Staff Infrastructure Security Engineer (USA)Active$291K

The opportunity

GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation.

What you'll do

  • Set the technical direction, architectural patterns, reference: implementations, and foundational security automation that shape how infrastructure security is implemented for GitLab's FedRAMP environment, and influence how those patterns are adopted across our broader Dedicated and Self-Managed offerings

  • Own the security posture of GitLab's FedRAMP environment as the senior: technical voice, partnering with the Public Sector SRE team as a stable counterpart

  • Lead infrastructure security initiatives from problem framing through: delivery, scoping ambiguous multi-quarter work — including FedRAMP continuous monitoring, control implementation, and authorization-impacting changes — into executable streams with clear success criteria

  • Conduct and lead comprehensive security reviews and threat modeling for: complex infrastructure components in the Federal environment, identifying systemic risks and driving remediation across affected systems

  • Set the team's approach to AI-assisted security engineering within the: constraints of a FedRAMP-authorized environment, identifying where AI can meaningfully increase leverage and establishing patterns others can adopt

  • Serve as an authoritative technical voice for Federal Infrastructure Security: across our stakeholders — including engineering, compliance, and senior leadership — translating architectural tradeoffs and FedRAMP control implications into clear decisions

What they're looking for

  • Partner on technical planning, prioritization, and roadmap development to: align infrastructure security work with the business objectives of our Public Sector offering
  • Mentor and develop engineers on the team, raising the technical bar and modeling inclusive collaboration
  • Fulfill the Product Security Division Mission of securing GitLab: Infrastructure with our own product ("dogfooding")