GitLab logo
GitLab

GitLab, founded in 2011 and based in San Francisco, California, maintains a distributed team of professionals that work remotely across multiple continents. GitLab advocates for pr

Staff Security Engineer, IAM

Location

California

Posted

10 days ago

Salary

$168K - $238K / year

Seniority

Lead

Bachelor Degree8 yrs expEnglishPythonTerraform

Job Description

Staff Security Engineer, IAM

GitLab

• Design comprehensive identity and AI access solutions that scale with our business growth, from AI agent governance frameworks to privileged access workflows that eliminate standing access through just-in-time provisioning • Lead identity and access engineering for our enterprise AI platforms including administration, SSO and SCIM integration, audit logging, data controls, and policy enforcement for Claude (web, Claude Code, Cowork) and adjacent tools • Codify our identity platforms in Terraform, leading the migration of Okta, Lumos, and our NHI platform from click-ops to peer-reviewed infrastructure-as-code, with a focus on global critical policies • Refactor our authentication framework to implement advanced conditional access controls such as device trust, location-based policies, risk-based step-up authentication, and behavioral analytics across our entire SaaS ecosystem • Pioneer non-human identity governance by designing monitoring and management solutions for service accounts, API keys, certificates, AI agents, and MCP integrations, and leading deployment, integration, and operationalization of our NHI platform across the SaaS estate • Drive cross-functional initiatives with Security, IT, Engineering, Enterprise AI, and the Office of the CIO to extract requirements from ambiguous business needs and translate them into actionable technical specifications • Mentor senior and intermediate engineers on technical implementation and strategic thinking, helping them develop expertise in modern identity and AI security practices

Job Requirements

  • 8+ years of IAM experience designing and implementing enterprise-scale solutions, with demonstrated time at a Staff or senior IC level
  • Expert-level Okta expertise including Identity Engine, advanced authentication policies, lifecycle workflows, and API automation
  • Strong infrastructure-as-code practice with Terraform, including provider experience for SaaS identity platforms and a track record of migrating click-ops to code
  • Hands-on experience administering or governing enterprise AI platforms (Anthropic Claude preferred; OpenAI ChatGPT Enterprise, Google Gemini Enterprise, or similar acceptable), and awareness of AI-specific risks including prompt injection, MCP attack surface, agent identity, and data leakage
  • Strong automation experience using Python and iPaaS tools (Tines, Okta Workflows)
  • Experience with IGA platforms like Lumos, ConductorOne, or similar
  • Working knowledge of non-human identity tooling (Token Security, Oasis, Astrix, or similar), or equivalent experience governing service accounts, OAuth grants, and workload identities
  • Experience in regulated environments with knowledge of compliance frameworks (FedRAMP, SOC2, SOX), including change management, evidence collection, and audit support
  • Collaborative mindset and strategic communication skills for writing technical proposals, leading cross-functional initiatives, and mentoring teammates
  • Nice to have Qualifications: Passion for emerging identity challenges including AI agent governance, non-human identity management, zero-trust architecture, and behavioral analytics; Active user of Claude Code, Cursor, or similar agentic development tools, with intuition for how engineers integrate them into daily workflows.

Benefits

  • Benefits to support your health, finances, and well-being
  • Flexible Paid Time Off
  • Team Member Resource Groups
  • Equity Compensation & Employee Stock Purchase Plan
  • Growth and Development Fund
  • Parental Leave

Related Categories

Related Job Pages

More Security Engineer Jobs

Full TimeRemoteTeam 51-200H1B No Sponsor

• Build and maintain strong relationships with AWS account teams, technical teams, and partner contacts to drive co-sell and joint GTM opportunities • Enable AWS teams to prospect and sell with Upwind, representing our solutions effectively to their customers • Train and support Upwind’s sales organization on working with AWS for co-sell, marketplace, and partner programs • Track and report on co-sell activity, joint pipeline, and partner-influenced deals, providing actionable insights to leadership • Collaborate with internal sales, marketing, and solutions engineering teams to execute joint campaigns, co-branded programs, and GTM initiatives • Support AWS Marketplace activities, including private offers, deal registration, and partner funding programs • Manage a large number of contacts and programs, ensuring organized and timely follow-up

California + 1 moreAll locations: California | New York
ECS Tech Inc logo

Security Engineer

ECS Tech Inc

All candidates must meet the following criteria: Must be a US Citizen, no dual Citizenships. Must be able to secure a Public trust clearance. Must be able to work across multiple programs across the Federal and DOD space. The core values that ECS looks for in an engagement manager include: Teamwork, Respect, Accountability, Integrity, and Leadership.

