GitLab logo
GitLab

GitLab, founded in 2011 and based in San Francisco, California, maintains a distributed team of professionals that work remotely across multiple continents. GitLab advocates for pr

Director of Engineering, Security Risk Management

Location

Canada

Posted

54 days ago

Salary

$194.8K - $365.2K / year

Seniority

Lead

Job Description

Director of Engineering, Security Risk Management

GitLab

• Drive the evolution of GitLab's Security Risk Management (SRM) stage into a world-class platform for vulnerability analysis and remediation at enterprise scale. • Own the technical strategy for processing, analyzing, and remediating vulnerabilities across massive codebases and complex enterprise environments. • Design distributed systems architecture capable of processing vulnerability data from thousands of repositories, millions of commits, and complex dependency graphs in real-time. • Drive storage system decisions for multi-petabyte security datasets, balancing query performance, cost efficiency, and data retention requirements across time-series, graph, and document storage paradigms. • Architect scalable analysis pipelines that can ingest vulnerability feeds, correlate findings across multiple security tools, and provide actionable intelligence to both security teams and individual developers. • Lead the technical evolution from monolithic security scanning to microservices-based, event-driven vulnerability management systems. • Champion high-performance systems thinking throughout the team, establishing patterns for horizontal scaling, efficient resource utilization, and fault-tolerant distributed computing. • Establish technical standards for system observability, chaos engineering, and performance optimization in security-critical systems. • Mentor and develop senior engineers in distributed systems design, database optimization, and large-scale system architecture. • Drive architectural decision records (ADRs) for major technical decisions, particularly around data storage, processing frameworks, and system boundaries. • Own the end-to-end user journey (in partnership with PM) for both AppSec professionals managing enterprise-wide risk and developers receiving actionable security feedback in their workflow. • Design APIs and interfaces that abstract complexity while providing the power and flexibility that security professionals demand. • Collaborate with Product Management, UX and Product Design to translate complex technical capabilities into intuitive user experiences. • Establish feedback loops with large enterprise customers to ensure our technical solutions scale with their organizational complexity. • Evaluate and integrate cutting-edge technologies in areas such as graph databases, stream processing, machine learning inference at scale, and distributed caching, in collaboration with GitLab’s Infrastructure, Data and AI teams. • Own the technical roadmap for vulnerability correlation, risk scoring, and automated remediation workflows. • Drive partnerships with other GitLab stages to ensure seamless integration across the DevSecOps platform. • Lead incident response for availability and performance issues in customer-facing security systems.

Job Requirements

  • 10+ years of software engineering experience with 5+ years leading distributed systems at scale (>100M daily operations)
  • Deep expertise in designing and operating high-throughput, low-latency distributed systems with complex data models
  • Proven experience with polyglot persistence strategies, including relational databases (PostgreSQL, Cloud Spanner), time-series databases, graph databases, and distributed key-value stores
  • Strong background in stream processing frameworks (Apache Kafka, Apache Flink, or similar) and event-driven architectures
  • Hands-on experience with container orchestration (Kubernetes) and cloud-native observability stacks
  • Security domain knowledge with understanding of vulnerability assessment, static analysis, dependency scanning, or application security testing.
  • Proven track record of leading and growing high-performing engineering teams (40+ engineers)
  • Experience transforming engineering culture and establishing technical excellence standards in fast-growing organizations
  • Strong technical communication skills with ability to present complex architectural decisions to executive stakeholders
  • Collaborative leadership style with experience working across multiple engineering teams and product stakeholders
  • Systems thinking approach to complex technical problems with demonstrated ability to make appropriate trade-offs between performance, scalability, and maintainability
  • Experience with A/B testing frameworks and data-driven decision making in technical contexts
  • Track record of successfully delivering large-scale technical migrations or architectural transformations
  • Startup or high-growth company experience with ability to balance technical debt with rapid feature delivery.

