
About the Role
GitLab’s Security Assurance organization is responsible for designing, testing, and evidencing the controls that protect our business. As a Senior Security Assurance Engineer, you will operate the technology compliance program across our corporate and business systems. This role is framework- and department-agnostic, applying control discipline to financial reporting, security commitments, customer contracts, and regulatory obligations.
Key Responsibilities
- Control Design & Testing: Design, document, and maintain IT General Controls (ITGC) and security controls. Test for design and operating effectiveness against frameworks like SOX, SOC 2, ISO 27001, ISO 42001, NIST CSF, and PCI-DSS.
- Compliance Liaison: Serve as the primary point of contact for IT, Corporate Security, Engineering, and Finance teams to ensure assessments satisfy multiple stakeholders (Internal Audit, Legal, Privacy, etc.) simultaneously.
- AI Governance: Set standards for the governed use of AI tools, agents, and integrations. Assess control impacts and define acceptable use and evidence requirements.
- Policy Partnership: Collaborate with Security Governance to contribute to policies, standards, and procedures.
- Monitoring & Automation: Run recurring compliance monitoring (access reviews, segregation of duties, change management) and automate evidence collection to reduce manual effort.
- Risk Management: Identify, track, and remediate control deficiencies and advise teams on control readiness during system implementations and migrations.
What You’ll Bring
- 5+ years of experience in IT compliance, security compliance, IT audit, or information security.
- Proven experience testing controls against frameworks like COSO, COBIT, NIST CSF, ISO 27001, SOC 2, and SOX ITGC.
- Experience assessing controls in SaaS and cloud-native application stacks.
- Working knowledge of IAM (SSO, SCIM, RBAC, privileged access).
- Familiarity with AI governance concepts (data handling, access scope, logging).
- Strong communication skills with the ability to influence senior leadership and technical teams.
- BA/BS in a business or technology field or equivalent experience.
Nice to Haves
- Relevant certifications (CISA, CISSP, CRISC, or CISM).
- Experience with usage-based billing platforms or subscription management systems.
- Experience with compliance automation and continuous control monitoring.
- Prior experience in a GRC function supporting both corporate IT and product engineering.
Timezone overlap
UTC-8–-4
Open to
US
Sign in to track applications and earn points.