168K–238K USD / year

Staff Security Governance Engineer, Policies & Standards

OtherRemote — United States
Published on 2026-09-30
These details were extracted automatically from the original listing. They may not be complete or fully up to date — it's worth checking the original job post.

About this role

The Staff Security Governance Engineer will manage GitLab's security policies and standards, ensuring compliance with regulations and maintaining effective communication with engineering and product teams. The role includes monitoring emerging regulations, defining policy adherence metrics, and utilizing automation for efficiency.

About the company

GitLab is a DevSecOps platform that brings source control, CI/CD, security, and project management into a single application. It helps engineering teams plan, build, secure, and ship software faster.

The team

Security Governance team within Security Assurance

What you'll do

  • Own the policy lifecycle: drafting, review, publication, and retirement
  • Define and run the exception management process
  • Monitor emerging regulations and align policies accordingly
  • Define KPIs for policy adherence and report to leadership
  • Support customer trust through collaboration
  • Implement automation for policy management
  • Mentor team members
  • Influence security governance direction

What we're looking for

  • 10+ years in security governance, GRC, or IT risk
  • Knowledge of SOC 2, ISO 27001, FedRAMP, NIST CSF
  • Experience with cloud, SaaS, and DevSecOps practices
  • Strong written and verbal communication skills
  • Experience collaborating with cross-functional teams

Nice to have

  • Certifications such as CISSP, CISM, CISA
  • Experience with automation or AI in governance

Benefits

  • Flexible Paid Time Off
  • Equity Compensation & Employee Stock Purchase Plan
  • Growth and Development Fund
  • Parental Leave
View original job post