Job Closed

This listing is no longer active.

GitLab logo
GitLab

Build software faster. The One DevOps Platform enables your entire org to collaborate around your code. We're hiring.

Manager, Infrastructure Security (USA)

Security EngineerSecurity EngineerFull TimeRemoteMid LevelTeam 1,001-5,000Since 2014H1B No SponsorCompany SiteLinkedIn

Location

United States

Posted

73 days ago

Salary

$140K - $225K / year

Seniority

Mid Level

Job Description

Manager, Infrastructure Security (USA)

GitLab

GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50 million registered users and more than 50% of the Fortune 100* trust GitLab to ship better, more secure software faster. The same principles built into our products are reflected in how our team works: we embrace AI as a core productivity multiplier, with all team members expected to incorporate AI into their daily workflows to drive efficiency, innovation, and impact. GitLab is where careers accelerate, innovation flourishes, and every voice is valued. Our high-performance culture is driven by our values and continuous knowledge exchange, enabling our team members to reach their full potential while collaborating with industry leaders to solve complex problems. Co-create the future with us as we build technology that transforms how the world develops software. *Fortune 500® is a registered trademark of Fortune Media IP Limited, used under license. Claim based on GitLab data. Fortune 100 refers to the top 20% ranked companies in the 2025 Fortune 500 list, published in June 2025. Fortune and Fortune Media IP Limited are not affiliated with, and do not endorse products or services of GitLab. An overview of this roleAs a Manager on the Infrastructure Security Team within the Product Security Department you will work with teams across GitLab to ensure that the components comprising our cloud infrastructure are built with the resiliency and security expectations that our customers depend on to power their software factories. You’ll lead and develop a high-performing team focused on securing GitLab’s internal cloud infrastructure (e.g. internal tooling and Sandbox) and our FedRAMP-authorized SaaS offering, GitLab Dedicated for Government. You’ll redefine the benchmark for Infrastructure Security through relentless advocacy of our Core Values and Dogfooding. You’ll maintain strong partnerships with peers across GitLab (e.g. Infrastructure, Finance, Product, and Legal) to ensure that the team can contribute effectively to cross-functional initiatives, building security in from the foundation upward. When required, you’ll leverage your extensive infrastructure experience and conflict resolution skills to unblock decisions. You’ll collaborate with the Product Security Leadership to develop and refine the Infrastructure Security vision and strategic roadmap. What you’ll do - Contribute to the Infrastructure Security team’s vision and strategic roadmap - Serve as a stable counterpart to teams such as Public Sector SRE, providing infrastructure security guidance and partnership - Provide professional guidance and input on infrastructure security within and outside of your team - Collaborate with other security teams in support of cross-team security efforts, process improvements, and driving down risk across the organization - Build collaborative cross-functional partnerships with teams across Infrastructure Engineering, Engineering and Development, Product Management, and Legal - Manage an existing high-performing team of infrastructure security professionals and hire new members as appropriate - Lead and mentor your team by helping grow their skills and experience, fostering a culture of continuous improvement, holding regular 1:1s, and being your team’s role model in exemplifying GitLab company values - Establish and implement security policies, procedures, standards, and guidelines in support of infrastructure security - Fulfill the Product Security Division Mission of securing GitLab Infrastructure with our own product (“dogfooding”) What you’ll bring - Hands-on public cloud security experience (GCP or AWS), ideally with SRE background - Practitioner-level CI/CD, Docker, Kubernetes, cloud-native, and serverless experience - Track record of leading and implementing infrastructure automation in service of security (e.g. Chef, Ansible, Terraform) - Experience managing infrastructure security in regulated environments (e.g. FedRAMP, PCI) - Solid grasp of the current threat landscape, distributed architectures, infrastructure-level systems design, and threat modeling - Strong written, verbal, and presentation skills across a range of stakeholders - Comfortable operating in a remote, async, distributed environment with ambiguity and shifting priorities - Experience managing and developing teams of 5+ - Alignment with GitLab's values and Leadership at GitLab manager responsibilities Due to government requirements, you must be a United States Citizen (defined as any individual who is a citizen of the United States by law, birth, or naturalization) to fill this position. The base salary range for this role’s listed level is currently for residents of the United States only. This range is intended to reflect the role's base salary rate in locations throughout the US. Grade level and salary ranges are determined through interviews and a review of education, experience, knowledge, skills, abilities of the applicant, equity with other team members, alignment with market data, and geographic location. The base salary range does not include any bonuses, equity, or benefits. See more information on our benefits and equity. Sales roles are also eligible for incentive pay targeted at up to 100% of the offered base salary. United States Salary Range $140,000—$225,000 USD How GitLab Supports Full-Time Employees - Benefits to support your health, finances, and well-being - Flexible Paid Time Off - Team Member Resource Groups - Equity Compensation & Employee Stock Purchase Plan - Growth and Development Fund - Parental leave - Home office support Please note that we welcome interest from candidates with varying levels of experience; many successful candidates do not meet every single requirement. Additionally, studies have shown that people from underrepresented groups are less likely to apply to a job unless they meet every single qualification. If you're excited about this role, please apply and allow our recruiters to assess your application. Country Hiring Guidelines: GitLab hires new team members in countries around the world. All of our roles are remote, however some roles may carry specific location-based eligibility requirements. Our Talent Acquisition team can help answer any questions about location after starting the recruiting process. Privacy Policy: Please review our Recruitment Privacy Policy. Your privacy is important to us. GitLab is proud to be an equal opportunity workplace and is an affirmative action employer. GitLab’s policies and practices relating to recruitment, employment, career development and advancement, promotion, and retirement are based solely on merit, regardless of race, color, religion, ancestry, sex (including pregnancy, lactation, sexual orientation, gender identity, or gender expression), national origin, age, citizenship, marital status, mental or physical disability, genetic information (including family medical history), discharge status from the military, protected veteran status (which includes disabled veterans, recently separated veterans, active duty wartime or campaign badge veterans, and Armed Forces service medal veterans), or any other basis protected by law. GitLab will not tolerate discrimination or harassment based on any of these characteristics. See also GitLab’s EEO Policy and EEO is the Law. If you have a disability or special need that requires accommodation, please let us know during the recruiting process.

