Senior Security Risk Engineer @GitLab
All Others
Salary usd 139,200 - 1..
Remote Location
Employment Type full-time
Posted YDay

[Hiring] Senior Security Risk Engineer @GitLab

YDay - GitLab is hiring a remote Senior Security Risk Engineer. πŸ’Έ Salary: usd 139,200 - 189,000 per year πŸ“Location: Northern America

Role Description

GitLab's Security Risk function is responsible for reducing risk across the security division: third-party risk (TPRM), annual security risk assessments, quarterly risk reporting, and remediation of security findings. As a Senior Security Risk Engineer, you'll take ownership of risk identification, quantification, and remediation tracking across the business, and you'll be a driving force behind automating and modernizing how the team does this work using AI and scripting. Reporting to the Security Risk Manager, you will bring expertise on risk methodology, risk-based thinking, and AI-enablement.

In this role, you'll partner closely with Security, Legal, IT, Product, and Engineering to translate technical findings and vendor risk into business-relevant risk statements and risk treatments. You’ll help surface emerging risks, and report top risks to leadership.

  • Building and maintaining a risk register that translates technical vulnerabilities, control gaps, and third-party risk findings into quantified, business-relevant risk statements.
  • Driving cross-functional remediation of security findings and risk issues to closure, tracked against SLAs.
  • Driving automation and AI-enabled improvements for risk and GRC workflows so the team can spend less time on manual work and more time on high-value risk analysis and program maturity.

Qualifications

  • 5+ years of experience in security risk management, working with security-centric risk management or compliance frameworks (e.g., NIST RMF, NIST 800-39, ISO 31000).
  • Familiarity with AI governance frameworks (e.g., ISO 42001, NIST AI RMF) is a plus.
  • Experience designing and executing qualitative and quantitative risk analyses that translate technical risks into measurable business impact.
  • A track record of driving risk assessments, risk registers, and remediation efforts to closure across IT, Procurement, Internal Audit, Legal, Product, and Engineering, in a heavily regulated or multi-entity environment.
  • Experience interpreting technical control requirements and translating them for both technical and non-technical stakeholders.
  • Demonstrated bias toward automation: you've personally built scripts, workflows, or AI-enabled tooling that reduced manual risk or GRC work, not just evaluated tools conceptually.
  • Comfort operating with ambiguity, managing multiple concurrent assessments, and reprioritizing under tight deadlines.
  • Exceptional written and verbal communication skills with demonstrated ability to translate security risks into business risks.
  • Strong understanding of cloud security, SaaS security models, and DevSecOps practices.
  • Relevant certifications (e.g., CISSP, CISM, CISA, CRISC) are preferred but not required.

Requirements

  • Own risk identification, analysis, and prioritization across third-party risk (TPRM), security risk assessments, and security findings, using an established risk framework (e.g., NIST RMF, ISO 31000, or NIST 800-39).
  • Translate technical vulnerabilities, control gaps, and risk findings into clear, quantified risk statements that non-security stakeholders and leadership can act on.
  • Drive remediation of findings and risk exceptions to closure, partnering with Engineering, IT, Product, and Legal, and escalating stalled or high-severity items.
  • Mature and maintain a risk register and quarterly reporting cadence that gives leadership clear visibility into open risk, remediation progress, and trends.
  • Own and mature AI risk management, including AI impact assessments, AI risk assessments, and risk treatments, to support ISO 42001 certification.
  • Design, develop, and implement key risk indicators and supporting metrics for top risks in the risk register.
  • Identify manual, repetitive steps in risk and TPRM workflows and personally build the automation, scripting, or AI-enabled tooling to remove them.
  • Contribute to the roadmap for the risk program, incorporating new frameworks, regulatory changes, and lessons learned from past assessments.
  • Monitor the internal and external risk landscape (new frameworks, threat trends, business changes) to identify and escalate emerging risks before they become findings.

Benefits

  • Flexible Paid Time Off
  • Team Member Resource Groups
  • Equity Compensation & Employee Stock Purchase Plan
  • Growth and Development Fund
  • Parental Leave
Before You Apply
️
remote Be aware of the location restriction for this remote position: Northern America
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Senior Security Risk Engineer @GitLab
All Others
Salary usd 139,200 - 1..
Remote Location
Employment Type full-time
Posted YDay
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
️
remote Be aware of the location restriction for this remote position: Northern America
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
Γ—
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews

⚑ 129,250+ remote jobs, refreshed hourly

πŸ”” Real-time alerts: Apply first, direct to employer

πŸ›‘οΈ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later