Staff Security Engineer, IAM

GitLab

Confirmed live yesterday High trust
Remote

Quick summary

Work type
Remote
Location
Canada
Salary
$168,000–$238,000 / yr
Posted
11 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

Above market

How this pay compares to similar roles

Similar $185k
This role $203k
$119k most similar roles pay here $251k

This role pays more than 70% of similar roles. Most pay $157,707–$212,000 — the shaded band above. At the midpoint, this role pays about $203k versus about $185k for comparable roles.

Based on 240 similar postings.

Employer

About GitLab

GitLab is an all-remote software company that develops an AI-powered DevSecOps platform combining source code management, CI/CD, security scanning, and project planning in a single application.

GitLab currently has 79 open roles on FindRole.

Listed pay typically runs $137,400–$213,600 across 61 roles with salary data.

Most-posted roles

View all roles at GitLab

At a glance

TL;DR · Staff Security Engineer, IAM

Staff Security Engineer, IAM joins the Corporate Security Identity Team to lead the transition from manual configurations to automated, code-based identity governance. This role involves designing scalable access solutions for human and non-human identities, building Python services on GCP Cloud Run, and codifying infrastructure using Terraform, OpenTofu, or Pulumi. The engineer will manage Okta, Lumos, and various enterprise AI platforms like Anthropic Claude while re-architecting identity across GCP and AWS environments to ensure least privilege. Key responsibilities include mentoring engineers, drafting technical proposals, and managing complex projects involving IGA platforms in regulated environments. The ideal candidate possesses deep expertise in IAM policies, infrastructure-as-code, and cloud security controls. They must be proficient in Python and experienced in securing AI tools against risks like prompt injection while navigating compliance frameworks such as FedRAMP and SOC2.

What does a Security Engineer earn?

Median $185250 from 84 postings across 39 companies.

See salary data

What you'll do

  • Design scalable identity and AI access solutions including just-in-time provisioning and governance frameworks for AI agents.
  • Replace low-code automation with engineered Python services deployed on GCP Cloud Run with full CI/CD and observability.
  • Codify identity platforms like Okta and Lumos using Terraform, OpenTofu, or Pulumi to move from click-ops to infrastructure-as-code.
  • Re-architect cloud identity across GCP and AWS by implementing resource hierarchies, guardrails, and workload identity federation.
  • Manage enterprise AI platform security including SSO integration, audit logging, and policy enforcement for tools like Claude.
  • Pioneer non-human identity governance for service accounts, API keys, and certificates across the SaaS estate.
  • Translate ambiguous business requirements from cross-functional teams into actionable technical specifications and roadmap items.
  • Mentor senior and intermediate engineers on modern identity practices and strategic technical implementation.

What we're looking for

  • Extensive experience designing and implementing enterprise-scale IAM solutions at a Staff or senior IC level.
  • Expert-level Okta expertise including Identity Engine, advanced authentication policies, lifecycle workflows, and API automation.
  • Strong infrastructure-as-code practice using Terraform, OpenTofu, or Pulumi to migrate click-ops to code.
  • Proficiency in writing and shipping modular, tested Python services deployed on GCP Cloud Run or similar serverless runtimes.
  • Deep knowledge of cloud identity in GCP and/or AWS, including resource hierarchy, workload identity federation, and preventive controls.
  • Hands-on experience governing enterprise AI platforms and managing risks like prompt injection and data leakage.
  • Proven ability to use agentic AI tools in daily engineering workflows.
  • Experience in regulated environments with knowledge of compliance frameworks such as FedRAMP, SOC2, or SOX.

More like this

Similar roles

Staff Enterprise Security Engineer, AI Security

Twilio

Remote 16 days ago $155,520$194,400
Security Engineering Cloud Security Kubernetes Python Go Java AWS GCP Container Security Threat Modeling Data Protection AI Security Automation
7+ yrs exp Remote

Staff Security Engineer

Okta Inc

San Francisco, CA 43 days ago $134,000$184,800
DevSecOps AWS Snyk Semgrep Qualys Cyera CI/CD Security Posture Management SRE SDLC Secrets Management Infrastructure Security Automation Salesforce Google Workspace
10+ yrs exp

Staff Security Engineer

Okta Inc

San Francisco, CA 43 days ago $134,000$184,800
DevSecOps AWS Snyk Semgrep Qualys Cyera CI/CD Security Posture Management Secrets Management SDLC SRE Salesforce Google Workspace Slack Zoom Infrastructure Security
10+ yrs exp

Senior IAM Automation Engineer

Apex

Austin, TX 149 days ago $108,800$136,000
Okta Entra ID Tines Terraform Python PowerShell Go Active Directory Adaxes AWS IAM GCP Cloud Identity SAML OIDC SCIM CI/CD Ansible Workday ServiceNow Slack Teams M365
7+ yrs exp Hybrid

Principal Security Engineer, Identity and Access Management

Nordstrom

Seattle, WA 11 days ago $191,000$297,000
IAM Identity Governance Privileged Access Management PAM CIAM SSO OAuth 2.0 OpenID Connect SAML SCIM SPIFFE/SPIRE FIDO2 WebAuthn AWS IAM Azure Entra ID GCP IAM Zero Trust infrastructure-as-code CI/CD Identity Orchestration
10+ yrs exp Hybrid

Senior Security Engineer I, IAM

Oscar Health

New York, NY 56 days ago
Okta Google Workspace Identity AWS BigQuery SAML OAuth OIDC SCIM LDAP IAM SIEM SOAR UEBA ITDR
4+ yrs exp Hybrid