Senior Security Assurance EngineerActive$196K

The opportunity

The Security Assurance organization helps GitLab build and maintain trust by strengthening how we approach security, compliance, and risk across the company. This role sits within Security Compliance and owns the control framework for the systems that run the business.

What you'll do

  • Design, document, and maintain IT General Controls and security controls: across the in-scope estate, and test them for design and operating effectiveness against regulatory, contractual, and corporate policy requirements.

  • Map shared controls once and test them to serve multiple obligations at the: same time — SOX, SOC 2, ISO 27001, ISO 42001, NIST CSF, PCI-DSS, privacy regulations, and customer contractual commitments.

  • Serve as the compliance point of contact and liaison for the IT, Corporate: Security, Engineering, and Finance teams that own in-scope systems, so a single assessment serves Security Governance, Security Risk, Internal Audit, the SOX PMO, Legal, and Privacy.

  • Help set standards and control expectations for the governed use of AI across: corporate and business systems — assess tools, agents, and integrations for control impact, define what acceptable use and evidence look like, and escalate where a use case is SOX-relevant or touches customer data.

  • Partner with Security Governance on corporate security policy work: contribute and review policy, standard, and procedure content for the systems you act as liaison for, and support policy review, attestation, and Acceptable Use Policy adherence.

  • Run recurring compliance monitoring: user access reviews, privileged access, segregation of duties, change management, and configuration baselines — on monthly, quarterly, and annual cadences.

What they're looking for

  • Assess system implementations, migrations, and significant changes for: control readiness ahead of go-live, and advise Engineering and application teams on control requirements early in design.
  • Manage SOX ITGC testing and certification requests from internal and external: auditors, and direct evidence collection for external audits, automating that collection wherever possible.
  • Identify, track, and lead remediation of control deficiencies and risks, and: recommend improvements to compliance processes, metrics, and reporting across the estate.