Senior Security Risk Engineer

at GitLab
📍 Canada
📍 United States
USD 139,200-189,000 per year
SENIOR
✅ Remote

Tech Stack

AI @ 3 Audit @ 6 Communication @ 9 Compliance @ 6 Security @ 6

Details

GitLab's Security Risk function is responsible for reducing risk across the security division, including third-party risk management (TPRM), annual security risk assessments, quarterly risk reporting, and remediation of security findings. This role owns risk identification, quantification, and remediation tracking across the business while helping automate and modernize risk management through AI and scripting.

The role partners with Security, Legal, IT, Product, and Engineering teams to translate technical findings and vendor risk into business-relevant risk statements and risk treatments, surface emerging risks, and report top risks to leadership.

Responsibilities

  • Own risk identification, analysis, and prioritization across TPRM, security risk assessments, and security findings using established frameworks such as NIST RMF, NIST 800-39, or ISO 31000.
  • Translate technical vulnerabilities, control gaps, and risk findings into clear, quantified risk statements for non-security stakeholders and leadership.
  • Drive remediation of findings and risk exceptions to closure, partnering with Engineering, IT, Product, and Legal, and escalating stalled or high-severity items.
  • Mature and maintain a risk register and quarterly reporting cadence covering open risks, remediation progress, and trends.
  • Own and mature AI risk management, including AI impact assessments, AI risk assessments, and risk treatments, to support ISO 42001 certification.
  • Design, develop, and implement key risk indicators and supporting metrics for top risks in the risk register.
  • Identify manual and repetitive steps in risk and TPRM workflows and build automation, scripts, or AI-enabled tooling to reduce manual work.
  • Contribute to the risk program roadmap, incorporating new frameworks, regulatory changes, and lessons learned from past assessments.
  • Monitor internal and external risk landscapes, including new frameworks, threat trends, and business changes, to identify and escalate emerging risks.

Requirements

  • 5+ years of experience in security risk management, including security-centric risk management or compliance frameworks such as NIST RMF, NIST 800-39, or ISO 31000.
  • Familiarity with AI governance frameworks such as ISO 42001 or NIST AI RMF is a plus.
  • Experience designing and executing qualitative and quantitative risk analyses that translate technical risks into measurable business impact.
  • Track record of driving risk assessments, risk registers, and remediation efforts to closure across IT, Procurement, Internal Audit, Legal, Product, and Engineering in a heavily regulated or multi-entity environment.
  • Experience interpreting technical control requirements and translating them for technical and non-technical stakeholders.
  • Demonstrated ability to build scripts, workflows, or AI-enabled tooling that reduces manual risk or GRC work.
  • Ability to operate with ambiguity, manage multiple concurrent assessments, and reprioritize under tight deadlines.
  • Exceptional written and verbal communication skills, including the ability to translate security risks into business risks.
  • Strong understanding of cloud security, SaaS security models, and DevSecOps practices.
  • Relevant certifications such as CISSP, CISM, CISA, or CRISC are preferred but not required.

Team

The Security Assurance organization strengthens GitLab's security, compliance, and risk practices. The Security Risk team owns TPRM, security risk assessments, and remediation of security findings, working alongside Security Compliance, Security Governance, and Security Enablement.

Benefits

  • Benefits supporting health, finances, and well-being
  • Flexible paid time off
  • Team Member Resource Groups
  • Equity Compensation and Employee Stock Purchase Plan
  • Growth and Development Fund
  • Parental Leave

More jobs at GitLab

Similar jobs