SlipstreamJobsFresh Startup & VC-Backed Jobs

Senior Security Risk Engineer

GitLab - Remote - Remote - posted 2026-09-29

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 139,200 - 189,000 / annual

GitLab is seeking a Senior Security Risk Engineer to join the Security Risk function within the Security Assurance organization. This role is responsible for reducing risk across the security division through third-party risk management (TPRM), annual security risk assessments, quarterly risk reporting, and remediation of security findings. You will take ownership of risk identification, quantification, and remediation tracking across the business, serving as a driving force behind automating and modernizing risk workflows using AI and scripting. Reporting to the Security Risk Manager, you will bring expertise in risk methodology, risk-based thinking, and AI-enablement. Key responsibilities include: - Own risk identification, analysis, and prioritization across third-party risk (TPRM), security risk assessments, and security findings using established risk frameworks (NIST RMF, ISO 31000, NIST 800-39) - Translate technical vulnerabilities, control gaps, and risk findings into clear, quantified risk statements for non-security stakeholders and leadership - Drive remediation of findings and risk exceptions to closure, partnering with Engineering, IT, Product, and Legal teams - Mature and maintain a risk register and quarterly reporting cadence providing leadership visibility into open risk, remediation progress, and trends - Own and mature AI risk management, including AI impact assessments, AI risk assessments, and risk treatments to support ISO 42001 certification - Design, develop, and implement key risk indicators and supporting metrics for top risks - Identify manual, repetitive steps in risk and TPRM workflows and personally build automation, scripting, or AI-enabled tooling to eliminate them - Contribute to the risk program roadmap, incorporating new frameworks, regulatory changes, and lessons learned - Monitor internal and external risk landscape to identify and escalate emerging risks You will partner closely with Security, Legal, IT, Product, and Engineering to translate technical findings and vendor risk into business-relevant risk statements and treatments. REQUIREMENTS: - 5+ years of experience in security risk management, working with security-centric risk management or compliance frameworks (NIST RMF, NIST 800-39, ISO 31000). Familiarity with AI governance frameworks (ISO 42001, NIST AI RMF) is a plus. - Experience designing and executing qualitative and quantitative risk analyses that translate technical risks into measurable business impact - Track record of driving risk assessments, risk registers, and remediation efforts to closure across IT, Procurement, Internal Audit, Legal, Product, and Engineering in heavily regulated or multi-entity environments - Experience interpreting technical control requirements and translating them for both technical and non-technical stakeholders - Demonstrated bias toward automation: personally built scripts, workflows, or AI-enabled tooling that reduced manual risk or GRC work - Comfort operating with ambiguity, managing multiple concurrent assessments, and reprioritizing under tight deadlines - Exceptional written and verbal communication skills with demonstrated ability to translate security risks into business risks - Strong understanding of cloud security, SaaS security models, and DevSecOps practices - Relevant certifications (CISSP, CISM, CISA, CRISC) preferred but not required

Similar roles