Staff Security Governance Engineer, Policies & StandardsPosted today$238K

The opportunity

The Security Assurance organization helps GitLab build and maintain trust by strengthening how we approach security, compliance, and risk. Security Governance sits within it and owns customer trust, security awareness, policies and standards, and other governance functions.

What you'll do

  • Policies and standards

  • Own the end-to-end lifecycle of GitLab's security policies, standards,: procedures, and guidelines: drafting, stakeholder review, approval, publication, annual review, and retirement.

  • Define and run the exception management process, including risk-based: approvals, expiry tracking, and trend reporting that shows where policies need to change.

  • Run policy attestation and investigate non-adherence.

  • Keep policies clear, practical, and aligned with how GitLab's engineering: teams work in a DevSecOps environment.

  • Regulatory and framework alignment

What they're looking for

  • Monitor emerging regulations and standards (e.g., EU AI Act, NIST AI RMF, ISO: 42001, sector or regional requirements) and partner with Legal well ahead of compliance deadlines to assess impact and update policy.
  • Maintain mappings between our policies and frameworks such as SOC 2, ISO: 27001, ISO 42001, FedRAMP, and NIST CSF, so requirements are written once and reused.
  • Measurement and assurance
  • Define KPIs for policy adherence and report trends to Security leadership.