Staff Security Governance Engineer, Policies & Standards

at GitLab
USD 168,000-238,000 per year
SENIOR
✅ Remote

Tech Stack

AI @ 6 Communication @ 7 Compliance @ 6 Security @ 6 Technical Leadership

Details

GitLab is seeking a Staff Security Governance Engineer to own how the company writes, maintains, communicates, and measures its security policies and standards. The role will translate emerging regulations, including AI regulation, into actionable requirements for engineering, product, and legal teams, while using automation to make governance continuous and lightweight. This individual contributor role sits within the Security Governance team in Security Assurance and reports to the Director, Customer Trust & Security Governance.

Responsibilities

Policies and Standards

  • Own the end-to-end lifecycle of GitLab's security policies, standards, procedures, and guidelines, including drafting, stakeholder review, approval, publication, annual review, and retirement.
  • Define and operate the exception management process, including risk-based approvals, expiry tracking, and trend reporting.
  • Run policy attestation and investigate non-adherence.
  • Keep policies practical and aligned with engineering practices in a DevSecOps environment.

Regulatory and Framework Alignment

  • Monitor emerging regulations and standards, including the EU AI Act, NIST AI RMF, ISO 42001, and sector or regional requirements.
  • Partner with Legal to assess regulatory impact and update policies ahead of compliance deadlines.
  • Maintain mappings between policies and frameworks including SOC 2, ISO 27001, ISO 42001, FedRAMP, and NIST CSF.

Measurement and Assurance

  • Define policy-adherence KPIs and report trends to Security leadership.
  • Run targeted internal assessments and drive remediation to closure.
  • Support audits by coordinating evidence, testing, and remediation management.

Customer Trust

  • Support customer questionnaires and customer meetings.
  • Convert recurring customer requests into improved policies and self-service content.

Automation and AI

  • Identify and implement automation and AI-assisted workflows for policy management, evidence collection, control monitoring, and assessment work in partnership with GRC Engineering.

Technical Leadership

  • Act as a technical and program leader across Security, Product, Legal, and Engineering, influencing without direct authority.
  • Mentor team members and help define the Security Governance roadmap.

Requirements

  • 10+ years of experience in security governance, GRC, or IT risk, with hands-on ownership of a policy and standards lifecycle and measurable outcomes; experience at a global technology company is preferred.
  • Working knowledge of SOC 2, ISO 27001, ISO 42001, FedRAMP, and NIST CSF, including practical implementation.
  • Understanding of cloud, SaaS, and DevSecOps practices, with the ability to write policies that engineers will follow.
  • Risk-based mindset that balances compliance requirements with actual security risk.
  • Demonstrated use of automation or AI to reduce manual GRC work.
  • Strong written and verbal communication skills, including the ability to translate technical concepts for engineers, executives, auditors, and customers.
  • Experience collaborating with Security, Product, Legal, and Engineering teams.
  • Certifications such as CISSP, CISM, CISA, or similar are highly desirable.

Success Measures

  • Within 30 days: assess the policy library and exception process, build stakeholder relationships, and propose a prioritized roadmap.
  • Within 90 days: improve the security policy library to align with NIST CSF, ISO 27001/27017/27018/42001, and PCI-DSS.
  • Within 120 days: establish a refreshed review cadence, implement exception reporting, and demonstrate improved policy adherence.
  • Within six months: develop Policy as Code and collaborate with Security, Product, Legal, and Engineering to integrate it into existing workflows.

Team and Work Environment

The Security Governance team is part of GitLab's Security Assurance organization and works with Security Compliance, Security Risk, and GRC Engineering. The team works remote-first and asynchronously, documenting and sharing work openly. GitLab hires remotely, though specific location-based eligibility requirements may apply.

Compensation and Benefits

  • United States base salary range: $168,000–$238,000 USD per year.
  • Benefits supporting health, finances, and well-being.
  • Flexible paid time off.
  • Team member resource groups.
  • Equity compensation and employee stock purchase plan.
  • Growth and development fund.
  • Parental leave.

More jobs at GitLab

Similar jobs