← Все вакансии/Senior/GitLab
SeniorRemoteRemote, United States

Security Assurance Engineer

G
GitLab
Уровень
Senior
Формат
Remote
О роли

Описание вакансии

About the company

GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50 million registered users and more than 50% of the Fortune 100 trust GitLab.

Responsibilities
  • Design, document, and maintain IT General Controls and security controls across the in-scope estate, and test them for design and operating effectiveness.
  • Map shared controls once and test them to serve multiple obligations at the same time — SOX, SOC 2, ISO 27001, ISO 42001, NIST CSF, PCI-DSS, privacy regulations, and customer contractual commitments.
  • Serve as the compliance point of contact and liaison for the IT, Corporate Security, Engineering, and Finance teams.
  • Help set standards and control expectations for the governed use of AI across corporate and business systems.
  • Partner with Security Governance on corporate security policy work.
  • Run recurring compliance monitoring — user access reviews, privileged access, segregation of duties, change management, and configuration baselines.
  • Assess system implementations, migrations, and significant changes for control readiness ahead of go-live.
  • Manage SOX ITGC testing and certification requests from internal and external auditors.
  • Identify, track, and lead remediation of control deficiencies and risks.
Requirements
  • 5+ years in IT compliance, security compliance, IT audit, information security, or information technology, with a BA/BS in a business or technology field or equivalent experience.
  • Demonstrated experience testing controls and documenting those tests against frameworks such as COSO, COBIT, NIST CSF, ISO 27001, SOC 2, and SOX ITGC.
  • Experience assessing controls in SaaS and cloud-native application stacks.
  • Working knowledge of identity and access management — SSO, SCIM, RBAC, privileged access, and joiner/mover/leaver processes.
  • Familiarity with AI governance concepts and the control questions raised by AI tools, agents, and integrations.
Стек и навыки

С чем работаем