4 days ago
Remote, United States +4 moreStaff+
Base Salary
$168k - $238k/yr
Responsibilities
- Partner with engineering and product leadership to anticipate and address security problems across GitLab product domains.
- Lead security architecture and design for strategic initiatives and provide direction to cross-functional delivery teams.
- Own high-priority product security risks and co-execute remediation with the teams responsible for the code.
- Create reusable security guardrails, standards, design patterns, skills, and threat models for developer and AI coding workflows.
- Build proofs of concept and prototypes that translate security requirements into working implementations.
- Conduct security architecture reviews and coordinate with Application Security for comprehensive review coverage.
- Threat model systems and establish patterns that enable engineering teams to perform their own threat modeling.
- Explore unknown architectural risks with Security Research, anticipate emerging challenges, mentor security engineers, and represent security architecture to engineering audiences.
Requirements
- Deep experience in application security architecture, including authentication, authorization, privilege escalation, multi-tenant isolation, and trust boundary analysis.
- Experience securing distributed systems, including service-to-service authentication, secrets handling, and cross-process security failure modes.
- Working knowledge of software supply chain security, build and release integrity, artifact provenance, and dependency risk.
- Track record of proactive architecture work that prevents classes of security problems before incidents occur.
- Ability to build trusted relationships with engineering leadership and influence technical direction through expertise.
- Experience defining security standards or patterns that engineering teams adopted voluntarily.
- Ability to operate strategically while reading unfamiliar code, building prototypes, and contributing changes.
- Clear written communication and ability to explain security arguments to engineering audiences.
- Perspective on authoring and delivering security guidance for AI coding tools.
Benefits
- Fully remote work arrangement, with location-based eligibility requirements possible.
- Benefits supporting health, finances, and well-being.
- Flexible paid time off.
- Team Member Resource Groups.
- Equity compensation and Employee Stock Purchase Plan.
- Growth and Development Fund.
- Parental leave.
Categories
About GitLab
GitLab builds a DevSecOps platform that unifies source code management, CI/CD, and security with AI-assisted workflows for software teams and enterprises. It sells cloud-hosted and self-managed subscriptions, plus enterprise features and support. Founded in 2014 and headquartered in San Francisco, GitLab is a public company listed on NASDAQ and is widely used by large enterprises, including many in the Fortune 100.
