Senior Security Assurance Engineer

GitLab

Confirmed live 2 days ago High trust
Remote

Quick summary

Work type
Remote
Location
Remote
Salary
$139,200–$196,000 / yr
Posted
8 days ago
Freshness
Confirmed live 2 days ago

Market check

Salary context

Competitive pay

How this pay compares to similar roles

Similar $181k
This role $168k
$121k most similar roles pay here $231k

This role pays less than 55% of similar roles. Most pay $151,475–$209,725 — the shaded band above. At the midpoint, this role pays about $168k versus about $181k for comparable roles.

Based on 240 similar postings.

Employer

About GitLab

GitLab is an all-remote software company that develops an AI-powered DevSecOps platform combining source code management, CI/CD, security scanning, and project planning in a single application.

GitLab currently has 79 open roles on FindRole.

Listed pay typically runs $137,400–$213,600 across 61 roles with salary data.

Most-posted roles

View all roles at GitLab

At a glance

TL;DR · Senior Security Assurance Engineer

As a Senior Security Assurance Engineer within the Security Compliance team, you will manage the control framework for systems powering the business. You will design, document, and maintain IT General Controls and security controls across a diverse estate including corporate applications, identity infrastructure, and engineering-owned tools like billing and subscription systems. Your daily work involves mapping shared controls to satisfy multiple requirements such as SOX, SOC 2, ISO 27001, and NIST CSF from a single evidence base. You will also establish standards for the governed use of AI across corporate systems and partner with governance teams on security policy development. Key technical competencies include experience with SaaS and cloud-native stacks, identity and access management (SSO, SCIM, RBAC), and automated evidence collection to streamline audits while ensuring compliance with various regulatory and contractual obligations.

What you'll do

  • Design, document, and maintain IT General Controls and security controls across the corporate and business systems estate.
  • Map shared controls to satisfy multiple regulatory frameworks including SOX, SOC 2, ISO 27001, and PCI-DSS from a single evidence base.
  • Establish standards and control requirements for the governed use of AI tools and integrations across company systems.
  • Perform recurring compliance monitoring for user access, privileged access, change management, and configuration baselines.
  • Advise engineering teams on control requirements during system implementations, migrations, and significant changes before go-live.
  • Manage SOX ITGC testing and coordinate evidence collection for internal and external audits while automating manual processes.
  • Identify and lead the remediation of control deficiencies and risks across the infrastructure.
  • Partner with Security Governance to develop and review corporate security policies and acceptable use standards.

What we're looking for

  • Hold a BA/BS degree in a business or technology field or possess equivalent experience.
  • Have 5+ years of experience in IT compliance, security compliance, IT audit, information security, or information technology.
  • Demonstrate experience testing and documenting controls against frameworks like COSO, COBIT, NIST CSF, ISO 27001, SOC 2, and SOX ITGC.
  • Possess experience assessing controls within SaaS and cloud-native application stacks.
  • Maintain working knowledge of identity and access management including SSO, SCIM, RBAC, and privileged access.
  • Demonstrate familiarity with AI governance concepts and the control risks associated with AI tools and integrations.
  • Experience contributing to security policies, standards, and procedures in partnership with a governance function.
  • Possess exceptional written and verbal communication skills for interacting with leadership, engineering teams, auditors, and legal counsel.

More like this

Similar roles

GRC Engineer

Apex

Austin, TX +6 15 days ago
SOC 2 NIST CSF ISO 27001 PCI DSS GLBA SQL Python API Anecdotes Vanta Drata Secureframe OneTrust ServiceNow GRC AWS Azure GCP IAM SIEM
2+ yrs exp Hybrid

SOX Compliance Lead

HP Inc.

Vancouver, WA 121 days ago $105,050$161,800
SOX ITGC SDLC ICOFR SOC2 ISO 27001 NIST CSF NIST AI RMF Agentic AI GitHub GDPR NIS2 DORA CISA CISM CRISC CISSP Risk Management
8+ yrs exp

Security GRC Analyst

Pinterest

Remote (San Francisco, CA) 7 days ago $123,696$254,667
SOC 2 CIS Controls ISO 27001 NIST CSF Risk Management Security Governance GRC Identity and Access Management Vulnerability Management Endpoint Security Third-party Risk Audit Support Control Testing Security Awareness Training
4+ yrs exp Remote

Senior Security Engineer

Green Dot Corp

Los Angeles, CA 86 days ago $113,400$162,000
Azure Network Security Penetration Testing CI/CD DevSecOps Identity and Access Management (IAM) NIST CIS Benchmarks OWASP SSDLC Azure Firewall Network Security Groups Key Vault Firewalls
5+ yrs exp Hybrid

Senior Security Engineer

Green Dot Corp

Los Angeles, CA 86 days ago $113,400$162,000
Azure Network Security Penetration Testing CI/CD DevSecOps Identity and Access Management (IAM) NIST CIS Benchmarks OWASP SSDLC Azure Firewall Network Security Groups Key Vault Firewalls
5+ yrs exp Hybrid

Senior Security Engineer

Green Dot Corp

Los Angeles, CA 86 days ago $113,400$162,000
Azure Network Security Penetration Testing CI/CD DevSecOps Identity and Access Management (IAM) NIST CIS Benchmarks OWASP SSDLC Azure Firewall Network Security Groups Key Vault Defender Firewalls
5+ yrs exp Hybrid