GitLab logo
    G

    Staff Security Governance Engineer, Policies & Standards

    GitLab
    Remote, United States
    Remote
    Senior
    Full Time
    💰$168,000 - $238,000
    remotesecuritygovernancepolicyAIautomation

    Requirements

    • •10+ years in security governance, GRC, or IT risk with hands-on ownership of policy and standards lifecycle
    • •Working knowledge of SOC 2, ISO 27001, ISO 42001, FedRAMP, and NIST CSF including practical application
    • •Understanding of cloud, SaaS, and DevSecOps practices
    • •Ability to write policy that engineers will follow
    • •Risk-based mindset balancing compliance with real security risk
    • •Demonstrated use of automation or AI to reduce manual GRC work
    • •Strong written and verbal communication skills
    • •Experience collaborating with Security, Product, Legal, and Engineering

    What You'll Do

    • •Own the end-to-end lifecycle of security policies, standards, procedures, and guidelines including drafting, review, approval, publication, annual review, and retirement
    • •Define and run the exception management process including risk-based approvals, expiry tracking, and trend reporting
    • •Run policy attestation and investigate non-adherence
    • •Keep policies clear, practical, and aligned with DevSecOps engineering practices
    • •Monitor emerging regulations and standards and partner with Legal to assess impact and update policy
    • •Maintain mappings between policies and frameworks such as SOC 2, ISO 27001, ISO 42001, FedRAMP, and NIST CSF
    • •Define KPIs for policy adherence and report trends to Security leadership
    • •Run targeted internal assessments of adherence and drive remediation to closure
    • •Support audit activities by coordinating evidence, testing, and remediation management
    • •Support customer questionnaires and meetings, and help turn recurring customer requests into better policies and self-service content
    • •Identify and implement automation and AI-assisted workflows for policy management, evidence collection, control monitoring, and assessment work
    • •Act as a technical and program leader across Security, Product, Legal, and Engineering
    • •Mentor other team members and help set the direction of the Security Governance roadmap

    Nice to Have

    • •Certifications such as CISSP, CISM, CISA, or similar

    Benefits

    • •Benefits to support health, finances, and well-being
    • •Flexible Paid Time Off
    • •Team Member Resource Groups
    • •Equity Compensation & Employee Stock Purchase Plan
    • •Growth and Development Fund
    • •Parental Leave

    About GitLab

    GitLab is a web-based Git repository manager that offers a variety of features for software development teams.

    San Francisco, CA, US
    1000 - 5000
    Developer Tools