Benefits

  • Benefits to support your health, finances, and well-being
  • Flexible Paid Time Off
  • Team Member Resource Groups
  • Equity Compensation & Employee Stock Purchase Plan
  • Growth and Development Fund
  • Parental leave
  • Home office support

Related Categories

Related Job Pages

More Security Engineer Jobs

Full TimeRemoteTeam 1,001-5,000Since 30+ yearsH1B Sponsor

• Measure, monitor, and report on information security risks • Review and report on vendor/third party risk to support vendor risk management activities • Engage staff and/or vendors to develop information security risk mitigation plans to address risks identified in Vendor risk reviews • Monitor and report on information security risk mitigation plans to ensure timely execution • Engage employees in the management of information security risk and ensure they are aware of their accountabilities with regard to information security risk management • Regularly assess and report to management any exceptions to information risk management policies, procedures and limits • Engage with the Enterprise Risk Management office to ensure information risk management policies, procedures and limits are aligned with Enterprise Risk Management policies and guidance • Contribute and provide input to the development of operational department goals • Acts as technical expert in functional domain • Recommends technical advancements to improve CareSource customer and partner experiences • Perform any other job related instructions as requested

United States
$94.1K - $164.8K / year
Job Closed
Balco, Inc. logo

Outside Architectural Solutions Sales Representative - Midwest Region

Balco, Inc.

Based in Houston, Texas, RectorSeal, LLC, is a wholly owned subsidiary of CSW Industrials, Inc. and is a leading provider of quality solutions for the professional trades serving heating, ventilation, and air conditioning (HVAC/R), plumbing, electrical, and construction markets. For more information about RectorSeal’s innovative products and brands that increase efficiency and improve reliability, please visit www.RectorSeal.com .

Full TimeRemoteTeam 51-200

Position Summary We are seeking a dynamic and results-oriented Outside Sales Representative to drive growth across Balco’s portfolio of architectural engineered products for the construction industry. Categories include expansion joint systems, stair nosings, entrance mats & grids, photoluminescent egress systems, etc. This role focuses on expanding market share through targeted outreach to General Contractors, Subcontractors and the Architectural/Specification community in the construction industry. The ideal candidate thrives in a face-to-face sales environment and is successful at building lasting relationships and loyal customers. **The salary range for this role is $100,000 to $145,000 annually, inclusive of base pay and sales incentive compensation Responsibilities - Conduct outside sales activities to achieve regional sales targets, including prospecting and closing deals with new customers across our architectural product line. - Identify and engage specialty contractors, demonstrating how Balco Architectural Products outperform competitors, and facilitate product switches through consultations and demonstrations. - Expand the wallet share of existing customers to multiple product categories, joint systems, stair nosings, entrance mats & grids, photoluminescent egress systems and additional solutions. - Build and nurture strong relationships with key accounts, distributors, contractors and the design community via in-person meetings, site visits, and networking events. - Perform product demonstrations, provide technical education on joint solutions and all architectural product offerings to address customer needs related to design requirements. - Travel regionally (up to 50% or more) to meet clients, attend trade shows, dealer meetings, and industry events to generate leads and expand market penetration. - Collaborate with internal teams to develop customized proposals, negotiate pricing and terms, and ensure seamless order fulfillment. - Track and report on sales performance, market trends, and competitive activities using CRM tools; prepare weekly, monthly, and quarterly reports. - Identify new business opportunities by analyzing local market conditions, including competition and stakeholder trends, to secure new customers and grow existing ones. - This role may require other job duties to be performed. The above statements are intended to describe the general nature and level of work performed by employees assigned to this role. They are not to be construed as an exhaustive list of all job duties performed by the personnel in this role. Qualifications (Knowledge & Skills) - High school diploma required, bachelor's degree in business, marketing, or related field preferred. - B2B outside sales experience, ideally in the construction or architectural design industry. - Proven track record of meeting or exceeding sales quotas through relationship-building and consultative selling. - Strong knowledge of construction materials and an understanding of a project team and lifecycle. - Excellent communication, negotiation, and interpersonal skills for face-to-face interactions. - Proficiency in CRM software, Microsoft Office, and sales reporting tools. - Valid U.S. driver’s license with a clean driving record (MVR and proof of insurance required). - Self-motivated, adaptable, and able to work independently in a fast-paced environment. Other Requirements - Field: This role will also be required to visit construction sites from time to time in all types of weather conditions, navigate uneven surfaces, reach, bend, kneel, lift 40 pounds, and stand for extended periods. - Remote: This is remote role. Remote employees are required to have a dedicated workspace where they can conduct business and have private conversations. Employees are expected to be available to perform the essential functions of their jobs whenever they are scheduled to work. Candidates who receive an offer of employment must successfully pass a background check and drug screen. CSWI products and systems help contractors do their jobs better, faster and easier; make buildings safer and more aesthetically pleasing; protect valuable assets from corrosion; and improve the reliability of mission critical equipment. CSW Industrials, Inc., together with its affiliated companies are equal opportunity employers. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status. We are proud to be an Equal Opportunity Employer (EOE) and encourage all to apply. CSW Industrials offers a competitive Total Rewards package including: - Health insurance - Dental insurance - Disability insurance - Life insurance - Flexible spending account - Health savings account - Vision insurance - Paid time off - Parental leave - Employee assistance program - Tuition reimbursement - Annual Performance Bonus Program - 401(k) $1-$1 match, up to 6% - vest immediately

