SlipstreamJobsFresh Startup & VC-Backed Jobs

Staff Infrastructure Security Engineer (USA)

GitLab - Remote - Remote - posted 2026-09-02

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

GitLab is seeking a Staff Infrastructure Security Engineer to serve as the technical lead for infrastructure security of GitLab Dedicated for Government and the broader FedRAMP environment. In this role, you will define the technical direction for securing the Federal platform, establish security patterns and automation, and influence how those patterns extend across GitLab's SaaS and Self-Managed offerings. You will own the security posture of GitLab's FedRAMP environment as the senior technical voice, partnering closely with the Public Sector SRE team. Key responsibilities include setting architectural patterns and reference implementations for infrastructure security, leading comprehensive security reviews and threat modeling for complex Federal infrastructure components, and identifying systemic risks across affected systems. You will scope and lead multi-quarter infrastructure security initiatives from problem framing through delivery, including FedRAMP continuous monitoring, control implementation, and authorization-impacting changes. As an authoritative technical voice, you will translate architectural tradeoffs and FedRAMP control implications into clear decisions for engineering, compliance, and senior leadership stakeholders. You will establish GitLab's approach to AI-assisted security engineering within FedRAMP constraints, identifying where AI can increase leverage and establishing patterns for team adoption. Additionally, you will mentor and develop engineers on the team, raising the technical bar and modeling inclusive collaboration. This role requires expert knowledge of cloud infrastructure security (AWS/GCP/Azure), container orchestration (Kubernetes), and deep working knowledge of FedRAMP (Moderate and High) with operational experience running and continuously monitoring authorized environments. You must be a U.S. citizen and based in the United States due to government requirements.

Similar roles