Full TimeRemoteH1B No Sponsor

Role Description The Security Engineer is responsible for supporting the engineering, implementation, and optimization of the security technologies, telemetry integrations, detection content, and automation capabilities that enable effective enterprise security monitoring and incident response operations. This role works closely with the SOC analysts, enterprise IT teams, and platform owners to ensure the reliability, scalability, and operational effectiveness of enterprise security monitoring capabilities. The Security Engineer will contribute to the continuous improvement of SOC technologies, detection engineering, and automation initiatives that strengthen the organization’s cybersecurity posture. - Security Platform Administration: Support the operation, maintenance, and optimization of SOC security platforms including SIEM, EDR, and related monitoring technologies. - Security Telemetry Integration: Configure and maintain telemetry integrations to ensure enterprise visibility across infrastructure, cloud, identity, and endpoint platforms. - Detection Engineering: Develop, tune, and maintain detection rules, alerts, and correlation logic to improve threat detection capabilities and reduce false positives. - SIEM Data Management: Monitor SIEM performance, data ingestion pipelines, and log normalization processes to ensure reliable and accurate data collection. - Security Automation Support: Implement and maintain automation and orchestration workflows to improve SOC operational efficiency and investigation response times. - Investigation Support: Provide technical support and expertise to SOC analysts during security investigations, threat hunting, and incident response activities. - Platform Integration: Collaborate with enterprise IT, cloud, and infrastructure teams to onboard new systems and services into the SOC monitoring environment. - Operational Monitoring: Monitor the health, reliability, and performance of security monitoring infrastructure and telemetry pipelines. - Technical Documentation: Maintain documentation related to detection logic, engineering procedures, telemetry integrations, and SOC platform configurations. - Continuous Improvement: Identify opportunities to enhance monitoring coverage, improve detection quality, and optimize engineering workflows within the SOC. Qualifications - Experience: Minimum of 3–5 years of cybersecurity or security engineering experience supporting enterprise security operations environments. - Security Engineering Experience: Hands-on experience supporting enterprise security monitoring technologies including SIEM, EDR, and log management platforms. - Detection Engineering Knowledge: Experience creating, tuning, and maintaining detection content and alerting logic. - Security Telemetry Experience: Familiarity with log collection, normalization, and telemetry integration across enterprise environments. - Security Automation Experience: Experience implementing or supporting automation workflows within SOC or incident response operations. - Enterprise Security Knowledge: Strong understanding of enterprise infrastructure, cloud environments, identity systems, and network security monitoring. - Security Framework Knowledge: Familiarity with cybersecurity frameworks such as NIST Cybersecurity Framework, CIS Critical Security Controls, and ISO 27001. Requirements - Able and willing to obtain a US Security Clearance. - On-Call Support: Participates in on-call support to assist with security incident response, operational issues, and investigation activities to maintain continuous SOC coverage and response capability. Physical Demands - While performing the duties of this job, the employee is regularly required to sit at a desk and use a computer for extended periods. - The position is generally sedentary but may require walking or standing for brief periods of time. - Employee may occasionally be required to move, carry, push, pull and/or lift objects up to 10 pounds. Work Environment - Job is performed in an office place setting. - The noise level in the work environment is generally very low with minimal background noise. - Comfortable climate control and adequate lighting.

United States
Job Closed
ECS Tech Inc logo

Senior Security Engineer

ECS Tech Inc

All candidates must meet the following criteria: Must be a US Citizen, no dual Citizenships. Must be able to secure a Public trust clearance. Must be able to work across multiple programs across the Federal and DOD space. The core values that ECS looks for in an engagement manager include: Teamwork, Respect, Accountability, Integrity, and Leadership.

