Senior Security Assurance Engineer

7 hours, 49 minutes ago
Full-time
Senior
Cybersecurity
GitLab

GitLab

GitLab: The comprehensive DevOps platform revolutionizing software development with automation, AI workflows, and essential tools for efficient collaboration.

Internet Software & Services
1K-5K
Founded 2014

Description

  • Design, document, maintain, and test IT general and security controls for design and operating effectiveness.
  • Map shared controls across SOX, SOC 2, ISO 27001, ISO 42001, NIST CSF, PCI-DSS, privacy regulations, and customer commitments.
  • Coordinate compliance assessments among IT, Corporate Security, Engineering, Finance, Security Governance, Internal Audit, Legal, and Privacy.
  • Establish control standards for AI tools, agents, and integrations, including acceptable use, evidence, and escalation requirements.
  • Partner on security policies, standards, procedures, attestations, and acceptable-use adherence.
  • Run recurring access, privileged-access, segregation-of-duties, change-management, and configuration monitoring.
  • Assess system implementations, migrations, and significant changes for control readiness.
  • Manage SOX ITGC testing, auditor requests, and evidence collection, automating collection where possible.
  • Track and remediate control deficiencies and improve compliance metrics, processes, and reporting.

Requirements

  • 5+ years of experience in IT compliance, security compliance, IT audit, information security, or information technology.
  • BA/BS in a business or technology field, or equivalent experience.
  • Experience testing and documenting controls against COSO, COBIT, NIST CSF, ISO 27001, SOC 2, and SOX ITGC frameworks.
  • Direct experience working with internal or external auditors; Big Four or external audit experience preferred.
  • Experience assessing SaaS and cloud-native application environments.
  • Working knowledge of IAM, including SSO, SCIM, RBAC, privileged access, and joiner/mover/leaver processes.
  • Familiarity with AI governance concerns such as data handling, access scope, human review, logging, and evidence.
  • Experience developing security policies and standards and supporting adherence or attestation programs.
  • Ability to analyze data flows across product usage, billing, subscription, metering, entitlement, and financial reporting systems.
  • Strong written and verbal communication skills, with credibility among executives, engineers, auditors, and legal teams.
  • Ability or willingness to use GitLab; CISA, CISSP, CRISC, or CISM certification is preferred.
  • Experience with compliance automation, continuous control monitoring, AI governance, ISO 42001, NIST AI RMF, or security assurance across corporate IT and engineering is preferred.

Benefits

  • United States base salary range of $139,200–$196,000 USD, excluding bonuses, equity, and benefits.
  • Remote work environment, subject to location-based eligibility requirements.
  • Health, financial, and well-being benefits.
  • Flexible paid time off.
  • Equity compensation and employee stock purchase plan.
  • Growth and Development Fund.
  • Parental leave and Team Member Resource Groups.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Cyber Security Analyst II

RecargaPay 251-1K Capital Markets

RecargaPay is seeking a Cyber Security Analyst II for its Blue Team to defend cloud and internal environments through monitoring, hardening, vulnerability management, and resilient security controls.

AWS CI/CD Cybersecurity Encryption SIEM
9 hours, 34 minutes ago

Investigator

Stripe 5K-10K Diversified Financial Services

Stripe is hiring an Abuse Operations professional to investigate and lead response to product abuse and fraud incidents, helping protect merchants and strengthen fraud prevention across its financial infrastructure platform.

Apache Spark Databricks Network Security Pandas Python Scikit-learn SQL Trino
1 day, 8 hours ago

Senior Incident Responder

Dragos 251-1K Professional Services

Dragos is hiring a Senior Incident Responder in Singapore to support APAC customers by investigating and coordinating responses to high-impact incidents across complex OT environments.

2 days, 8 hours ago

Senior SOC Analyst | MDR

UltraViolet Cyber 501-1000 Computer and Network Security

UltraViolet Cyber is seeking a Senior Security Analyst to join its 24/7 shared-services Cyber Defense team, investigating security incidents and strengthening protection for client infrastructure and data.

Cybersecurity Linux Network Security
2 days, 9 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers