Staff Security Governance Engineer, Policies & Standards
GitLab · Remote, United States
About this role
**GitLab — Staff Security Governance Engineer, Policies & Standards** ## Overview Own how GitLab writes, maintains, communicates, and measures its security policies and standards. Turn emerging regulations (including AI regulation) into clear, actionable requirements for Engineering, Product, and Legal—using automation to keep governance lightweight and continuous. You’ll sit on the **Security Governance** team within **Security Assurance**, working closely with **Security Compliance, Security Risk, and GRC Engineering**. Reports to the **Director, Customer Trust & Security Governance**. ## What you’ll do ### Policies and standards - Own the end-to-end lifecycle of GitLab security policies, standards, procedures, and guidelines (drafting, review, approval, publication, annual review, retirement). - Define and run the exception management process (risk-based approvals, expiry tracking, and trend reporting). - Run policy attestation and investigate non-adherence. - Keep policies clear, practical, and aligned with how GitLab engineering teams operate in a DevSecOps environment. ### Regulatory and framework alignment - Monitor emerging regulations and standards (e.g., **EU AI Act, NIST AI RMF, ISO 42001**, plus sector/regional requirements) and partner with Legal ahead of deadlines. - Maintain mappings between GitLab policies and frameworks such as **SOC 2, ISO 27001, ISO 42001, FedRAMP, and NIST CSF**—write once, reuse everywhere. ### Measurement and assurance - Define KPIs for policy adherence and report trends to Security leadership. - Run targeted internal adherence assessments and drive remediation to closure. - Support audit activities by coordinating evidence, testing, and remediation management. ### Customer trust - Support customer questionnaires and meetings. - Turn recurring customer requests into improved policies and self-service content. ### Automation and AI - Identify and implement automation and AI-assisted workflows for policy management, evidence collection, control monitoring, and assessments (with GRC Engineering). ### Technical leadership - Act as a technical/program leader across Security, Product, Legal, and Engineering—driving outcomes without direct authority. - Mentor team members and help set the Security Governance roadmap direction. ## What you’ll bring - **10+ years** in security governance, GRC, or IT risk, with hands-on ownership of policy/standards lifecycle and measurable outcomes (global tech company experience preferred). - Working knowledge of **SOC 2, ISO 27001, ISO 42001, FedRAMP, and NIST CSF**—practical application, not just familiarity. - Understanding of **cloud, SaaS, and DevSecOps**; ability to write policy engineers will follow. - Risk-based mindset balancing compliance with real security risk. - Demonstrated use of automation or AI to reduce manual GRC work. - Strong written and verbal communication (translate technical concepts for engineers, executives, auditors, and customers). - Experience collaborating across Security, Product, Legal, and Engineering. - Certifications like **CISSP, CISM, CISA** (or similar) are highly desirable. ## What success looks like - **First 30 days:** Assess current policy library and exception process, build stakeholder relationships, propose a prioritized roadmap. - **First 90 days:** Uplift the security policy library to align with **NIST CSF, ISO 27001/27017/27018/42001, and PCI-DSS**. - **First 120 days:** Refreshed review cadence in place, exceptio
Listing freshness
CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.