# Senior Security Assurance Engineer

**Company**: GitLab
**Location**: Remote, United States
**Work arrangement**: remote
**Experience**: senior
**Job type**: full-time
**Salary**: $139,200-$196,000 USD
**Category**: IT
**Industry**: Technology

**Apply**: https://job-boards.greenhouse.io/gitlab/jobs/8770542002?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply
**Canonical**: https://yubhub.co/jobs/job_6a046c46-787

## Description

GitLab's Security Assurance organization is responsible for designing, testing, and evidencing controls that protect the business. As a Senior Security Assurance Engineer, you will design and maintain IT General Controls and security controls across the in-scope estate, test them for design and operating effectiveness, and serve as a compliance point of contact for various teams.

Responsibilities:

- Design, document, and maintain IT General Controls and security controls across the in-scope estate

- Test controls for design and operating effectiveness against regulatory, contractual, and corporate policy requirements

- Map shared controls to serve multiple obligations at the same time

- Serve as the compliance point of contact and liaison for IT, Corporate Security, Engineering, and Finance teams

- Help set standards and control expectations for the governed use of AI across corporate and business systems

- Partner with Security Governance on corporate security policy work

- Run recurring compliance monitoring

- Assess system implementations, migrations, and significant changes for control readiness

- Manage SOX ITGC testing and certification requests

- Identify, track, and lead remediation of control deficiencies and risks

Requirements:

- 5+ years in IT compliance, security compliance, IT audit, information security, or information technology

- Demonstrated experience testing controls and documenting those tests against various frameworks

- Experience assessing controls in SaaS and cloud-native application stacks

- Working knowledge of identity and access management

- Familiarity with AI governance concepts

- Exceptional written and verbal communication skills

Nice to haves:

- Relevant certifications such as CISA, CISSP, CRISC, or CISM

- Experience with usage-based or consumption billing platforms, subscription management systems, or in-house metering and entitlement services

- Experience with compliance automation and continuous control monitoring

- Prior experience in a Security Assurance or GRC function

## Skills

### Required
- IT compliance
- security compliance
- IT audit
- information security
- identity and access management
- AI governance

### Nice to have
- CISA
- CISSP
- CRISC
- CISM
- compliance automation
- continuous control monitoring

---

Source: [Apply at job-boards.greenhouse.io](https://job-boards.greenhouse.io/gitlab/jobs/8770542002?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply)
