
About the Role
As a Staff Corporate Security Engineer, you will secure the systems GitLab team members rely on daily in a fully remote environment. This role focuses on building secure-by-default controls for endpoints and SaaS platforms, with a strong emphasis on macOS. You will own technical decisions regarding endpoint hardening, automation, and detection, turning security requirements into scalable, auditable engineering systems.
What You’ll Do
- Architecture: Lead the security architecture of GitLab's endpoint fleet, focusing on macOS.
- Automation: Design and support secure endpoint deployment and lifecycle management using code-based workflows.
- Infrastructure as Code: Manage endpoint and SaaS security configurations via Terraform, version control, and CI/CD pipelines.
- Security Baselines: Define and enforce security standards across macOS, iOS, Windows, and Linux.
- Collaboration: Partner with IT, Security Operations, and Detection teams to improve telemetry and response models.
- Mentorship: Serve as a senior escalation point and mentor engineers across Corporate Security and IT.
What You’ll Bring
- Proven experience designing scalable endpoint or corporate security solutions.
- Deep expertise in endpoint management platforms (e.g., Jamf Pro, FleetDM) and macOS security.
- Strong proficiency in Terraform and Infrastructure-as-Code (IaC) practices.
- Experience with GitOps workflows (Git, merge requests, automated pipelines).
- Proficiency in scripting/programming (Python, Bash, PowerShell, or Go).
- Familiarity with cloud identity providers (Okta, Google Workspace, LDAP).
- Ability to communicate and collaborate effectively in an all-remote, asynchronous environment.
About the Team
The Corporate Security Engineering team treats security as engineering work. We build with code, operate through Git, and prioritize testable, auditable workflows to support GitLab's global, remote-first workforce.
Timezone overlap
UTC-8–-4
Open to
NA
Sign in to track applications and earn points.