Senior Security Compliance Engineer, Public Sector

at GitLab
USD 139,200-196,000 per year
SENIOR
✅ Remote

Tech Stack

AWS @ 3 Communication @ 7 Compliance @ 4 GCP @ 3 Project Management @ 6 Security @ 4

Details

GitLab is seeking a highly skilled and experienced Senior Security Compliance Engineer to support its Public Sector Compliance team. The role focuses on advancing customer trust and executing the Public Sector Compliance roadmap for GitLab Dedicated, GitLab Dedicated for Government, self-managed offerings, and GitLab Inc. Due to government requirements, candidates must be United States citizens and based in the United States.

Responsibilities

  • Develop, implement, and manage Governance, Risk, and Compliance (GRC) strategies and processes supporting FedRAMP, IRAP, and other regulatory and industry standards.
  • Work with highly regulated customers to understand compliance requirements and provide tailored solutions supporting relevant frameworks and certifications.
  • Lead security assessments, audits, and certification processes through timely and successful completion.
  • Support GitLab Dedicated for Government's ongoing FedRAMP continuous monitoring commitments.
  • Collaborate with IT, Product, Engineering, Security, and Legal teams to integrate GRC requirements into operations and the technology stack.
  • Develop and maintain policies, procedures, controls, and other compliance documentation.
  • Use scripting and coding skills to automate GRC processes and implement compliance-as-code or policy-as-code solutions.
  • Monitor regulatory changes and industry trends to continuously improve the GRC program and maintain current compliance.
  • Provide training and guidance to internal teams and customers on GRC topics.
  • Serve as a subject matter expert on GRC issues and provide strategic advice to senior management and stakeholders.

Requirements

  • Valid proof of United States citizenship and residency.
  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field, or equivalent experience.
  • At least 5 years of experience in GRC, cybersecurity, or a related field, with a focus on highly regulated industries.
  • Experience achieving and maintaining security certifications such as FedRAMP, CMMC, SOC 2, IRAP, and ISO 27001.
  • Strong understanding of public-sector and highly regulated-industry regulatory and compliance requirements.
  • Familiarity with compliance-as-code, policy-as-code, automated control testing, and automated evidence collection.
  • Basic knowledge of FedRAMP requirements, processes, and documentation.
  • Familiarity with cloud hyperscaler services such as AWS and GCP.
  • Excellent analytical, problem-solving, and project management skills.
  • Strong communication and interpersonal skills for collaboration with internal teams, auditors, customers, and regulatory bodies.
  • Ability to work independently and manage multiple projects in a fast-paced environment.
  • CISSP, CISM, CISA, or similar certifications are highly desirable.

Team

The Public Sector Compliance team is part of GitLab's Security Assurance department within the Security division. The team works closely with the Commercial Security Compliance team and collaborates cross-functionally with Security, Product, Engineering, and Sales.

Benefits

  • Benefits supporting health, finances, and well-being
  • Flexible paid time off
  • Team member resource groups
  • Equity compensation and employee stock purchase plan
  • Growth and development fund
  • Parental leave

More jobs at GitLab

Similar jobs