Skip to content
GitLabGitLab

Senior Security Compliance Engineer, Public Sector

Senior Security Compliance Engineer supporting public-sector compliance programs, regulated customers, audits, certifications, and FedRAMP continuous monitoring. Requires 5+ years in GRC or cybersecurity, compliance automation experience, cloud familiarity, and U.S. citizenship and residency.

About the job

Responsibilities

  • Develop, implement, and manage GRC strategies and processes supporting FedRAMP, IRAP, and other regulatory and industry standards.
  • Partner with highly regulated customers to understand compliance requirements and provide tailored solutions.
  • Lead security assessments, audits, and certification processes.
  • Support GitLab Dedicated for Government’s FedRAMP continuous monitoring commitments.
  • Collaborate with IT, Product, Engineering, Security, and Legal to integrate GRC requirements into operations and technology.
  • Maintain policies, procedures, controls, and other compliance documentation.
  • Automate GRC processes and implement compliance-as-code or policy-as-code solutions using scripting and coding skills.
  • Monitor regulatory changes and industry trends to improve the GRC program.
  • Train and advise internal teams and customers on GRC and security awareness.
  • Provide subject-matter expertise and strategic guidance to senior stakeholders.

Requirements

  • United States citizenship and residency.
  • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field, or equivalent experience.
  • At least 5 years of experience in GRC, cybersecurity, or a related field, preferably in highly regulated industries.
  • Experience achieving and maintaining certifications or attestations such as FedRAMP, CMMC, SOC 2, IRAP, and ISO 27001.
  • Strong understanding of public-sector and highly regulated-industry compliance requirements.
  • Experience with compliance-as-code or policy-as-code, control testing, and evidence-collection automation.
  • Knowledge of FedRAMP requirements, processes, and documentation.
  • Familiarity with cloud hyperscaler services, including AWS and Google Cloud.
  • Strong analytical, problem-solving, project-management, communication, and collaboration skills.
  • Ability to work independently and manage multiple projects in a fast-paced environment.

Nice-to-haves

  • CISSP, CISM, CISA, or similar certification.

Compensation and Benefits

  • United States base salary: $139,200–$196,000 USD annually.
  • Flexible paid time off.
  • Equity compensation and employee stock purchase plan.
  • Growth and development fund.
  • Parental leave.
  • Benefits supporting health, finances, and well-being.

Skills

GRC, Cybersecurity, FedRAMP, Cmmc, SOC 2, Irap, ISO 27001, Compliance-As-Code, Policy-As-Code, AWS, GCP, Control Testing, Evidence Collection, Cissp, Cism

GitLab

GitLab

United States

Senior Security Assurance Engineer
$139k+/yrRemote5+ YOESecurity Engineering

Owns technology compliance and security assurance controls across corporate and business systems, aligning evidence for SOX, SOC 2, ISO, regulatory, and contractual obligations. The role requires 5+ years in compliance, audit, security, or IT, strong control-testing experience, and a bachelor's degree or equivalent.

Pindrop

Pindrop

United States

Senior Security Engineer
$140k+/yrRemote3+ YOESecurity Engineering

Senior Security Engineer on the Red Team performing offensive security, adversarial testing, and red team operations against GenAI/LLM systems, deepfake defenses, cloud infrastructure, and SaaS products. Requires 3+ years of hands-on pen testing/red team experience plus demonstrable GenAI attack experience.

Twilio

Twilio

United States

Senior Security Engineer, Incident Response
$142k+/yrRemote5+ YOESecurity Engineering

Lead technical response to security incidents across Twilio's global cloud infrastructure, including triage, containment, remediation, documentation, and post-incident improvements. Requires 5+ years incident response experience, expertise with SIEM/SOAR, cloud platforms, and AI-driven security tools.

Writer

Writer

San Francisco, CA
Security Engineer, Detection and Response
$132k+/yrHybrid7+ YOESecurity Engineering

Build detection, threat-hunting, and automated incident-response capabilities for AI infrastructure, including GPU clusters, training pipelines, and model deployments. The role requires substantial security operations experience, strong programming skills, and expertise in distributed systems or AI/ML environments.

Sardine

Sardine

United States

Security Compliance Manager
$130k+/yrRemote7+ YOESecurity Engineering

Own and scale Sardine’s security compliance and GRC function across major security, privacy, and resilience frameworks, including FedRAMP. The role leads audits, risk management, customer assurance, executive reporting, and a growing compliance team while partnering closely with technical and business stakeholders.