Staff Infrastructure Security Engineer
Leads infrastructure security strategy and execution across GitLab’s cloud platforms and self-managed offerings. The role requires deep cloud, Kubernetes, Infrastructure-as-Code, security tooling, threat modeling, and technical leadership experience.
About the job
Responsibilities
- Set architectural patterns, reference implementations, and foundational security automation for infrastructure security across GitLab.
- Lead infrastructure security initiatives from problem framing through delivery, scoping ambiguous multi-quarter work into executable streams with clear success criteria.
- Conduct and lead security reviews and threat modeling for complex infrastructure components, identify systemic risks, and drive remediation across affected systems.
- Define the approach to AI-assisted security engineering and establish reusable patterns.
- Serve as a technical voice for Infrastructure Security, translating architectural tradeoffs into decisions for engineering teams and senior leadership.
- Partner on technical planning, prioritization, and roadmap development.
- Mentor and develop engineers while modeling inclusive collaboration.
- Secure GitLab infrastructure through internal use of GitLab products.
Requirements
- Expert knowledge of cloud infrastructure security across AWS, Google Cloud, or Azure.
- Expertise in Kubernetes and related infrastructure and data security topics.
- Proficiency in multiple programming languages, including Go, Python, and Ruby, with experience delivering production-quality security tooling.
- Extensive experience with Infrastructure-as-Code security using Terraform, Ansible, or CloudFormation.
- Experience with policy-as-code and automated compliance.
- Hands-on experience applying AI to security workflows.
- Track record of leading multi-team technical initiatives from ambiguous problem statements to measurable outcomes.
- Strong written and verbal communication skills, including communication with senior leadership.
- Familiarity with FedRAMP, ISO 27001, SOC 2, and PCI-DSS.
Benefits
- Health, financial, and well-being benefits
- Flexible paid time off
- Team member resource groups
- Equity compensation and employee stock purchase plan
- Growth and development fund
- Parental leave
Skills
AWS, GCP, Azure, Kubernetes, Go, Python, Ruby, Terraform, Ansible, CloudFormation, Policy As Code, FedRAMP, ISO 27001, SOC 2, Pci-Dss
Similar jobs
Security Engineering jobsConducts advanced application and AI security research for GitLab, identifying and validating systemic vulnerabilities, developing scalable research tooling, and guiding remediation. Requires 7+ years in offensive security and expertise across multiple technical domains and programming languages.
Own the architecture and automation of enterprise identity governance, privileged access, and identity security posture programs. The role requires advanced IGA/PAM experience, production RBAC and lifecycle expertise, and the ability to lead technical direction and communicate with executives.
Leads cloud security detection and response engineering, building AI-enabled agents, threat-hunting capabilities, and automated security tooling. Requires deep security expertise, cloud experience, and strong knowledge of SIEM, SOAR, infrastructure as code, and AI threat frameworks.
Own security-critical identity and corporate security controls, managing IAM platforms, SSO/MFA integrations, RBAC policies, and endpoint trust for macOS/Windows environments.
Staff Identity Engineer serving as a technical authority for enterprise IAM, owning Okta architecture, cloud identity guardrails, automation, and AI identity security. Requires deep Okta and authentication-protocol expertise, multi-cloud experience, and technical leadership.