GitLab4 дня назад

Staff Infrastructure Security Engineer (USA)

Зарплата не указана
РЫНОК
10 833медиана по профессии
Security Engineer · 5 вакансий с указанной зарплатой
8 417половина предложений: 8 500–15 00016 667
Работодатель не указал зарплату — сравните с рынком сами.
Remote

Обязанности

  • 01Set the technical direction, architectural patterns, reference implementations, and foundational security automation for infrastructure security in GitLab's FedRAMP environment
  • 02Own the security posture of GitLab's FedRAMP environment as the senior technical voice, partnering with the Public Sector SRE team
  • 03Lead infrastructure security initiatives from problem framing through delivery, scoping ambiguous multi-quarter work
  • 04Conduct and lead comprehensive security reviews and threat modeling for complex infrastructure components in the Federal environment
  • 05Set the team's approach to AI-assisted security engineering within the constraints of a FedRAMP-authorized environment
  • 06Serve as an authoritative technical voice for Federal Infrastructure Security across stakeholders
  • 07Partner on technical planning, prioritization, and roadmap development
  • 08Mentor and develop engineers on the team
  • 09Fulfill the Product Security Division Mission of securing GitLab Infrastructure with our own product

Требования

  • 01Proof of U.S. citizenship and U.S. residency
  • 02Expert knowledge of security for cloud infrastructure (AWS/GCP/Azure), container orchestration (Kubernetes) and related infrastructure and data security topics
  • 03Deep working knowledge of FedRAMP (Moderate and/or High) and the operational realities of running and continuously monitoring an authorized environment
  • 04Familiarity with adjacent frameworks and standards (NIST 800-53, FIPS 140-2/3, ISO 27001, SOC 2, PCI-DSS)
  • 05Proficiency in multiple programming languages (Go, Python, Ruby) with a track record of delivering production-quality security tooling
  • 06Extensive experience with Infrastructure-as-Code security (Terraform, Ansible, CloudFormation), policy-as-code, and automated compliance
  • 07Hands-on experience applying AI to security workflows, with a point of view on where it creates meaningful leverage in compliance-constrained environments
  • 08Track record of leading multi-team technical initiatives from ambiguous problem statements to measurable outcomes
  • 09Strong written and verbal communication skills, able to explain security and compliance tradeoffs to technical and non-technical audiences
  • 10Share our values, and work in accordance with those values

Условия

  • 01Must be a United States Citizen
  • 02Must be based in the United States