Benefits

  • 401(K), 401(K) matching, Company equity, Company-sponsored outings, Continuing education stipend, Dedicated diversity and inclusion staff, Dental insurance, Disability insurance, Diversity manifesto, Documented equal pay policy, Volunteer in local community, Employee stock purchase plan, Family medical leave, Flexible Spending Account (FSA), Flexible work schedule, Generous parental leave, Generous PTO, Company-sponsored happy hours, Health insurance, Highly diverse management team, Job training & conferences, Life insurance, Mean gender pay gap below 10%, Mentorship program, Paid volunteer time, Online course subscriptions available, Paid holidays, Paid sick days, Partners with nonprofits, Performance bonus, Promote from within, Relocation assistance, Remote work program, Return-to-work program post parental leave, Team based strategic planning, OKR operational model, Continuing education available during work hours, Tuition reimbursement, Mandated unconscious bias training, Unlimited vacation policy, Vision insurance, Some meals provided, Mental health benefits, Home-office stipend for remote employees, Diversity employee resource groups, Hiring practices that promote diversity, Employee resource groups, President's club

Related Categories

Related Job Pages

More Security Engineer Jobs

Salesforce logo

Principal Security Engineer, SaaS Security Posture Management

Salesforce

👋 We're Salesforce, the customer company. CRM + Data + AI + Trust.

