Principal Security Awareness & Human Risk Engineer
Own GitLab’s global security awareness and human-risk program, leading phishing simulations, behavior-change initiatives, training platforms, vendor strategy, and audit support. Requires 10+ years scaling enterprise awareness programs and strong stakeholder influence in a distributed organization.
About the job
Responsibilities
- Own and evolve GitLab’s global security awareness and education program, including annual, new-hire, role-based, targeted, executive, and microlearning content.
- Lead enterprise phishing simulations from design through deployment, analysis, and targeted follow-up.
- Apply behavior-change principles to reinforce secure habits and address priority risk behaviors.
- Build security culture through learning campaigns, Security Awareness Month, and ongoing engagement.
- Produce multimedia security awareness and education content, including video.
- Administer training and phishing platforms, including program data and reporting.
- Define and report performance indicators to Security Assurance leadership.
- Manage vendors for phishing, secure coding (OWASP) training, and video production.
- Evaluate markets and competitors, make renewal and vendor decisions, negotiate costs, and recommend in-house alternatives when appropriate.
- Collaborate on security policies, standards, and procedures.
- Coordinate audit evidence and demonstrate control effectiveness.
- Track remediation of identified gaps through closure.
Requirements
- 10+ years of experience building or scaling global security awareness and human-risk programs in a large, globally distributed enterprise; regulated-industry experience preferred.
- SANS Security Awareness Professional (SSAP) certification or equivalent expertise building, maintaining, and measuring a mature awareness program.
- Experience running enterprise-scale phishing programs and organization-wide awareness campaigns.
- Experience evaluating, selecting, consolidating, or replacing security training vendors, including cost and value analysis.
- Instructional design capability.
- Working knowledge of security policy development, audit support, and control evidence.
- Ability to influence enterprise strategy across technical and non-technical teams without formal authority.
- Ability to make complex security topics practical and engaging in an all-remote organization.
- Experience onboarding, managing, and negotiating with third-party vendors.
Compensation and Benefits
- United States base salary: $203,200–$275,000 USD.
- Benefits include flexible paid time off, team member resource groups, equity compensation and employee stock purchase plan, growth and development fund, and parental leave.
Skills
Security Awareness, Human Risk Management, Phishing Simulations, Instructional Design, Security Training, Security Policies, Audit Support, Control Evidence, Vendor Management, Owasp, Behavior Change
Similar jobs
Security Engineering jobsLeads offensive security research across GitLab’s codebase and AI-powered agentic surfaces, identifying systemic vulnerabilities, developing exploit proofs of concept, and driving remediation. Requires 10+ years of security research or penetration-testing experience and proficiency in multiple programming languages.
Leads security, privacy, audit, vendor-risk, and AI governance programs while setting long-term GRC strategy and executing cross-functional controls. Requires 10+ years of GRC, information security, and privacy compliance experience, with deep SOC 2, privacy, and emerging AI governance expertise.
Own the technical security function across cloud infrastructure, detection and response, application security, incident response, and automation. The role requires 8+ years of security engineering experience, deep AWS expertise, and the ability to lead security improvements across engineering teams.
Staff-level AppSec engineer building secure coding practices and vulnerability management for a commerce platform. Requires 6+ years in application security with deep AWS and Python experience.
Build and scale container security capabilities that orchestrate Zero Trust Segmentation at the application and pod level. The role requires 8+ years developing distributed systems, proficiency in a higher-level language, and strong Kubernetes, networking, and Linux expertise.