139K–189K USD / year

Senior Security Risk Engineer

OtherRemote — Canada; United States
Published on 2026-09-29
These details were extracted automatically from the original listing. They may not be complete or fully up to date — it's worth checking the original job post.

About this role

The Senior Security Risk Engineer will be responsible for identifying and remediating security risks across the organization, focusing on third-party risks and security assessments. The role involves automating workflows using AI and collaborating closely with various departments to translate technical risks into business-relevant statements.

About the company

GitLab is a DevSecOps platform that brings source control, CI/CD, security, and project management into a single application. It helps engineering teams plan, build, secure, and ship software faster.

The team

Security Risk function

What you'll do

  • Own risk identification, analysis, and prioritization across security findings.
  • Translate technical vulnerabilities into quantified risk statements.
  • Drive remediation efforts in collaboration with various teams.
  • Maintain a risk register and reporting cadence.
  • Develop AI risk management practices to support ISO certification.
  • Identify and automate repetitive tasks in risk workflows.

What we're looking for

  • 5+ years in security risk management with related frameworks.
  • Experience with qualitative and quantitative risk analysis.
  • Track record of driving risk assessments to closure.
  • Ability to interpret technical requirements for diverse stakeholders.
  • Demonstrated bias toward automation and scripting.

Nice to have

  • Familiarity with AI governance frameworks.
  • Relevant security certifications (CISSP, CISM, CISA, CRISC).

Benefits

  • Flexible Paid Time Off
  • Equity Compensation & Employee Stock Purchase Plan
  • Growth and Development Fund
  • Parental Leave
View original job post