GitLab Logo

GitLab

Staff Security Engineer, IAM

Posted 2 Hours Ago
Be an Early Applicant
Easy Apply
Remote
Hiring Remotely in Canada
Expert/Leader
Easy Apply
Remote
Hiring Remotely in Canada
Expert/Leader
Lead enterprise IAM and AI access security engineering across Okta, GCP, AWS, and IGA platforms. Replace low-code automation with tested Python services, codify identity infrastructure using Terraform/OpenTofu/Pulumi, implement least-privilege and privileged-access controls, govern human and non-human identities, and secure enterprise AI platforms. Drive cross-functional initiatives, develop technical roadmaps and proposals, support compliance, and mentor engineers.
The summary above was generated by AI

GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50 million registered users and more than 50% of the Fortune 100* trust GitLab to ship better, more secure software faster.

The same principles built into our products are reflected in how our team works: we embrace AI as a core productivity multiplier, with all team members expected to incorporate AI into their daily workflows to drive efficiency, innovation, and impact. GitLab is where careers accelerate, innovation flourishes, and every voice is valued. Our high-performance culture is driven by our values and continuous knowledge exchange, enabling our team members to reach their full potential while collaborating with industry leaders to solve complex problems. Co-create the future with us as we build technology that transforms how the world develops software.

*Fortune 500® is a registered trademark of Fortune Media IP Limited, used under license. Claim based on GitLab data. Fortune 100 refers to the top 20% ranked companies in the 2025 Fortune 500 list, published in June 2025. Fortune and Fortune Media IP Limited are not affiliated with, and do not endorse products or services of GitLab.

An overview of this role

The Corporate Security Identity Team is on a mission to transform how our workforce ecosystem securely accesses the tools they need to do their best work, advancing from foundational controls to sophisticated, automated governance across our identity platforms and our emerging AI tooling.
As a Staff Security Engineer, you'll be a senior technical leader and strategic anchor on the team. You're passionate about designing elegant solutions to complex identity challenges, whether that's architecting enterprise-scale conditional access policies, codifying our configuration of our identity platforms, or building governance frameworks for AI agents and non-human identities. You'll be responsible for critical systems, write technical proposals that influence our roadmap, raise the bar through design and code review, and lead cross-functional initiatives that span Security, IT, Engineering, Compliance and People teams.

We're deliberately moving off click-ops and low-code platforms. Configuration is becoming peer-reviewed code; automation is becoming tested code running on GCP Cloud Run. Join us to lean in!

What you’ll do  

  • Design comprehensive identity and AI access solutions that scale with our business growth, from AI agent governance frameworks to privileged access workflows that eliminate standing access through just-in-time provisioning
  • Replace low-code automation with engineered services, migrating our existingiPaaS automation to Python services on GCP Cloud Run with source control, tests, CI and observability 
  • Codify our identity platforms in Terraform/OpenTofu/Pulumi, leading the migration of Okta, Lumos, and our NHI platform from click-ops to peer-reviewed infrastructure-as-code, with a focus on global critical policies
  • Help re-architect identity and access across our GCP and AWS organizations, partnering on resource hierarchy design, secure-by-default guardrails (org policies, SCPs, permission boundaries), workload identity federation, and a credible path to least privilege for both human and workload access
  • Lead identity and access engineering for our enterprise AI platforms including administration, SSO and SCIM integration, audit logging, data controls, and policy enforcement for Claude (web, Claude Code, Cowork) and adjacent tools
  • Pioneer non-human identity governance by designing monitoring and management solutions for service accounts, API keys, certificates, AI agents, and MCP integrations, and leading deployment, integration, and operationalization of our NHI platform across the SaaS estate
  • Drive cross-functional initiatives with Security, IT, Engineering, Enterprise AI, and the Office of the CIO to extract requirements from ambiguous business needs and translate them into actionable technical specifications
  • Mentor senior and intermediate engineers on technical implementation and strategic thinking, helping them develop expertise in modern identity and AI security practices

What you’ll bring 

  • Extensive IAM experience designing and implementing enterprise-scale solutions, with demonstrated time at a Staff or senior IC level
  • Expert-level Okta expertise including Identity Engine, advanced authentication policies, lifecycle workflows, and API automation
  • Strong infrastructure-as-code practice with Terraform/OpenTofu/Pulumi, including provider experience for SaaS identity platforms and a track record of migrating click-ops to code
  • Proficiency writing and shipping Python as a software engineer designed as modular, tested, code-reviewed, deployed as services (GCP Cloud Run or equivalent serverless runtime) and instrumented for failure
  • Cloud identity depth in GCP and/or AWS, including resource hierarchy and organization design, IAM policy models, workload identity federation, and preventive controls such as org policies, SCPs, and permission boundaries
  • Hands-on experience administering or governing enterprise AI platforms (Anthropic Claude preferred; OpenAI ChatGPT Enterprise, Google Gemini Enterprise, or similar acceptable), and awareness of AI-specific risks including prompt injection, MCP attack surface, agent identity, and data leakage
  • A working practice of building with AI tooling you use agentic tools (Claude Code, Cursor, or similar) in your daily engineering work, iterate on your own workflows as capabilities shift, and can bring the rest of the team along. The tooling landscape changes monthly and identity is at the center of it; we want someone whose instincts stay current because they're a practitioner
  • Experience with IGA platforms like Lumos, ConductorOne, or similar, with a preference for managing them declaratively
  • Experience in regulated environments with knowledge of compliance frameworks (FedRAMP, SOC2, SOX), including change management, evidence collection, and audit support

