# Senior Security Compliance Engineer, Public Sector

**Company:** [GitLab](https://hotfix.jobs/companies/gitlab)
**Location:** Remote
**Role:** Security Engineering
**Salary:** $139k – $196k/yr
**Experience:** 5+ years
**Skills:** GRC, Cybersecurity, FedRAMP, Cmmc, SOC 2, Irap, ISO 27001, Compliance-As-Code, Policy-As-Code, AWS, GCP, Control Testing, Evidence Collection, Cissp, Cism
**Posted:** 2026-09-04

> Senior Security Compliance Engineer supporting public-sector compliance programs, regulated customers, audits, certifications, and FedRAMP continuous monitoring. Requires 5+ years in GRC or cybersecurity, compliance automation experience, cloud familiarity, and U.S. citizenship and residency.

## Job Description

## Responsibilities
- Develop, implement, and manage GRC strategies and processes supporting FedRAMP, IRAP, and other regulatory and industry standards.
- Partner with highly regulated customers to understand compliance requirements and provide tailored solutions.
- Lead security assessments, audits, and certification processes.
- Support GitLab Dedicated for Government’s FedRAMP continuous monitoring commitments.
- Collaborate with IT, Product, Engineering, Security, and Legal to integrate GRC requirements into operations and technology.
- Maintain policies, procedures, controls, and other compliance documentation.
- Automate GRC processes and implement compliance-as-code or policy-as-code solutions using scripting and coding skills.
- Monitor regulatory changes and industry trends to improve the GRC program.
- Train and advise internal teams and customers on GRC and security awareness.
- Provide subject-matter expertise and strategic guidance to senior stakeholders.

## Requirements
- United States citizenship and residency.
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field, or equivalent experience.
- At least 5 years of experience in GRC, cybersecurity, or a related field, preferably in highly regulated industries.
- Experience achieving and maintaining certifications or attestations such as FedRAMP, CMMC, SOC 2, IRAP, and ISO 27001.
- Strong understanding of public-sector and highly regulated-industry compliance requirements.
- Experience with compliance-as-code or policy-as-code, control testing, and evidence-collection automation.
- Knowledge of FedRAMP requirements, processes, and documentation.
- Familiarity with cloud hyperscaler services, including AWS and Google Cloud.
- Strong analytical, problem-solving, project-management, communication, and collaboration skills.
- Ability to work independently and manage multiple projects in a fast-paced environment.

## Nice-to-haves
- CISSP, CISM, CISA, or similar certification.

## Compensation and Benefits
- United States base salary: **$139,200–$196,000 USD annually**.
- Flexible paid time off.
- Equity compensation and employee stock purchase plan.
- Growth and development fund.
- Parental leave.
- Benefits supporting health, finances, and well-being.

## Similar jobs

- [Senior Security Assurance Engineer](https://hotfix.jobs/jobs/4db71196-4678-47f9-b8fd-a70dc317bd46) - GitLab - Remote - $139k – $196k/yr
- [Senior Security Engineer](https://hotfix.jobs/jobs/bf99bce1-bf10-4938-81d3-d24f8455171f) - Pindrop - Remote - $140k – $165k/yr
- [Senior Security Engineer, Incident Response](https://hotfix.jobs/jobs/c68462e8-6fd9-48ef-99a9-0516fb5468d8) - Twilio - Remote - $142k – $208k/yr
- [Security Engineer, Detection and Response](https://hotfix.jobs/jobs/e00040ab-bd5e-47da-a22b-c36fa3dea16c) - Writer - San Francisco, CA - $132k – $258k/yr
- [Security Compliance Manager](https://hotfix.jobs/jobs/a631d7a7-01a4-496e-8e8c-97bd0b990c08) - Sardine - Remote - $130k – $190k/yr

**Apply:** https://hotfix.jobs/jobs/3427156e-b584-45f3-8a5e-23c79be146af
**Canonical:** https://hotfix.jobs/jobs/3427156e-b584-45f3-8a5e-23c79be146af