Skip to content
GitLabGitLab

Senior Security Assurance Engineer

Owns technology compliance and security assurance controls across corporate and business systems, aligning evidence for SOX, SOC 2, ISO, regulatory, and contractual obligations. The role requires 5+ years in compliance, audit, security, or IT, strong control-testing experience, and a bachelor's degree or equivalent.

About the job

Responsibilities

  • Design, document, maintain, and test IT general and security controls for corporate applications, identity infrastructure, security tooling, business systems, and relevant third-party SaaS.
  • Map shared controls across SOX, SOC 2, ISO 27001, ISO 42001, NIST CSF, PCI-DSS, privacy regulations, and customer contractual commitments.
  • Serve as the compliance liaison for IT, Corporate Security, Engineering, Finance, Security Governance, Security Risk, Internal Audit, the SOX PMO, Legal, and Privacy.
  • Define control expectations for AI tools, agents, and integrations, including acceptable use, evidence requirements, data handling, access scope, human review, and logging.
  • Contribute to security policies, standards, procedures, policy reviews, attestations, and Acceptable Use Policy adherence.
  • Run recurring access reviews, privileged-access reviews, segregation-of-duties reviews, change-management testing, and configuration-baseline monitoring.
  • Assess implementations, migrations, and significant changes for control readiness before go-live.
  • Manage SOX ITGC testing and auditor certification requests, direct evidence collection, and automate recurring evidence gathering where possible.
  • Track and lead remediation of control deficiencies and risks; improve compliance processes, metrics, and reporting.

Requirements

  • 5+ years of experience in IT compliance, security compliance, IT audit, information security, or information technology.
  • Bachelor's degree in a business or technology field, or equivalent experience.
  • Experience testing and documenting controls against COSO, COBIT, NIST CSF, ISO 27001, SOC 2, and SOX ITGC.
  • Experience working directly with internal or external auditors.
  • Experience assessing controls in SaaS and cloud-native application environments.
  • Working knowledge of identity and access management, including SSO, SCIM, RBAC, privileged access, and joiner/mover/leaver processes.
  • Familiarity with AI governance and control considerations for AI tools, agents, and integrations.
  • Experience contributing to security policies and standards and supporting adherence or attestation processes.
  • Ability to analyze data flows across product usage, billing, subscription, and financial reporting systems.
  • Exceptional written and verbal communication skills with credibility across leadership, engineering, auditors, and legal teams.
  • Ability or willingness to learn GitLab.

Nice to Have

  • CISA, CISSP, CRISC, or CISM certification.
  • Big Four or external audit experience.
  • Experience with usage-based billing, subscription management, metering, or entitlement systems.
  • Experience with compliance automation, continuous control monitoring, or enterprise AI-use standards such as ISO 42001 and NIST AI RMF.
  • Security Assurance or GRC experience supporting both corporate IT and product engineering.

Compensation

  • United States base salary range: $139,200–$196,000 annually.

Skills

It General Controls, Sox Itgc, SOC 2, ISO 27001, Iso 42001, Nist Csf, Pci-Dss, Identity And Access Management, SSO, SCIM, RBAC, Privileged Access, Ai Governance, Compliance Automation, GitLab

GitLab

GitLab

United States

Senior Security Compliance Engineer, Public Sector
$139k+/yrRemote5+ YOESecurity Engineering

Senior Security Compliance Engineer supporting public-sector compliance programs, regulated customers, audits, certifications, and FedRAMP continuous monitoring. Requires 5+ years in GRC or cybersecurity, compliance automation experience, cloud familiarity, and U.S. citizenship and residency.

Pindrop

Pindrop

United States

Senior Security Engineer
$140k+/yrRemote3+ YOESecurity Engineering

Senior Security Engineer on the Red Team performing offensive security, adversarial testing, and red team operations against GenAI/LLM systems, deepfake defenses, cloud infrastructure, and SaaS products. Requires 3+ years of hands-on pen testing/red team experience plus demonstrable GenAI attack experience.

Twilio

Twilio

United States

Senior Security Engineer, Incident Response
$142k+/yrRemote5+ YOESecurity Engineering

Lead technical response to security incidents across Twilio's global cloud infrastructure, including triage, containment, remediation, documentation, and post-incident improvements. Requires 5+ years incident response experience, expertise with SIEM/SOAR, cloud platforms, and AI-driven security tools.

Writer

Writer

San Francisco, CA
Security Engineer, Detection and Response
$132k+/yrHybrid7+ YOESecurity Engineering

Build detection, threat-hunting, and automated incident-response capabilities for AI infrastructure, including GPU clusters, training pipelines, and model deployments. The role requires substantial security operations experience, strong programming skills, and expertise in distributed systems or AI/ML environments.

Sardine

Sardine

United States

Security Compliance Manager
$130k+/yrRemote7+ YOESecurity Engineering

Own and scale Sardine’s security compliance and GRC function across major security, privacy, and resilience frameworks, including FedRAMP. The role leads audits, risk management, customer assurance, executive reporting, and a growing compliance team while partnering closely with technical and business stakeholders.