SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
GitLab is seeking a Staff Corporate Security Engineer to lead the security architecture and engineering of GitLab's endpoint fleet in a fully remote environment. This role sits within Corporate Security Engineering and focuses on building secure-by-default controls for endpoints and SaaS platforms, with a strong emphasis on macOS.
You will own meaningful technical decisions around endpoint hardening, automation, and detection, turning security requirements into scalable engineering systems that are measurable, auditable, and designed to reduce friction for end users. Working across endpoint management, identity, and security operations, you'll improve how GitLab manages macOS, iOS, Windows, and Linux devices through Infrastructure-as-Code, Terraform, and GitOps workflows.
Key responsibilities include: leading the security architecture of GitLab's endpoint fleet with primary focus on macOS; designing and supporting automation for secure endpoint deployment, configuration, and lifecycle management using code-based workflows; managing endpoint and SaaS security configuration through Terraform, version control, merge requests, and continuous integration pipelines; defining and enforcing security baselines across multiple platforms; developing patching and software distribution approaches; partnering with IT, Security Operations, and Detection teams to improve endpoint telemetry and detections; driving process improvements that reduce manual work through automation and policy-driven controls; and mentoring engineers across Corporate Security and IT as a senior escalation point for complex endpoint security issues.
Required experience includes designing and delivering endpoint, systems, or corporate security solutions in scalable environments; deep knowledge of endpoint management platforms such as Jamf Pro or FleetDM for macOS; strong hands-on ability with Terraform and Infrastructure-as-Code practices; experience with GitOps workflows; strong proficiency in scripting or programming (bash, Python, PowerShell, Go); familiarity with cloud identity providers (Okta, Google Workspace, LDAP); ability to communicate clearly and work independently in all-remote environments; and a practical, security-focused approach to problem solving.