CronJobs

security jobs

Senior Security Assurance Engineer

GitLab · Remote, United States

remotesenior$139,200–$139,200Posted Sep 3, 2026SOX ITGCISO 27001SOC 2NIST CSFIdentity & Access ManagementGitLabCloud SecurityCompliance Automation

Apply on the employer site

About this role

**Senior Security Assurance Engineer** **About the Role** GitLab's Security Assurance organization is seeking a Senior Security Assurance Engineer to design, test, and evidence controls that protect the business. This role operates the technology compliance program across systems critical to financial reporting, security commitments, customer contracts, and regulatory obligations—including IT-owned corporate applications, Corporate Security tooling, Engineering-owned business operations systems, and third-party SaaS platforms. **Key Responsibilities** • Design, document, and maintain IT General Controls and security controls across the in-scope estate • Map shared controls to serve multiple compliance obligations (SOX, SOC 2, ISO 27001, ISO 42001, NIST CSF, PCI-DSS, privacy regulations) • Serve as compliance liaison for IT, Corporate Security, Engineering, and Finance teams • Set standards for governed AI use across corporate and business systems • Partner on corporate security policy work and standards development • Run recurring compliance monitoring (access reviews, privileged access, change management) • Assess system implementations and migrations for control readiness • Manage SOX ITGC testing and external audit requests • Identify, track, and lead remediation of control deficiencies **Required Experience** • 5+ years in IT compliance, security compliance, IT audit, information security, or IT (BA/BS in business/technology or equivalent) • Demonstrated control testing experience against COSO, COBIT, NIST CSF, ISO 27001, SOC 2, SOX ITGC • Experience assessing controls in SaaS and cloud-native application stacks • Working knowledge of identity and access management (SSO, SCIM, RBAC, privileged access) • Familiarity with AI governance concepts and control implications • Experience contributing to security policies and standards • Understanding of data flows between billing, subscription, and financial reporting systems • Exceptional written and verbal communication skills • Ability to use GitLab or willingness to learn **Nice to Haves** CISA, CISSP, CRISC, or CISM certifications; experience with usage-based billing or subscription management systems; compliance automation and continuous control monitoring; ISO 42001 or NIST AI RMF experience; prior Security Assurance or GRC role supporting both corporate IT and product engineering. **Compensation** $139,200 – $196,000 USD (base salary for US residents) **What GitLab Offers** Comprehensive benefits, flexible PTO, team member resource groups, equity compensation, growth and development fund, and more.

Listing freshness

CronJobs last confirmed this listing 19h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.

Browse all software engineering jobs →

Follow fresh jobs in Discord