The opportunity
The Security Assurance organization helps GitLab build and maintain trust by strengthening how we approach security, compliance, and risk across the company. The Security Risk team sits within that group and owns third-party risk (TPRM), security risk assessments, and remediation of security findings.
What you'll do
Own and evolve the global security awareness and education program, spanning: annual, new-hire, role-based, targeted, executive, and microlearning content.
Lead the phishing simulation program end to end: design, deployment, analysis, and targeted follow-up.
Apply behavior change principles to reinforce secure habits and address priority risk behaviors.
Build and sustain security culture through learning campaigns, Security: Awareness Month, and ongoing engagement.
Produce multimedia awareness and education content, including video.
Administer the training and phishing platforms, owning program data and reporting end to end.
What they're looking for
- Define and report performance indicators to Security Assurance leadership.
- Own vendor relationships for phishing, secure coding (OWASP) training, and video production.
- Lead market and competitor evaluations, renewal decisions, and cost: negotiation, recommending in-house builds where commercial options underperform.
- Collaborate on and maintain security policies, standards, and procedures.