SlipstreamJobsFresh Startup & VC-Backed Jobs

Senior Security Assurance Engineer

GitLab - Remote - Remote - posted 2026-09-03

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

GitLab's Security Assurance organization is seeking a Senior Security Assurance Engineer to design, test, and evidence controls that protect the business across IT-owned corporate applications, identity infrastructure, Corporate Security tooling, and Engineering-owned systems supporting business operations like billing and subscription management. In this role, you will operate the technology compliance program across systems material to financial reporting, security commitments, customer contracts, and regulatory obligations. You'll design controls once and satisfy multiple assurance consumers (SOX ITGC, SOC 2, ISO 27001, ISO 42001, NIST CSF, PCI-DSS, privacy regulations, and customer contractual commitments) from the same evidence. Key responsibilities include: - Design, document, and maintain IT General Controls and security controls, testing them for design and operating effectiveness against regulatory, contractual, and corporate policy requirements - Map shared controls to serve multiple compliance obligations simultaneously - Serve as the compliance liaison for IT, Corporate Security, Engineering, and Finance teams, coordinating with Security Governance, Internal Audit, the SOX PMO, Legal, and Privacy - Help set standards for governed use of AI across corporate and business systems, assessing tools and integrations for control impact - Partner with Security Governance on corporate security policy work, contributing to policy and procedure content - Run recurring compliance monitoring on user access reviews, privileged access, segregation of duties, change management, and configuration baselines - Assess system implementations, migrations, and significant changes for control readiness - Manage SOX ITGC testing and certification requests from internal and external auditors - Identify, track, and lead remediation of control deficiencies and risks You'll bring 5+ years in IT compliance, security compliance, IT audit, information security, or information technology, with a BA/BS in a business or technology field or equivalent experience. The role requires expertise in compliance frameworks, control design and testing, and the ability to work cross-functionally with technical and business teams.

Similar roles