
Staff Infrastructure Security Engineer
Posted 5 days ago

Posted 5 days ago
This is a fully remote position, open to applicants in United States.
• Establish the technical direction, architectural frameworks, reference implementations, and foundational security automation for infrastructure security within GitLab's FedRAMP environment and its wider Dedicated and Self-Managed offerings.
• Take ownership of the security posture of GitLab's FedRAMP environment as the primary technical authority, collaborating with the Public Sector SRE team.
• Drive infrastructure security initiatives from problem identification to delivery, including FedRAMP continuous monitoring, control implementation, and changes impacting authorization.
• Perform and lead thorough security reviews and threat modeling for intricate infrastructure components in the Federal environment.
• Define the team's strategy for AI-assisted security engineering within a FedRAMP-authorized setting.
• Act as a recognized technical authority across engineering, compliance, and senior leadership, clarifying architectural trade-offs and the implications of FedRAMP controls into comprehensible decisions.
• Collaborate on technical planning, prioritization, and roadmap development for Public Sector infrastructure security.
• Mentor and nurture engineers within the team.
• Uphold the Product Security Division Mission of safeguarding GitLab Infrastructure using GitLab's own product ("dogfooding").
• Proof of U.S. citizenship and residency.
• In-depth expertise in security for cloud infrastructure (AWS/GCP/Azure), container orchestration (Kubernetes), and associated infrastructure and data security topics.
• Profound working knowledge of FedRAMP (Moderate and/or High) and the operational nuances of managing and continuously monitoring an authorized environment.
• Awareness of NIST 800-53, FIPS 140-2/3, ISO 27001, SOC 2, PCI-DSS.
• Proficient in several programming languages (Go, Python, Ruby) with a proven history of delivering production-quality security tools.
• Significant experience with Infrastructure-as-Code security (Terraform, Ansible, CloudFormation), policy-as-code, and automated compliance, especially in regulated environments.
• Practical experience in applying AI to security workflows, with insights on where it adds significant value in compliance-constrained settings.
• A track record of leading multi-team technical initiatives from vague problem statements to measurable results, establishing technical direction that other teams embrace.
• Excellent written and verbal communication abilities, capable of discussing security and compliance trade-offs with both technical and non-technical audiences, including senior leadership and assessors.
• Align with GitLab's values and operate in accordance with those principles.
• Benefits designed to enhance your health, financial stability, and overall well-being.
• Flexible Paid Time Off.
• Team Member Resource Groups.
• Equity Compensation & Employee Stock Purchase Plan.
• Growth and Development Fund.
• Parental Leave.
Primer
Akamai Technologies
Mashreq
Alice
Get handpicked remote jobs straight to your inbox weekly.