Full TimeRemoteTeam 10,001+Since 1999H1B Sponsor

• Lead the design, deployment, and lifecycle management of secure configuration baselines • Perform in-depth and high quality security assessments of third parties • Define and perform security assessments on emerging technologies provided by third parties • Act as the subject matter expert for SaaS-related security telemetry • Spearhead the use of Large Language Models (LLMs) and autonomous AI Agents • Provide guidance to team members and Salesforce suppliers on Salesforce security requirements • Build cross-functional partnerships with departments including Business, Sourcing, Legal, and Information Technology

California + 1 moreAll locations: California | Texas
$197.3K - $313.7K / year
Job Closed
Cotiviti logo

Senior Investigator (Healthcare FWA)

Cotiviti

Enabling a high-quality and viable healthcare system

Full TimeRemoteTeam 5,001-10,000H1B Sponsor

Overview As a Senior Investigator, you will investigate suspected incidents of healthcare fraud, waste, or abuse through data analysis (a high level of proficiency with Excel is required). This is not a physical investigator role. This role aligns with our pre-pay Fraud Waste & Abuse team. Responsibilities - Identify, investigate, analyze and evaluate instances of potential fraud, waste, and abuse. - Conduct interviews or correspond with patients, providers, witnesses or other relevant parties to determine settlement, denial or review. - Analyze information gathered by investigation and report findings and recommendations as a written summary and/or presentation. - Conducts investigation-related training. - Supports legal proceedings as needed, including testifying in court or working with law enforcement personnel to prepare cases for civil or criminal actions. - Negotiates settlement agreements to resolve disputes. - Maintain current knowledge of relevant laws, regulations and standards. - Participates in special projects as required. This job description is intended to describe the general nature and level of work being performed and is not to be construed as an exhaustive list of responsibilities, duties and skills required. This job description does not constitute an employment agreement and is subject to change as the needs of Cotiviti and requirements of the job change. Qualifications - Bachelor’s Degree in related discipline, or the equivalent combination of education, professional training and work experience. - 5-8 years of related investigative experience. - Advanced level skills in Excel. - Excellent verbal and written communication skills. - Strong listening and observation skills. - Attention to detail and high level of accuracy. - Effective organizational and prioritization skills with multi-tasking ability. - Preferred certifications: - Accredited Healthcare Fraud Investigator (AHFI), - Certified Fraud Specialist (CFS), - Certified Fraud Examiner (CFE), - Certified Forensic Interviewer (CFI), or - Certified in Healthcare Compliance (CHC). Job Demands: - This is a work-at-home position. Access to high-speed internet is required (all other equipment will be provided). - Must be able to sit and use a computer keyboard for extended periods of time. - Travel up to 15%. - Must have flexibility and willingness to participate in the work processes of an international organization, including conference calls scheduled to accommodate global time zones. - After hours and/or weekend work is required where necessary for major deliverables/deadlines (not consistent). Mental Requirements: - Communicating with others to exchange information. - Assessing the accuracy, neatness, and thoroughness of the work assigned. Physical Requirements and Working Conditions: - Remaining in a stationary position, often standing or sitting for prolonged periods. - Repeating motions that may include the wrists, hands, and/or fingers. - Must be able to provide a dedicated, secure work area. - Must be able to provide high-speed internet access/connectivity and office setup and maintenance. Base compensation ranges from $70,000 to $90,000 per year. Specific offers are determined by various factors, such as experience, education, skills, certifications, and other business needs. Cotiviti offers team members a competitive benefits package to address a wide range of personal and family needs, including medical, dental, vision, disability, and life insurance coverage, 401(k) savings plans, paid family leave, 9 paid holidays per year, and 17-27 days of Paid Time Off (PTO) per year, depending on specific level and length of service with Cotiviti. For information about our benefits package, please refer to our Careers page. Date of posting: 4/3/2026 Applications are assessed on a rolling basis. We anticipate that the application window will close on 6/3/2026, but the application window may change depending on the volume of applications received or close immediately if a qualified candidate is selected. #senior #LI-JB1 #LI-Remote

United States
$70K - $90K / year
Full TimeRemoteTeam 10,001+Since 1910H1B No Sponsor

