Senior Security Compliance Engineer, Public Sector

GitLab

Confirmed live yesterday High trust
Remote

Quick summary

Work type
Remote
Location
Remote
Salary
$139,200–$196,000 / yr
Posted
7 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

Competitive pay

How this pay compares to similar roles

Similar $180k
This role $168k
$123k most similar roles pay here $230k

This role pays less than 58% of similar roles. Most pay $151,475–$208,800 — the shaded band above. At the midpoint, this role pays about $168k versus about $180k for comparable roles.

Based on 240 similar postings.

Employer

About GitLab

GitLab is an all-remote software company that develops an AI-powered DevSecOps platform combining source code management, CI/CD, security scanning, and project planning in a single application.

GitLab currently has 79 open roles on FindRole.

Listed pay typically runs $137,400–$213,600 across 61 roles with salary data.

Most-posted roles

View all roles at GitLab

At a glance

TL;DR · Senior Security Compliance Engineer, Public Sector

The Senior Security Compliance Engineer joins the Public Sector Compliance team within the Security Assurance department to advance customer trust and execute the compliance roadmap for GitLab Dedicated offerings. This role involves developing GRC strategies, managing security assessments, and overseeing audit processes to maintain certifications like FedRAMP, CMMC, IRAP, SOC2, and ISO 27001. The candidate will collaborate with cross-functional teams to integrate requirements into the technology stack while creating comprehensive policy documentation. Key responsibilities include automating GRC processes using scripting and coding skills to implement compliance-as-code or policy-as-code solutions. Essential qualifications include a background in cybersecurity for highly regulated verticals, familiarity with cloud hyperscaler services, and expertise in automated control testing. The role addresses the complex challenge of ensuring security compliance for government and highly regulated customers within the DevSecOps space.

What you'll do

  • Develop and manage GRC strategies to ensure compliance with FedRAMP, IRAP, SOC2, and ISO 27001 standards.
  • Lead security assessments, audits, and certification processes for public sector and highly regulated customers.
  • Manage ongoing FedRAMP continuous monitoring commitments for GitLab Dedicated for Government offerings.
  • Automate GRC processes by implementing compliance-as-code and policy-as-code solutions using scripting or coding skills.
  • Create and maintain comprehensive documentation including policies, procedures, and controls to support compliance initiatives.
  • Provide tailored compliance solutions and technical guidance to customers in highly regulated industries.
  • Monitor regulatory changes and industry trends to ensure the continuous improvement of the GRC program.
  • Act as a subject matter expert providing strategic advice on GRC issues to senior management and stakeholders.

What we're looking for

  • You must be a United States citizen and resident based in the United States.
  • A Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or equivalent experience is required.
  • Minimum of 5 years of experience in GRC, cybersecurity, or a related field within highly regulated industries.
  • Proven experience achieving and maintaining certifications such as FedRAMP, CMMC, IRAP, SOC2, and ISO 27001.
  • Familiarity with implementing compliance-as-code, policy-as-code, and automating control testing/evidence collection.
  • Basic knowledge of FedRAMP requirements, processes, and documentation is required.
  • Familiarity with cloud hyperscaler services such as AWS or GCP is required.
  • US citizenship and residency.

More like this

Similar roles

Senior Security Assurance Engineer

GitLab

Remote 8 days ago $139,200$196,000
SOX ITGC SOC 2 ISO 27001 NIST CSF PCI-DSS ISO 42001 SSO SCIM RBAC GitLab SaaS AI Governance GRC
5+ yrs exp Remote

Staff Infrastructure Security Engineer

GitLab

Remote 9 days ago $168,000$238,000
FedRAMP Kubernetes Terraform Ansible CloudFormation Python Go Ruby AWS GCP Azure Infrastructure-as-Code Policy-as-Code NIST 800-53 FIPS 140-2/3 ISO 27001 SOC 2 PCI-DSS DevSecOps Threat Modeling
Remote

Staff Security Engineer, GRC

Oscar Health

New York, NY 21 days ago $245,916$286,902
GRC NIST SP 800-53 AWS Azure Compliance-as-Code Infrastructure-as-Code Policy-as-Code CMS EDE FedRAMP Risk Assessment Audit Readiness Security Engineering Cloud Security Posture Management SIEM Configuration Management
7+ yrs exp Hybrid

Senior Security Engineer

Green Dot Corp

Los Angeles, CA 86 days ago $113,400$162,000
Azure Network Security Penetration Testing CI/CD DevSecOps Identity and Access Management (IAM) NIST CIS Benchmarks OWASP SSDLC Azure Firewall Network Security Groups Key Vault Firewalls
5+ yrs exp Hybrid

Senior Security Engineer

Green Dot Corp

Los Angeles, CA 86 days ago $113,400$162,000
Azure Network Security Penetration Testing CI/CD DevSecOps Identity and Access Management (IAM) NIST CIS Benchmarks OWASP SSDLC Azure Firewall Network Security Groups Key Vault Firewalls
5+ yrs exp Hybrid

Senior Security Engineer

Green Dot Corp

Los Angeles, CA 86 days ago $113,400$162,000
Azure Network Security Penetration Testing CI/CD DevSecOps Identity and Access Management (IAM) NIST CIS Benchmarks OWASP SSDLC Azure Firewall Network Security Groups Key Vault Defender Firewalls
5+ yrs exp Hybrid