# Senior Manager, Security Compliance

**Company**: GitLab
**Location**: Remote, US
**Work arrangement**: remote
**Experience**: senior
**Job type**: full-time
**Salary**: $168,000-$245,000 USD
**Category**: IT
**Industry**: Technology

**Apply**: https://job-boards.greenhouse.io/gitlab/jobs/8612148002?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply
**Canonical**: https://yubhub.co/jobs/job_ac087b33-b38

## Description

As a Senior Manager, Security Compliance at GitLab, you'll lead and mature our security compliance function while helping the company meet the needs of customers, auditors, and regulators.

### Job Overview

You'll report to the VP of Security Assurance and bring deep expertise in security frameworks, risk-based thinking, and team leadership to guide our certification strategy and strengthen how we manage compliance across the business.

### Responsibilities

- Lead and mentor a team focused on security compliance, providing direction, support, and clear priorities while building a high-performing function.

- Oversee and expand GitLab's certification portfolio across frameworks such as ISO 27001/17/18, ISO 42001, Service Organization Control 2 (SOC 2), Payment Card Industry (PCI), TiSAX, Cyber Essentials, and Federal Risk and Authorization Management Program (FedRAMP).

- Partner with cross-functional stakeholders in IT, Security, Legal, Product, and Engineering to integrate governance, risk, and compliance requirements into business processes and technical systems.

- Drive automation within the function by using scripting, coding, and AI-enabled approaches to improve governance, risk, and compliance workflows, including compliance-as-code and policy-as-code practices.

- Monitor regulatory changes, emerging frameworks, and industry trends, and use those insights to help shape the team's roadmap and prepare the business for new requirements.

- Manage relationships with third-party auditors, assessors, and consultants during activities such as external audits, certification reviews, and penetration tests.

- Strengthen the team's security metrics and reporting practices, including preparing and facilitating regular business reviews and giving leadership clear visibility into progress and risk.

- Serve as a subject matter expert and thought partner by delivering guidance, training, and security-focused content for internal teams, customers, and senior stakeholders, while helping strengthen GitLab's voice in the broader security market.

### Requirements

- Extensive experience in security compliance, audit, or related governance, risk, and compliance work, including experience supporting external audits.

- Deep knowledge of security and compliance frameworks such as SOC 2, ISO 27001, FedRAMP, and National Institute of Standards and Technology (NIST), with public sector or FedRAMP experience preferred.

- Experience leading teams and developing people, with the ability to set direction, manage priorities, and build strong partnerships across a distributed organization.

- Strong understanding of cloud security, software as a service (SaaS) security models, and DevSecOps practices, with the ability to apply that knowledge in a fast-moving technology environment.

- A risk-based mindset that goes beyond checklist compliance and focuses on meaningful control design, testing, and continuous improvement.

- Comfort using automation, scripting, or AI-enabled approaches to reduce manual work and improve the scale and efficiency of compliance programs.

- Excellent written and verbal communication skills, including the ability to explain complex technical and regulatory topics clearly to auditors, customers, executives, and cross-functional partners.

- Relevant certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), or similar credentials are highly desirable.

### Benefits

- Benefits to support your health, finances, and well-being

- Flexible Paid Time Off

- Team Member Resource Groups

- Equity Compensation & Employee Stock Purchase Plan

- Growth and Development Fund

- Parental Leave

## Skills

### Required
- security compliance
- governance
- risk management
- compliance frameworks
- cloud security
- SaaS security models
- DevSecOps practices
- automation
- scripting
- AI-enabled approaches

### Nice to have
- public sector or FedRAMP experience
- Certified Information Systems Security Professional (CISSP)
- Certified Information Security Manager (CISM)
- Certified Information Systems Auditor (CISA)

---

Source: [Apply at job-boards.greenhouse.io](https://job-boards.greenhouse.io/gitlab/jobs/8612148002?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply)