• Responsible for the design, configuration, optimization, and ongoing support of Workday Security and Core HCM • Partner closely with HR and IT stakeholders • Manage core HCM setup configuration • Provide technical leadership by evaluating design options and proposing alternatives • Review and assess proposed changes to ensure alignment with security architecture and audit requirements • Contribute to ongoing system maintenance and business continuity

Illinois
$92K - $138K / year
Job Closed
ACV logo

Director, Product Security

ACV

ACV is a technology company that has revolutionized how dealers buy and sell cars online. We are transforming the automotive industry. ACV Auctions Inc. (ACV) has applied innovation and user-designed, data-driven applications and solutions. We are building the most trusted and efficient digital marketplace with data solutions for sourcing, selling, and managing used vehicles with transparency and comprehensive insights that were once unimaginable. We are disruptors of the industry and we want you to join us on our journey.

Full TimeRemoteTeam 1,001-5,000

If you are looking for a career at a dynamic company with a people-first mindset and a deep culture of growth and autonomy, ACV is the right place for you! Competitive compensation packages and learning and development opportunities, ACV has what you need to advance to the next level in your career. We will continue to raise the bar every day by investing in our people and technology to help our customers succeed. We hire people who share our passion, bring innovative ideas to the table, and enjoy a collaborative atmosphere. Who we are: ACV is a technology company that has revolutionized how dealers buy and sell cars online. We are transforming the automotive industry. ACV Auctions Inc. (ACV), has applied innovation and user-designed, data driven applications and solutions. We are building the most trusted and efficient digital marketplace with data solutions for sourcing, selling and managing used vehicles with transparency and comprehensive insights that were once unimaginable. We are disruptors of the industry and we want you to join us on our journey. Our network of brands include ACV Auctions, ACV Transportation, ClearCar, MAX Digital and ACV Capital within its Marketplace Products, as well as, True360 and Data Services. At ACV we focus on the Health, Physical, Financial, Social and Emotional Wellness of our Teammates and, to support this, we offer: - Multiple medical plans including a high deductible, low cost health plan - Company-sponsored (paid) Short-Term Disability, Long-Term Disability, and Life Insurance - Comprehensive optional benefits such as Dental, Vision, Supplemental Life/AD&D, Legal/ID Protection, and Accident and Critical Illness Insurance - Generous paid time off options, including uncapped vacation days, the greater of 3 paid sick days or in accordance with the applicable state or local paid sick leave law, 6 paid company holidays, 2 floating holidays, parental leave, bereavement leave, jury duty leave, voting leave, and other forms of paid leave as required by applicable law or regulation - Employee Stock Purchase Program with additional opportunities to earn stock in the Company - Retirement planning through the Company’s 401(k) Who we are looking for: The Director of Product Security is a critical leadership role responsible for the overall security posture of ACV’s software applications and platforms. Reporting directly to the CISO, this individual will own and mature the entire Product and Application Security program, integrating security practices throughout the Secure Software Development Lifecycle (SSDLC). This position requires a self-motivated and highly organized leader with excellent communication and technical skills. The Director will ensure the confidentiality, integrity, and availability of ACV’s product-related data and systems by mitigating code-based risks within a fast-paced, technology-driven environment. You will build and lead a high-performing team, driving continuous improvement and ensuring ACV remains a secure and trusted platform for dealers and buyers nationwide. What you will do: - Design, implement, and manage the end-to-end Product Security program, focusing on securing ACV's proprietary applications and code base. - Lead the adoption of DevSecOps practices, automating security tools and gates within the Continuous Integration/Continuous Deployment (CI/CD) pipelines to prevent security defects from reaching production. - Establish and enforce Secure Software Development Lifecycle (SSDLC) requirements, including security training for engineering teams and defining secure coding standards. - Build, mentor, and manage a team of Product Security Engineers responsible for application vulnerability management, security testing, and architectural review. - Understand and protect against the risks that AI brings without becoming the team that puts the No in Innovation. Proactively identify and establish security guardrails for AM/ML model development and usage to ensure safe innovation and high engineering velocity. - Oversee the deployment, tuning, and management of application