United States
$100K - $145K / year
TekSynap logo

Cybersecurity Subject Matter Expert w/Secret Clearance

TekSynap

TekSynap, formerly known as Synaptek, is a privately held, ISO-certified IT company offering solutions and services to meet the business technology needs of local, state, and feder

Responsibilities & Qualifications TekSynap is seeking a Cybersecurity Subject Matter Expert to join our team at Defense Health Agency to provide senior cybersecurity subject matter expertise supporting DHA cybersecurity assessment, RMF authorization, IV&V validation, and enterprise risk management activities across systems, enclaves, and sites supported by NIWC Atlantic. REQUIRED QUALIFICATIONS Experience - 15 years IT experience HIPAA/Medical Systems expertise - Senior DoD cybersecurity experience - RMF subject matter expertise - A&A authorization experience - IV&V cybersecurity validation experience - Enterprise cybersecurity architecture experience - Risk management expertise - DoD policy knowledge Certifications - IAM Level III Certification preferred (e.g., CISSP, CISM, CASP) Education - Bachelor’s degree in Cybersecurity, IT, Engineering, or related field Equivalent experience acceptable Clearance - Secret clearance (ability to obtain TS preferred) RESPONSIBILITIES - Serve as senior cybersecurity advisor for RMF and A&A execution - Provide subject matter expertise on DoD cybersecurity policy and guidance - Provide oversight of RMF lifecycle implementation across systems - Review and approve Security Assessment Plans and test strategies - Provide technical review of Security Assessment Reports - Provide expert analysis of residual risk and authorization recommendations - Provide oversight of IV&V cybersecurity validation activities - Provide expert guidance on STIG compliance and implementation - Support development of RMF strategies for enterprise systems - Provide guidance on cybersecurity architecture and control selection - Review system boundary definitions and enclave architectures - Provide oversight of vulnerability remediation strategies - Review POA&M development and risk mitigation approaches - Provide expert support for eMASS package development - Review authorization packages for completeness and accuracy - Provide consultation to system owners and program managers - Support validation readiness review decision-making - Provide guidance for continuous monitoring strategy implementation - Support development of cybersecurity SOPs and policies - Provide guidance on NIST, FISMA, and DoD RMF requirements - Participate in technical review boards and governance forums - Provide expert analysis of cybersecurity test results - Support development of enterprise cybersecurity dashboards - Provide subject matter expertise for DHA cybersecurity initiatives - Support toolset enhancement and automation planning - Provide guidance on risk scoring and vulnerability prioritization - Support enterprise-wide cybersecurity compliance activities - Provide executive-level cybersecurity recommendations - Support CONUS and OCONUS cybersecurity assessment activities - Provide technical mentoring to engineering and analyst teams - Support Government briefings and technical presentations - Provide advisory support for authorization decisions COMPETENCIES - Cybersecurity subject matter expertise - RMF governance - Risk management - Architecture review - Technical advisory - Strategic cybersecurity planning - Policy interpretation - Executive communication Overview WORK ENVIRONMENT The work environment characteristics described here are representative of those an employee encounters while performing the essential functions of the job. Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions. - Location: North Charleston, SC area (contractor facility within 15 miles of NIWC Atlantic). Remote/telework may be approved - Type of environment: Office environment - Noise level: Medium - Work schedule: Core hours (0800-1700), Monday through Friday. Occasional extended hours during testing events - Amount of Travel: Minimal (5-15%). Primarily CONUS support WORK AUTHORIZATION/SECURITY CLEARANCE U.S. Citizen Secret clearance (ability to obtain TS preferred) PHYSICAL DEMANDS The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. While performing the duties of this job, the employee is regularly required to use hands to handle, feel, touch; reach with hands and arms; talk and hear. The employee is regularly required to stand; walk; sit; climb or balance; and stoop, kneel, crouch, or crawl. The employee is regularly required to lift up to 10 pounds. The employee is frequently required to lift up to 25 pounds; and up to 50 pounds. The vision requirements include close vision, distance vision, peripheral vision, depth perception, and ability to adjust focus. OTHER INFORMATION Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this job. Duties, responsibilities and activities may change at any time with or without notice Additional Job Information TekSynap is a fast growing high-tech company that understands both the pace of technology today and the need to have a comprehensive well planned information management environment. “Technology moving at the speed of thought” embodies these principles – the need to nimbly utilize the best that information technology offers to meet the business needs of our Federal Government customers. Apply now to explore jobs with us at www.TekSynap.com. We offer our full-time employees a competitive benefits package to include health, dental, vision, 401K, life insurance, short-term and long-term disability plans, vacation time and holidays. TekSynap is a drug-free workplace. We reserve the right to conduct drug testing in accordance with federal, state, and local laws. All employees and candidates may be subject to drug screening if deemed necessary to ensure a safe and compliant working environment. By applying to a role at TekSynap you are providing consent to receive text messages regarding your interview and employment status. If at any time you would like to opt out of text messaging, respond "STOP". As part of the application process, you agree that TekSynap Corporation may retain and use your name, e-mail, and contact information for purposes related to employment consideration. EQUAL EMPLOYMENT OPPORTUNITY In order to provide equal employment and advancement opportunities to all individuals, employment decisions will be based on merit, qualifications, and abilities. TekSynap does not discriminate against any person because of race, color, creed, religion, sex, sexual orientation, gender identity, protected veteran status, national origin, disability, age, genetic information or any other characteristic protected by law (referred to as “protected status”). This nondiscrimination policy extends to all terms, conditions, and privileges of employment as well as the use of all company facilities, participation in all company-sponsored activities, and all employment actions such as promotions, compensation, benefits, and termination of employment. TekSynap is committed to ensuring that our online application process provides an equal employment opportunity to all job seekers, including individuals with disabilities. If you believe you need a reasonable accommodation in order to search for a job opening or to submit an application, please contact hr@teksynap.com for assistance.

