New The Skills of Tomorrow: how AI-exposed is every skill in 2026? See the data →
GitLab

Senior Security Assurance Engineer

GitLab
Apply →
remote senior full-time $139,200-$196,000 USD Remote, United States

First indexed 4 Sept 2026

Description

GitLab's Security Assurance organization is responsible for designing, testing, and evidencing controls that protect the business. As a Senior Security Assurance Engineer, you will design and maintain IT General Controls and security controls across the in-scope estate, test them for design and operating effectiveness, and serve as a compliance point of contact for various teams.

Responsibilities:

  • Design, document, and maintain IT General Controls and security controls across the in-scope estate
  • Test controls for design and operating effectiveness against regulatory, contractual, and corporate policy requirements
  • Map shared controls to serve multiple obligations at the same time
  • Serve as the compliance point of contact and liaison for IT, Corporate Security, Engineering, and Finance teams
  • Help set standards and control expectations for the governed use of AI across corporate and business systems
  • Partner with Security Governance on corporate security policy work
  • Run recurring compliance monitoring
  • Assess system implementations, migrations, and significant changes for control readiness
  • Manage SOX ITGC testing and certification requests
  • Identify, track, and lead remediation of control deficiencies and risks

Requirements:

  • 5+ years in IT compliance, security compliance, IT audit, information security, or information technology
  • Demonstrated experience testing controls and documenting those tests against various frameworks
  • Experience assessing controls in SaaS and cloud-native application stacks
  • Working knowledge of identity and access management
  • Familiarity with AI governance concepts
  • Exceptional written and verbal communication skills

Nice to haves:

  • Relevant certifications such as CISA, CISSP, CRISC, or CISM
  • Experience with usage-based or consumption billing platforms, subscription management systems, or in-house metering and entitlement services
  • Experience with compliance automation and continuous control monitoring
  • Prior experience in a Security Assurance or GRC function
This listing is enriched and indexed by YubHub. To apply, use the employer's original posting: https://job-boards.greenhouse.io/gitlab/jobs/8770542002