in GRC, cybersecurity, or a related field, with a focus on highly regulated industries.
- Experience achieving and maintaining security certifications such as FedRAMP, CMMC, SOC 2, IRAP, and ISO 27001.
- Strong understanding of public-sector and highly regulated-industry regulatory and compliance requirements.
- Familiarity with compliance-as-code, policy-as-code, automated control testing, and automated evidence collection.
- Basic knowledge of FedRAMP requirements, processes, and documentation.
- Familiarity with cloud hyperscaler services such as AWS and GCP.
- Excellent analytical, problem-solving, and project management skills.
- Strong communication and interpersonal skills for collaboration with internal teams, auditors, customers, and regulatory bodies.
- Ability to work independently and manage multiple projects in a fast-paced environment.
- CISSP, CISM, CISA, or similar certifications are highly desirable.
Team
The Public Sector Compliance team is part of GitLab's Security Assurance department within the Security division. The team works closely with the Commercial Security Compliance team and collaborates cross-functionally with Security, Product, Engineering, and Sales.
Benefits
- Benefits supporting health, finances, and well-being
- Flexible paid time off
- Team member resource groups
- Equity compensation and employee stock purchase plan
- Growth and development fund
- Parental leave
More jobs at GitLab
Principal Security Researcher
GitLab · Canada, United Kingdom, Israel, United States
USD 203,200-275,000 per year
Staff Security Researcher
GitLab · Canada, United Kingdom, Israel, United States
USD 168,000-238,000 per year
Engineering Manager, Trusted Agentic Development
GitLab · Poland
PLN 296,000-444,000 per year
Senior Security Assurance Engineer
GitLab · United States
USD 139,200-196,000 per year
Staff Infrastructure Security Engineer
GitLab · United States
USD 168,000-238,000 per year
Similar jobs
Sr. Security Engineer - GRC Fintech & Financial Services
SpaceXAI · Washington, United States, New York City, United States, Palo Alto, United States
USD 152,000-258,000 per year
Senior Security Engineer - GRC Frameworks & AI Governance
SpaceXAI · Washington, United States, New York City, United States, Palo Alto, United States
USD 152,000-258,000 per year
Senior Manager, IT SOX
Anthropic · San Francisco, United States
USD 230,000-300,000 per year
Staff+ Software Engineer, Enterprise
Anthropic · New York City, United States, San Francisco, United States
USD 405,000-485,000 per year
Solutions Engineer
SentinelOne · United States
USD 196,000-250,000 per year
Senior Cloud Software Engineer - Efficiency Engineering
ClickHouse · United States
USD 133,400-232,000 per year
Senior Manager, Detection & Response (Security Engineering)
Confluent · United States
USD 241,700-319,000 per year
Manager, Information Security
ClickHouse · United States
USD 180,000-300,000 per year