Principal Security Awareness & Human Risk Engineer

GitLab
Canada, United Kingdom, United States
Workplace: RemoteFull timeUSD 203,200 - 275,000 annuallyFunction: Legal, Risk & ComplianceExperience: 10+ yearsSkills: ["Behavior change","Instructional design","Influence without authority","Vendor management","Making complex topics engaging"]

Own and evolve GitLab’s global security awareness and education program, driving measurable behavior change and sustained security culture. Lead end-to-end phishing simulations and targeted follow-ups, applying behavior change principles to reinforce secure habits. Manage training and phishing platforms, define performance indicators, and oversee vendor relationships for phishing, OWASP secure coding training, and video production. Coordinate audit evidence and track remediation of human-risk gaps through closure.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
GitLab
GitLab
1 day ago

Principal Security Awareness & Human Risk Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 10 hours agoStatus: Live

Job Summary

Own and evolve GitLab’s global security awareness and education program, driving measurable behavior change and sustained security culture. Lead end-to-end phishing simulations and targeted follow-ups, applying behavior change principles to reinforce secure habits. Manage training and phishing platforms, define performance indicators, and oversee vendor relationships for phishing, OWASP secure coding training, and video production. Coordinate audit evidence and track remediation of human-risk gaps through closure.
Location: Canada, United Kingdom, United States
Workplace: Remote
Employment Type: Full time
Job Function: Legal, Risk & Compliance

Key Responsibilities

  • •Own and evolve GitLab’s global security awareness and education program across annual, new-hire, role-based, targeted, executive, and microlearning content
  • •Run phishing simulations end to end, including design, deployment, analysis, and targeted follow-up
  • •Apply behavior change principles to reinforce secure habits and address priority human risk behaviors
  • •Administer training and phishing platforms and own program data and reporting end to end
  • •Own vendor relationships and coordinate audit evidence, control effectiveness, and remediation tracking to closure

Pay and Benefits

Salary: USD 203,200 - 275,000 annually
Perks:Paid LeaveParental LeaveEquityLearning Budget

Key Requirements

  • •10+ years building or scaling global security awareness and human-risk programs with measurable outcomes in a large, distributed enterprise
  • •SANS Security Awareness Professional (SSAP) certification or equivalent demonstrated expertise in building and measuring a mature awareness program
  • •Experience running enterprise-scale phishing programs and organization-wide awareness campaigns
  • •Ability to evaluate and select security training vendors, including cost/value analysis and vendor consolidation or replacement
  • •Instructional design experience and working knowledge of security policy development, audit support, and control evidence
Experience:10+ yearsEnterprise securityGlobal awarenessRegulated industry
Skills:Behavior changeInstructional designInfluence without authorityVendor managementMaking complex topics engaging
Certifications:SANS Security Awareness Professional (SSAP)
Languages:English
Tech Stack:OWASP

Company Brief

GitLab
Provides a single application for the complete DevSecOps lifecycle, offering source code management, CI/CD, security, and collaboration tools to help teams deliver software faster and more securely.
Industry: Developer Tools
Company Size: Enterprise (1,001+ employees)
Revenue: USD 250M to 500M
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: San Francisco, United States
Founded: 2011
WebsiteLinkedIn