Senior Security Compliance Engineer, Public Sector

GitLab
United States
Workplace: RemoteFull timeUSD 139,200 - 196,000 annuallyFunction: Government & Public AdministrationExperience: 5+ yearsEducation: bachelorsSkills: ["Analytical thinking","Problem-solving","Project management","Communication","Independent work"]

Support the Public Sector Compliance team by developing and executing GRC strategies and processes for highly regulated environments. Lead security assessments, audits, and certification activities (including FedRAMP continuous monitoring), and tailor compliance requirements for GitLab Dedicated and self-managed offerings. Partner cross-functionally with IT, Product, Engineering, Security, and Legal, automate evidence/control testing with compliance-as-code or policy-as-code, and continuously track regulatory changes to mature the compliance program.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
GitLab
GitLab
1 day ago

Senior Security Compliance Engineer, Public Sector

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 19 hours agoStatus: Live

Job Summary

Support the Public Sector Compliance team by developing and executing GRC strategies and processes for highly regulated environments. Lead security assessments, audits, and certification activities (including FedRAMP continuous monitoring), and tailor compliance requirements for GitLab Dedicated and self-managed offerings. Partner cross-functionally with IT, Product, Engineering, Security, and Legal, automate evidence/control testing with compliance-as-code or policy-as-code, and continuously track regulatory changes to mature the compliance program.
Location: United States
Workplace: Remote
Employment Type: Full time
Job Function: Government & Public Administration
Seniority: Mid level

Key Responsibilities

  • •Develop, implement, and manage GRC strategies and processes aligned to regulatory and industry standards such as FedRAMP and IRAP.
  • •Partner with highly regulated customers to understand compliance requirements and provide tailored solutions for certifications and frameworks.
  • •Lead security assessments, audits, and certification processes to ensure timely and successful completion.
  • •Support ongoing FedRAMP continuous monitoring commitments for GitLab Dedicated for Government.
  • •Use scripting/coding skills to automate GRC processes with compliance-as-code or policy-as-code, and update the program based on regulatory and industry changes.

Pay and Benefits

Salary: USD 139,200 - 196,000 annually
Equity and Bonus:Equity
Perks:Paid LeaveEquityParental Leave

Key Requirements

  • •Valid proof of US citizenship and residency, and must be based in the United States.
  • •Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or equivalent experience.
  • •Minimum 5 years of experience in GRC, cybersecurity, or a related field focused on highly regulated industries.
  • •Proven experience achieving and maintaining security certifications such as FedRAMP, CMMC, SOC 2, IRAP, ISO 27001, or similar.
  • •Experience implementing compliance-as-code or policy-as-code, automating control testing and evidence collection; relevant certifications (e.g., CISSP, CISM, CISA) are desirable.
Experience:5+ yearsPublic sectorHighly regulated industries
Education:Bachelor's in Computer Science, Information Technology, Cybersecurity
Skills:Analytical thinkingProblem-solvingProject managementCommunicationIndependent work
Certifications:FedRAMPCMMCSOC 2IRAPISO 27001CISSPCISMCISA
Tech Stack:FedRAMPCMMCSOC 2IRAPISO 27001Compliance-as-codePolicy-as-codeAWSGCP

Eligibility

Nationality:US National

Company Brief

GitLab
Provides a single application for the complete DevSecOps lifecycle, offering source code management, CI/CD, security, and collaboration tools to help teams deliver software faster and more securely.
Industry: Developer Tools
Company Size: Enterprise (1,001+ employees)
Revenue: USD 250M to 500M
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: San Francisco, United States
Founded: 2011
WebsiteLinkedIn