About the Company
GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50 million registered users and more than 50% of the Fortune 100* trust GitLab to ship better, more secure software faster.
The same principles built into our products are reflected in how our team works: we embrace AI as a core productivity multiplier, with all team members expected to incorporate AI into their daily workflows to drive efficiency, innovation, and impact.
About the Role
The Corporate Security Identity Team is on a mission to transform how our workforce ecosystem securely accesses the tools they need to do their best work, advancing from foundational controls to sophisticated, automated governance across our identity platforms and our emerging AI tooling.
As a Staff Security Engineer, you'll be a senior technical leader and strategic anchor on the team. You're passionate about designing elegant solutions to complex identity challenges, whether that's architecting enterprise-scale conditional access policies, codifying our configuration of our identity platforms, or building governance frameworks for AI agents and non-human identities. You'll be responsible for critical systems, write technical proposals that influence our roadmap, raise the bar through design and code review, and lead cross-functional initiatives that span Security, IT, Engineering, Compliance and People teams.
Responsibilities
- Design comprehensive identity and AI access solutions that scale with our business growth, from AI agent governance frameworks to privileged access workflows that eliminate standing access through just-in-time provisioning.
- Replace low-code automation with engineered services, migrating our existing iPaaS automation to Python services on GCP Cloud Run with source control, tests, CI and observability.
- Codify our identity platforms in Terraform/OpenTofu/Pulumi, leading the migration of Okta, Lumos, and our NHI platform from click-ops to peer-reviewed infrastructure-as-code, with a focus on global critical policies.
- Help re-architect identity and access across our GCP and AWS organizations, partnering on resource hierarchy design, secure-by-default guardrails (org policies, SCPs, permission boundaries), workload identity federation, and a credible path to least privilege for both human and workload access.
- Lead identity and access engineering for our enterprise AI platforms including administration, SSO and SCIM integration, audit logging, data controls, and policy enforcement for Claude (web, Claude Code, Cowork) and adjacent tools.
- Pioneer non-human identity governance by designing monitoring and management solutions for service accounts, API keys, certificates, AI agents, and MCP integrations, and leading deployment, integration, and operationalization of our NHI platform across the SaaS estate.
- Drive cross-functional initiatives with Security, IT, Engineering, Enterprise AI, and the Office of the CIO to extract requirements from ambiguous business needs and translate them into actionable technical specifications.
- Mentor senior and intermediate engineers on technical implementation and strategic thinking, helping them develop expertise in modern identity and AI security practices.
Requirements
- Extensive IAM experience designing and implementing enterprise-scale solutions, with demonstrated time at a Staff or senior IC level.
- Expert-level Okta expertise including Identity Engine, advanced authentication policies, lifecycle workflows, and API automation.
- Strong infrastructure-as-code practice with Terraform/OpenTofu/Pulumi, including provider experience for SaaS identity platforms and a track record of migrating click-ops to code.
- Proficiency writing and shipping Python as a software engineer designed as modular, tested, code-reviewed, deployed as services (GCP Cloud Run or equivalent serverless runtime) and instrumented for failure.
- Cloud identity depth in GCP and/or AWS, including resource hierarchy and organization design, IAM policy models, workload identity federation, and preventive controls such as org policies, SCPs, and permission boundaries.
- Hands-on experience administering or governing enterprise AI platforms (Anthropic Claude preferred; OpenAI ChatGPT Enterprise, Google Gemini Enterprise, or similar acceptable), and awareness of AI-specific risks including prompt injection, MCP attack surface, agent identity, and data leakage.
- A working practice of building with AI tooling: you use agentic tools (Claude Code, Cursor, or similar) in your daily engineering work, iterate on your own workflows as capabilities shift, and can bring the rest of the team along.