The opportunity
GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation.
What you'll do
Lead comprehensive, governed rollouts of GitLab's own security capabilities: across the estate, bringing every project into alignment with our Project Security Configuration Standard and keeping it there.
Set a security baseline that accelerates engineering rather than gating it,: so teams inherit secure defaults and paved paths instead of negotiating requirements project by project.
Serve as Customer Zero for GitLab's security features: capture where adoption at scale is hard, and feed that evidence to Product and Engineering as a leading indicator of customer sentiment and a driver of roadmap decisions.
Establish proactive software supply chain security as a first-class: capability in Product Security, including third party component governance, trusted dependency controls, and the requirements behind product-level SBOMs.
Reduce systemic risk across our own groups and namespaces, including lateral movement and token governance.
Own the operations of the Product Security Risk Register and the metrics and: dashboards that give the department a single, data-driven view of our posture.
What they're looking for
- Partner with Compliance to produce evidence of our security control: implementation for audits, certifications, and internal security maturity assessments, so the same work that hardens the estate also satisfies the auditors.
- Represent this work externally, contributing thought leadership on how GitLab: secures its own software factory that strengthens our go-to-market narrative and customer trust.
- Lead, coach, and grow the team, and shape how it operates as it forms.
- Experience managing a security or engineering team, including hiring, performance, and career development.