Skip to content
GitLabGitLab

Staff Corporate Security Engineer

Leads corporate endpoint security architecture and automation, with emphasis on macOS, Terraform, GitOps, and scalable controls across device platforms. The role partners across security and IT, improves detection and auditability, and mentors engineers.

About the job

Responsibilities

  • Lead the security architecture of the endpoint fleet and related infrastructure, with a primary focus on macOS.
  • Design and support automation for secure endpoint deployment, configuration, and lifecycle management using code-based workflows.
  • Manage endpoint and SaaS security configuration through Terraform, version control, merge requests, continuous integration pipelines, and automated rollouts.
  • Define and enforce security baselines across macOS, iOS, Windows, and Linux endpoints.
  • Develop patching and software distribution approaches aligned with security, compliance, and operational requirements.
  • Partner with Information Technology, Security Operations, and Detection and Response teams to improve endpoint telemetry, detections, and response models.
  • Drive process improvements that reduce manual work and risk through automation, policy-driven controls, and auditable change management.
  • Mentor engineers across Corporate Security and Information Technology and serve as a senior escalation point for complex endpoint security issues.

Requirements

  • Experience designing and delivering endpoint, systems, or corporate security solutions requiring scalable, durable controls.
  • Deep knowledge of endpoint management platforms such as Jamf Pro or FleetDM, particularly for architecting and securing macOS environments.
  • Strong hands-on ability with Terraform and infrastructure-as-code practices, including module design, state management, and pipeline-based deployment.
  • Experience with GitOps workflows using Git repositories, merge requests, code review, and automated pipelines.
  • Strong proficiency in scripting or programming for automation and security tooling, such as Bash, Python, PowerShell, or Go.
  • Familiarity with cloud identity providers and directories, including Okta, Google Workspace, and LDAP.
  • Clear communication, cross-functional collaboration, and independent work in an all-remote environment.
  • Transferable experience from adjacent security, systems, or platform engineering backgrounds and a practical, security-focused problem-solving approach.

Compensation and Benefits

  • United States base salary: $168,000–$238,000 USD.
  • Flexible paid time off.
  • Team Member Resource Groups.
  • Equity compensation and Employee Stock Purchase Plan.
  • Growth and Development Fund.
  • Parental leave.

Skills

macOS, Jamf Pro, Fleetdm, Terraform, Infrastructure As Code, GitOps, Bash, Python, PowerShell, Go, Okta, Google Workspace, Ldap, iOS, Windows

GitLab

GitLab

United States
Staff Security Researcher
$168k+/yrRemote7+ YOESecurity Engineering

Conducts advanced application and AI security research for GitLab, identifying and validating systemic vulnerabilities, developing scalable research tooling, and guiding remediation. Requires 7+ years in offensive security and expertise across multiple technical domains and programming languages.

GitLab

GitLab

United States
Staff Security Engineer, IAM
$168k+/yrRemote7+ YOESecurity Engineering

Staff-level security engineer leading enterprise IAM, cloud identity, AI platform access, and non-human identity governance. The role requires deep Okta, infrastructure-as-code, Python, GCP or AWS, and regulated-environment experience.

Ironclad

Ironclad

San Francisco, CA

Staff IAM Engineer
$170k+/yrHybrid4+ YOESecurity Engineering

Own security-critical identity and corporate security controls, managing IAM platforms, SSO/MFA integrations, RBAC policies, and endpoint trust for macOS/Windows environments.

Chainguard

Chainguard

United States
Staff Vulnerability Management Engineer
$170k+/yrRemote7+ YOESecurity Engineering

Leads vulnerability disclosure operations at scale, including novel vulnerability measurement, CVE assignment, embargo coordination, and industry collaboration. The Staff individual contributor provides technical leadership and requires extensive software security or open source experience.

Okta

Okta

Bellevue, WA
Staff Identity Governance and Access Engineer
$161k+/yrOn-site7+ YOESecurity Engineering

Own the architecture and automation of enterprise identity governance, privileged access, and identity security posture programs. The role requires advanced IGA/PAM experience, production RBAC and lifecycle expertise, and the ability to lead technical direction and communicate with executives.