security testing tools, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA) to identify and remediate code-based vulnerabilities. - Lead vulnerability remediation efforts for all ACV products, working closely with engineering and product teams to prioritize and track fixes based on risk. - Perform and oversee deep-dive security architecture and design reviews for all new products, features, and core application services, ensuring security is "baked in" from conception. - Define and manage secure configuration standards for containerized applications, microservices, APIs, and their supporting cloud infrastructure (AWS and GCP). - Manage and coordinate external penetration testing and bug bounty programs focused on ACV’s applications and APIs. - Design, maintain, and measure processes to prevent vulnerabilities from reaching production in a true Shift Left fashion. - Work with Technical Program Management to create appropriate key performance indicators to show success and improvement points in the program. - Contribute to ACV’s overall Governance, Risk, and Compliance (GRC) program by ensuring applications meet required internal security policies and external regulatory standards (e.g., SOC2, GDPR, CCPA). - Lead security risk assessments, threat modeling, and tabletop exercises specific to product features and application architecture, identifying and prioritizing technical vulnerabilities and developing mitigation strategies. - Ensure protection of sensitive data, including PII and financial information, within the application environment in compliance with relevant regulations. Validate that products conform to ACV’s data classification policies and other relevant documents and oversee processes to measure and enforce this before deployment. - Serve as the primary security advisor to Product and Engineering leadership and stakeholders on all matters related to application and product security. - Collaborate effectively with IT, Engineering, and Product teams to integrate security into their processes, fostering a strong security-conscious culture across development teams. - Maintain strong communication channels with remote team members, ensuring alignment and fostering a cohesive team environment. - Create a culture of communication, where collaboration and a sense of partnership with the remainder of the organization is evident and valued. - Create and maintain executive dashboards to increase security visibility throughout the organization and identify opportunities for improvement. - Perform additional duties as assigned. What you will need: - 10+ years experience in Information Security, with at least 5+ years directly focused on Product Security or Application Security in a leadership role. - Proven experience building and leading a centralized Product Security/AppSec program within a technology-driven, cloud-based SaaS company. - Deep, hands-on knowledge of the Secure Software Development Lifecycle (SSDLC), CI/CD, and DevSecOps principles, including automating security tooling. - Strong understanding of security frameworks and best practices (NIST CSF, ISO 27001, CIS Controls). - Extensive experience with cloud security, with a strong focus on securing applications deployed in AWS and/or GCP environments. Experience with Fintech companies is desirable. - Experience with modern software development including Agentic and Generative AI techniques. - Expertise with multiple application security tools, including SAST, DAST, MAST, SCA, API security platforms, and Web Application Firewalls (WAF). - Excellent communication, interpersonal, and leadership skills, with an ability to translate complex technical risks into business context for executive leadership and stakeholders. - Ability to work effectively in a remote environment and manage geographically dispersed teams. #LI-AM1 Our Values Trust & Transparency | People First | Positive Experiences | Calm Persistence | Never Settling At ACV, we are committed to an inclusive culture in which every individual is welcomed and empowered to celebrate their true selves. We achieve this by fostering a work environment of acceptance and understanding that is free from discrimination. ACV is committed to being an equal opportunity employer regardless of sex, race, creed, color, religion, marital status, national origin, age, pregnancy, sexual orientation, gender, gender identity, gender expression, genetic information, disability, military status, status as a veteran, or any other protected characteristic. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. If you have a disability or special need that requires reasonable accommodation, please let us know. For information on our collection and use of your personal information, please see our Privacy Notice. No immigration or work visa sponsorship provided for this position. Compensation: The compensation range for this position is listed in the "Job Details" section at the bottom of this posting. Please note that final compensation will be determined based upon the applicant's relevant experience, skill set, location, business needs, market demands, and other factors as permitted by law.

United States
$178K - $220K / year