GitLab logo
GitLab·Verified

Staff Security Engineer, IAM - GitLab

Fully remoteFull-timeSenior$168K - $238KUTC-8–-4NA#iam#terraform#pythonEquityESPPPTOParental leaveWellness

About the Role

As a Staff Security Engineer on the Corporate Security Identity Team, you will be a strategic technical leader responsible for transforming how our workforce accesses tools. You will move the organization from foundational controls to sophisticated, automated governance across identity platforms and emerging AI tooling.

What You’ll Do

  • Design Identity & AI Solutions: Architect scalable solutions, including AI agent governance frameworks and privileged access workflows that eliminate standing access.
  • Engineer Services: Replace low-code automation with robust Python services deployed on GCP Cloud Run, utilizing CI/CD, testing, and observability.
  • Codify Infrastructure: Lead the migration of identity platforms (Okta, Lumos, NHI) from click-ops to Terraform/OpenTofu/Pulumi.
  • Cloud Identity Architecture: Re-architect identity across GCP and AWS, focusing on resource hierarchy, secure-by-default guardrails, and workload identity federation.
  • AI Platform Governance: Manage identity and access for enterprise AI platforms (e.g., Anthropic Claude), including SSO, SCIM, and audit logging.
  • Non-Human Identity (NHI) Management: Pioneer governance for service accounts, API keys, and AI agents across the SaaS estate.
  • Cross-Functional Leadership: Partner with Security, IT, Engineering, and the Office of the CIO to translate business needs into technical specifications.
  • Mentorship: Guide senior and intermediate engineers in modern identity and AI security practices.

What You’ll Bring

  • IAM Expertise: Extensive experience at a Staff or senior IC level designing enterprise-scale identity solutions.
  • Okta Mastery: Deep knowledge of Identity Engine, advanced authentication policies, and API automation.
  • Infrastructure as Code: Strong proficiency in Terraform, OpenTofu, or Pulumi with a track record of migrating manual processes to code.
  • Software Engineering: Proficiency in writing modular, tested, and instrumented Python services.
  • Cloud Identity: Depth in GCP/AWS IAM, organization design, and workload identity federation.
  • AI Security: Hands-on experience governing enterprise AI platforms and awareness of risks like prompt injection and data leakage.
  • AI Tooling: Active practitioner of agentic tools (e.g., Claude Code, Cursor) in daily workflows.
  • Compliance Knowledge: Experience in regulated environments (FedRAMP, SOC2, SOX).

Benefits

  • Flexible Paid Time Off
  • Equity Compensation & Employee Stock Purchase Plan
  • Growth and Development Fund
  • Comprehensive health, financial, and well-being benefits
  • Parental Leave
  • Team Member Resource Groups

Timezone overlap

UTC-8–-4

Open to

NA

Sign in to track applications and earn points.

More roles at GitLab

Similar remote roles