SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
GitLab is seeking a Senior Security Compliance Engineer to support its Public Sector Compliance team. This role focuses on advancing customer trust and executing GitLab's public sector compliance roadmap, with direct support for GitLab Dedicated and GitLab Dedicated for Government SaaS offerings, as well as maturing GitLab's overall compliance posture.
Key responsibilities include developing and implementing Governance, Risk, and Compliance (GRC) strategies and processes aligned with regulatory standards such as FedRAMP, CMMC, IRAP, SOC 2, and ISO 27001. You will work closely with highly regulated government and public sector customers to understand their unique compliance requirements and deliver tailored solutions. You'll lead security assessments, audits, and certification processes, ensuring timely completion and supporting GitLab Dedicated for Government's ongoing FedRAMP continuous monitoring commitments.
The role requires cross-functional collaboration with IT, Product, Engineering, Security, and Legal teams to integrate GRC requirements into operations and technology. You will develop and maintain comprehensive documentation including policies, procedures, and controls. Technical responsibilities include utilizing scripting and coding skills to automate GRC processes and implement compliance-as-code or policy-as-code solutions.
Additional duties include monitoring regulatory changes and industry trends to drive continuous improvement of the GRC program, providing training and guidance to internal teams and customers on compliance topics, and serving as a subject matter expert providing strategic advice to senior management.
Required qualifications: Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or equivalent experience. Minimum 5 years in GRC, cybersecurity, or related fields with focus on highly regulated industries. Proven experience achieving and maintaining FedRAMP, CMMC, SOC 2, IRAP, ISO 27001, or similar certifications. Strong understanding of public sector and highly regulated vertical compliance requirements. Familiarity with compliance-as-code, policy-as-code, and automating control testing. Basic FedRAMP knowledge and familiarity with cloud hyperscaler services (AWS, GCP, etc.). Excellent analytical, problem-solving, and project management skills. Strong communication and interpersonal abilities. Must be a United States Citizen and based in the United States due to government requirements.