About the company
GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50 million registered users and more than 50% of the Fortune 100* trust GitLab to ship better, more secure software faster.
Responsibilities
- Set the technical direction, architectural patterns, reference implementations, and foundational security automation that shape how infrastructure security is implemented for GitLab's FedRAMP environment, and influence how those patterns are adopted across our broader Dedicated and Self-Managed offerings.
- Own the security posture of GitLab's FedRAMP environment as the senior technical voice, partnering with the Public Sector SRE team as a stable counterpart.
- Lead infrastructure security initiatives from problem framing through delivery, scoping ambiguous multi-quarter work — including FedRAMP continuous monitoring, control implementation, and authorization-impacting changes — into executable streams with clear success criteria.
- Conduct and lead comprehensive security reviews and threat modeling for complex infrastructure components in the Federal environment, identifying systemic risks and driving remediation across affected systems.
- Set the team's approach to AI-assisted security engineering within the constraints of a FedRAMP-authorized environment, identifying where AI can meaningfully increase leverage and establishing patterns others can adopt.
- Serve as an authoritative technical voice for Federal Infrastructure Security across our stakeholders — including engineering, compliance, and senior leadership — translating architectural tradeoffs and FedRAMP control implications into clear decisions.
- Partner on technical planning, prioritization, and roadmap development to align infrastructure security work with the business objectives of our Public Sector offering.
- Mentor and develop engineers on the team, raising the technical bar and modeling inclusive collaboration.
- Fulfill the Product Security Division Mission of securing GitLab Infrastructure with our own product ("dogfooding").
Requirements
- Proof of U.S. citizenship and U.S. residency.
- Expert knowledge of security for cloud infrastructure (AWS/GCP/Azure), container orchestration (Kubernetes) and related infrastructure and data security topics.
- Deep working knowledge of FedRAMP (Moderate and/or High) and the operational realities of running and continuously monitoring an authorized environment; familiarity with adjacent frameworks and standards (NIST 800-53, FIPS 140-2/3, ISO 27001, SOC 2, PCI-DSS).
- Proficiency in multiple programming languages (Go, Python, Ruby) with a track record of delivering production-quality security tooling.
- Extensive experience with Infrastructure-as-Code security (Terraform, Ansible, CloudFormation), policy-as-code, and automated compliance — particularly in support of regulated environments.
- Hands-on experience applying AI to security workflows, with a point of view on where it creates meaningful leverage in compliance-constrained environments.
- Track record of leading multi-team technical initiatives from ambiguous problem statements to measurable outcomes, setting technical direction that peer teams adopt.
- Strong written and verbal communication skills, able to explain security and compliance tradeoffs to technical and non-technical audiences.