SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 168,000 - 238,000 / annual
GitLab is seeking a Staff Security Governance Engineer to own the end-to-end lifecycle of security policies, standards, procedures, and guidelines. This is an individual contributor role within the Security Assurance organization, reporting to the Director of Customer Trust & Security Governance.
You will be responsible for drafting, stakeholder review, approval, publication, annual review, and retirement of security policies. You will define and run the exception management process, including risk-based approvals, expiry tracking, and trend reporting. You will conduct policy attestation, investigate non-adherence, and keep policies clear and practical for GitLab's DevSecOps environment.
Key responsibilities include monitoring emerging regulations and standards (EU AI Act, NIST AI RMF, ISO 42001, sector/regional requirements) and partnering with Legal to assess impact and update policy ahead of compliance deadlines. You will maintain mappings between GitLab's policies and frameworks such as SOC 2, ISO 27001, ISO 42001, FedRAMP, and NIST CSF to ensure requirements are written once and reused.
You will define KPIs for policy adherence, report trends to Security leadership, run targeted internal assessments, and support audit activities through evidence coordination and remediation management. You will support customer questionnaires and meetings, turning recurring customer requests into better policies and self-service content.
You will identify and implement automation and AI-assisted workflows for policy management, evidence collection, control monitoring, and assessment work in partnership with GRC Engineering. You will act as a technical and program leader across Security, Product, Legal, and Engineering, influencing without direct authority, mentoring team members, and helping set the Security Governance roadmap direction.
The team is small (four direct reports under the Director) with broad scope and visible impact. Work is remote-first and asynchronous, with policies and standards drafted and revised openly with input from Security, Legal, Product, and Engineering.
Success milestones: First 30 days—assess current policy library and exception process, build stakeholder relationships, propose prioritized roadmap. First 90 days—uplift security policy library to align with NIST CSF, ISO 27001/27017/27018/42001, and PCI-DSS. First 120 days—implement refreshed review cadence, run exception reporting, demonstrate measurable improvement in policy adherence. First six months—develop Policy as Code and collaborate on implementation into existing workflows.
REQUIREMENTS:
- 10+ years in security governance, GRC, or IT risk with hands-on ownership of policy and standards lifecycle and measurable outcomes, ideally at a global technology company
- Working knowledge of SOC 2, ISO 27001, ISO 42001, FedRAMP, and NIST CSF, including practical implementation experience
- Understanding of cloud, SaaS, and DevSecOps practices with ability to write policy that engineers will follow
- Risk-based mindset that balances compliance with real security risk
- Demonstrated use of automation or AI to reduce manual GRC work
- Strong written and verbal communication, including translating technical concepts for engineers, executives, auditors, and customers
- Experience collaborating with Security, Product, Legal, and Engineering
- Certifications such as CISSP, CISM, CISA, or similar are highly desirable