Nice to have Qualifications:

  • Passion for emerging identity challenges including AI agent governance, non-human identity management, zero-trust architecture, and behavioral analytics
  • Experience carrying a cloud org restructuring through to completion, including the migration and stakeholder work, not just the target-state design

The base salary range for this role’s listed level is currently for residents of the United States only. This range is intended to reflect the role's base salary rate in locations throughout the US. Grade level and salary ranges are determined through interviews and a review of education, experience, knowledge, skills, abilities of the applicant, equity with other team members, alignment with market data, and geographic location. The base salary range does not include any bonuses, equity, or benefits. See more information on our benefits and equity. Sales roles are also eligible for incentive pay targeted at up to 100% of the offered base salary.

United States Salary Range
$168,000$238,000 USD
How GitLab Supports Full-Time Employees
  • Benefits to support your health, finances, and well-being
  • Flexible Paid Time Off 
  • Team Member Resource Groups
  • Equity Compensation & Employee Stock Purchase Plan
  • Growth and Development Fund
  • Parental Leave 

Please note that we welcome interest from candidates with varying levels of experience; many successful candidates do not meet every single requirement. Additionally, studies have shown that people from underrepresented groups are less likely to apply to a job unless they meet every single qualification. If you're excited about this role, please apply and allow our recruiters to assess your application.

Country Hiring Guidelines: GitLab hires new team members in countries around the world. All of our roles are remote, however some roles may carry specific location-based eligibility requirements. Our Talent Acquisition team can help answer any questions about location after starting the recruiting process.  

Privacy Policy: Please review our Recruitment Privacy Policy. Your privacy is important to us.

GitLab is proud to be an equal opportunity workplace and is an affirmative action employer. GitLab’s policies and practices relating to recruitment, employment, career development and advancement, promotion, and retirement are based solely on merit, regardless of race, color, religion, ancestry, sex (including pregnancy, lactation, sexual orientation, gender identity, or gender expression), national origin, age, citizenship, marital status, mental or physical disability, genetic information (including family medical history), discharge status from the military, protected veteran status (which includes disabled veterans, recently separated veterans, active duty wartime or campaign badge veterans, and Armed Forces service medal veterans), or any other basis protected by law. GitLab will not tolerate discrimination or harassment based on any of these characteristics. See also GitLab’s EEO Policy and EEO is the Law. If you have a disability or special need that requires accommodation, please let us know during the recruiting process.

Similar Jobs at GitLab

3 Days Ago
Easy Apply
Remote
Easy Apply
Senior level
Senior level
Cloud • Security • Software • Cybersecurity • Automation
Lead renewal analytics and forecasting for direct and channel motions. Build renewal health scoring and predictive models, improve Clari and SFDC processes, surface churn and expansion insights, partner with RevOps/Finance/IT, automate reporting, and present recommendations to senior stakeholders to improve retention and renewal performance.
Top Skills: ClariClaudeExcelGleanGoogle SheetsLookerSalesforceSisenseSnowflakeSQLTableau
3 Days Ago
Easy Apply
Remote
Easy Apply
Senior level
Senior level
Cloud • Security • Software • Cybersecurity • Automation
Lead pricing strategy and packaging across GitLab’s SaaS portfolio, including AI and usage-based products. Analyze market, competitor, customer, and usage data; build financial models; evaluate monetization opportunities; support product launches and SKU mapping; monitor post-launch results; and influence senior leaders across Product, Marketing, Finance, Sales, Deal Desk, and fulfillment.
Top Skills: SisenseTableau
3 Days Ago
Easy Apply
Remote
Easy Apply
Mid level
Mid level
Cloud • Security • Software • Cybersecurity • Automation
Full lifecycle recruiter supporting AMER sales roles: sourcing passive and active candidates, partnering with hiring teams, using ATS and sourcing tools, leveraging market data and metrics to improve pipelines and candidate experience during a six-month contract.
Top Skills: GitGitlabGreenhouseLinkedin Recruiter

What you need to know about the Dublin Tech Scene

From Bono and Oscar Wilde to today's tech leaders, Dublin has always attracted trailblazers, with more than 70,000 people working in the city's expanding digital sector. Continuing its legacy of drawing pioneers, the city is advancing rapidly. Ireland is now ranked as one of the top tech clusters in the region and the number one destination for digital companies, with the highest hiring intention of any region across all sectors.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account