GitLab4 дня назад
Staff Infrastructure Security Engineer (USA)
Зарплата не указана
РЫНОК
10 833 ₽медиана по профессии
Security Engineer · 5 вакансий с указанной зарплатой
8 417половина предложений: 8 500–15 00016 667
Работодатель не указал зарплату — сравните с рынком сами.
Remote
Обязанности
- 01Set the technical direction, architectural patterns, reference implementations, and foundational security automation for infrastructure security in GitLab's FedRAMP environment
- 02Own the security posture of GitLab's FedRAMP environment as the senior technical voice, partnering with the Public Sector SRE team
- 03Lead infrastructure security initiatives from problem framing through delivery, scoping ambiguous multi-quarter work
- 04Conduct and lead comprehensive security reviews and threat modeling for complex infrastructure components in the Federal environment
- 05Set the team's approach to AI-assisted security engineering within the constraints of a FedRAMP-authorized environment
- 06Serve as an authoritative technical voice for Federal Infrastructure Security across stakeholders
- 07Partner on technical planning, prioritization, and roadmap development
- 08Mentor and develop engineers on the team
- 09Fulfill the Product Security Division Mission of securing GitLab Infrastructure with our own product
Требования
- 01Proof of U.S. citizenship and U.S. residency
- 02Expert knowledge of security for cloud infrastructure (AWS/GCP/Azure), container orchestration (Kubernetes) and related infrastructure and data security topics
- 03Deep working knowledge of FedRAMP (Moderate and/or High) and the operational realities of running and continuously monitoring an authorized environment
- 04Familiarity with adjacent frameworks and standards (NIST 800-53, FIPS 140-2/3, ISO 27001, SOC 2, PCI-DSS)
- 05Proficiency in multiple programming languages (Go, Python, Ruby) with a track record of delivering production-quality security tooling
- 06Extensive experience with Infrastructure-as-Code security (Terraform, Ansible, CloudFormation), policy-as-code, and automated compliance
- 07Hands-on experience applying AI to security workflows, with a point of view on where it creates meaningful leverage in compliance-constrained environments
- 08Track record of leading multi-team technical initiatives from ambiguous problem statements to measurable outcomes
- 09Strong written and verbal communication skills, able to explain security and compliance tradeoffs to technical and non-technical audiences
- 10Share our values, and work in accordance with those values
Условия
- 01Must be a United States Citizen
- 02Must be based in the United States