Base Salary
$168k - $238k/yr
Responsibilities
- Design enterprise-scale identity, privileged access, AI access, and non-human identity governance solutions.
- Replace low-code and iPaaS automation with modular, tested, code-reviewed Python services deployed on GCP Cloud Run or an equivalent serverless runtime.
- Migrate Okta, Lumos, and non-human identity platform configuration from click-ops to peer-reviewed infrastructure-as-code using Terraform, OpenTofu, or Pulumi.
- Re-architect identity and access across GCP and AWS organizations, including resource hierarchies, organization policies, SCPs, permission boundaries, and workload identity federation.
- Lead administration, SSO, SCIM integration, audit logging, data controls, and policy enforcement for enterprise AI platforms.
- Design monitoring and management for service accounts, API keys, certificates, AI agents, and MCP integrations.
- Lead cross-functional technical initiatives and translate ambiguous business needs into actionable specifications.
- Write technical proposals, review designs and code, and mentor senior and intermediate engineers.
Requirements
- Extensive experience designing and implementing enterprise-scale IAM solutions, including experience at a Staff or senior individual-contributor level.
- Expertise with Okta Identity Engine, advanced authentication policies, lifecycle workflows, and API automation.
- Strong Terraform, OpenTofu, or Pulumi experience, including SaaS identity platform providers and migration from click-ops to code.
- Proficiency writing and shipping modular, tested, code-reviewed Python services with deployment and observability practices.
- Deep cloud identity experience in GCP and/or AWS, including organization design, IAM policy models, workload identity federation, organization policies, SCPs, and permission boundaries.
- Hands-on experience administering or governing enterprise AI platforms; Anthropic Claude is preferred, while OpenAI ChatGPT Enterprise, Google Gemini Enterprise, or similar platforms are acceptable.
- Awareness of AI-specific risks including prompt injection, MCP attack surfaces, agent identity, and data leakage.
- Practical experience using agentic AI tools such as Claude Code, Cursor, or similar tools in daily engineering work.
- Experience with IGA platforms such as Lumos, ConductorOne, or similar platforms.
- Experience in regulated environments and knowledge of FedRAMP, SOC 2, or SOX compliance, including change management, evidence collection, and audit support.
- Knowledge of AI agent governance, non-human identity management, zero-trust architecture, or behavioral analytics is preferred.
- Experience completing a cloud organization restructuring, including migration and stakeholder work, is preferred.
Benefits
- Health, financial, and well-being benefits.
- Flexible paid time off.
- Team Member Resource Groups.
- Equity compensation and an Employee Stock Purchase Plan.
- Growth and Development Fund.
- Parental leave.
- Fully remote work, subject to country and location eligibility requirements.
Tech Stack
Categories
About GitLab
GitLab is the Intelligent Orchestration Platform where software teams and their AI agents stay in flow to amplify their capacity for innovation. Together, they automate repetitive tasks to plan, build, secure, test, deploy and maintain software. With GitLab, software teams spend less time on coordination overhead and more time on the next big idea. GitLab Duo Agent Platform provides AI agents that automate tasks across the software lifecycle. Agents handle code generation, security analysis, code review, CI/CD troubleshooting, and custom workflows — while teams maintain control through enterprise governance. Build what's next with us. Explore open roles and join our talent community: https://about.gitlab.com/jobs/