United States
The Mill Adventure logo

Senior Security Engineer – AppSec, Offensive

The Mill Adventure

“When the winds of change blow, some people build walls and others build windmills.” – Chinese proverb

Full TimeRemoteTeam 11-50H1B No Sponsor

• Own Application & Offensive Security: Drive the application security lifecycle. Lead architecture reviews, conduct deep-dive threat modeling sessions, and perform targeted internal penetration tests and secure code reviews to uncover blind spots early. • Drive DevSecOps Excellence: Architect and deeply integrate security tooling (SAST, DAST, SCA, secrets detection) directly into our CI/CD pipelines. Ensure high-signal alerts, low friction for developers, and seamless automation. • Own Vulnerability Management: Triage, validate, and prioritize application-level vulnerabilities based on actual business context and risk, guiding engineering teams through pragmatic remediation. • Support Cloud & Core IT Security: While AppSec is your primary focus, you will leverage your general working knowledge of AWS security and foundational IT controls (IAM, endpoint, zero-trust) to support the wider security team and ensure holistic coverage. • Be a Role Model & Culture Champion: Lead by example. Act as a definitive senior technical mentor for developers and a highly collaborative peer to our existing security team. Champion a culture of security ownership and actively spread security awareness across the entire technical organization. • Act as a Business Enabler: Eradicate the "security as a blocker" mentality. Partner proactively with product and engineering teams to find secure paths to "yes," ensuring our security initiatives accelerate rather than hinder product velocity.

Malta
Job Closed