Full TimeRemoteH1B No Sponsor

Role Description The Senior Security Engineer is responsible for supporting the engineering, implementation, and optimization of the security technologies, telemetry integrations, detection content, and automation capabilities that enable effective enterprise security monitoring and incident response operations. This role works closely with the Security Engineering Manager, SOC analysts, enterprise IT teams, and platform owners to ensure the reliability, scalability, and operational effectiveness of enterprise security monitoring capabilities. The Senior Security Engineer will contribute to the continuous improvement of SOC technologies, detection engineering, and automation initiatives that strengthen the organization’s cybersecurity posture. Responsibilities - Security Platform Administration: Support the operation, maintenance, and optimization of SOC security platforms including SIEM, EDR, and related monitoring technologies. - Security Telemetry Integration: Configure and maintain telemetry integrations to ensure enterprise visibility across infrastructure, cloud, identity, and endpoint platforms. - Detection Engineering: Develop, tune, and maintain detection rules, alerts, and correlation logic to improve threat detection capabilities and reduce false positives. - SIEM Data Management: Monitor SIEM performance, data ingestion pipelines, and log normalization processes to ensure reliable and accurate data collection. - Security Automation Support: Implement and maintain automation and orchestration workflows to improve SOC operational efficiency and investigation response times. - Investigation Support: Provide technical support and expertise to SOC analysts during security investigations, threat hunting, and incident response activities. - Platform Integration: Collaborate with enterprise IT, cloud, and infrastructure teams to onboard new systems and services into the SOC monitoring environment. - Operational Monitoring: Monitor the health, reliability, and performance of security monitoring infrastructure and telemetry pipelines. - Technical Documentation: Maintain documentation related to detection logic, engineering procedures, telemetry integrations, and SOC platform configurations. - Continuous Improvement: Identify opportunities to enhance monitoring coverage, improve detection quality, and optimize engineering workflows within the SOC. Qualifications - Experience: Minimum of 5–8 years of cybersecurity or security engineering experience supporting enterprise security operations environments. - Security Engineering Experience: Hands-on experience supporting enterprise security monitoring technologies including SIEM, EDR, and log management platforms. - Detection Engineering Knowledge: Experience creating, tuning, and maintaining detection content and alerting logic. - Security Telemetry Experience: Familiarity with log collection, normalization, and telemetry integration across enterprise environments. - Security Automation Experience: Experience implementing or supporting automation workflows within SOC or incident response operations. - Enterprise Security Knowledge: Strong understanding of enterprise infrastructure, cloud environments, identity systems, and network security monitoring. - Security Framework Knowledge: Familiarity with cybersecurity frameworks such as NIST Cybersecurity Framework, CIS Critical Security Controls, and ISO 27001. Requirements - Able and willing to obtain a US Security Clearance. - On-Call Support: Participates in on-call support to assist with security incident response, operational issues, and investigation activities to maintain continuous SOC coverage and response capability. Physical Demands - While performing the duties of this job, the employee is regularly required to sit at a desk and use a computer for extended periods. - The position is generally sedentary but may require walking or standing for brief periods of time. - Employee may occasionally be required to move, carry, push, pull and/or lift objects up to 10 pounds. Work Environment - Job is performed in an office place setting. - The noise level in the work environment is generally very low with minimal background noise. - Comfortable climate control and adequate lighting.

United States
Job Closed

• Support administration of AvidXchange’s security awareness and phishing simulation program in KnowBe4, including training assignments, campaign design, and coordination. • Assist with building creative cybersecurity awareness communications, campaigns, and recurring outreach activities designed to engage a wide range of teammates and cyber knowledge levels. • Monitor participation, phishing, and engagement metrics to measure program effectiveness and identify improvement opportunities. • Contribute to ongoing enhancement of awareness content to keep training engaging, relevant, and aligned with emerging threats. • Enhance and support our Security Champion Program to empower security-focused individuals to make a difference in their team. • Assist with cybersecurity risk assessments, audits, and third-party/vendor reviews. • Coordinate assessment and audit efforts through documentation, evidence gathering, and cross-functional collaboration. • Track remediation items, risk findings, audit observations, and follow-up efforts across teams. • Develop and maintain cybersecurity metrics, dashboards, and reporting tailored to technical teams, leadership, and executive audiences. • Create visualizations, presentations, and other deliverables using tools such as Power BI, Excel, and PowerPoint. • Coordinate recurring reporting activities related to risk committees, audits, awareness initiatives, and operational metrics. • Analyze data to identify meaningful trends, gaps, and opportunities for program improvement. • Maintain cybersecurity documentation, policies, standards, repositories, and other governance materials. • Assist with customer and vendor due diligence activities, including questionnaire responses, customer assurance communications, and trust center maintenance. • Coordinate business continuity and incident response preparedness efforts, including tabletop exercises and related operational initiatives.

United States
Job Closed