SlipstreamJobsFresh Startup & VC-Backed Jobs

Principal Security Awareness & Human Risk Engineer

GitLab - Remote - Remote - posted 2026-09-02

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

GitLab seeks a Principal Security Awareness & Human Risk Engineer to lead its global security awareness and education program within the Security Assurance team. This is a strategic individual contributor role focused on driving measurable reduction in human-related security risk and embedding security culture across a globally distributed organization. Key responsibilities include owning and evolving GitLab's comprehensive security awareness program (annual, new-hire, role-based, targeted, executive, and microlearning content); leading the enterprise phishing simulation program end-to-end (design, deployment, analysis, follow-up); applying behavioral change principles to reinforce secure habits; building security culture through campaigns and engagement; producing multimedia content including video; administering training and phishing platforms with full data ownership and reporting; defining and reporting KPIs to Security Assurance leadership; managing vendor relationships for phishing, secure coding (OWASP), and video production; leading market evaluations and renewal decisions with cost negotiation authority; collaborating on security policies and standards; coordinating audit evidence and control effectiveness; and tracking remediation of identified gaps. The ideal candidate brings 10+ years of experience building or scaling global awareness and human-risk programs in large, globally distributed enterprises with measurable outcomes (regulated-industry experience preferred). SANS Security Awareness Professional (SSAP) certification or equivalent demonstrated expertise is required. Must have proven experience running enterprise-scale phishing programs and organization-wide awareness campaigns, evaluating and selecting security training vendors, instructional design capability, working knowledge of security policy development and audit support, ability to influence enterprise strategy without formal authority, and skill in making complex security topics practical and engaging in an all-remote environment. Track record of vendor management and negotiation is essential.

Similar roles