Search...

Senior Manager, Security Compliance

GitLab Inc. logo
GitLab Inc.

GitLab is an AI-powered DevSecOps platform that unifies the entire software development lifecycle into a single application. It helps development, security, and operations teams to collaborate and deliver software more efficiently, with security integrated at every step. The platform is trusted by millions of users and a majority of the Fortune 100.

Distributed
About GitLab Inc.

GitLab is a comprehensive, AI-powered DevSecOps platform that streamlines the entire software delivery process by unifying the development lifecycle into a single application. It integrates source code management, CI/CD, security, and monitoring to help teams build, secure, and operate software more efficiently. Key features include automated security scans built into the development pipeline and AI-driven tools like GitLab Duo for code suggestions and chat, which enhance developer productivity. GitLab serves a diverse client base, from startups and open-source projects to large enterprises, including over half of the Fortune 100. The platform aims to reduce complexity, accelerate delivery cycles, and strengthen security and compliance for its users.

View jobs by GitLab Inc.

Skills

About the Role

You will lead and develop the security compliance function, setting priorities and supporting a high-performing team. You will expand certification coverage, partner with IT, Security, Legal, Product, and Engineering, and integrate governance, risk, and compliance requirements into processes and systems. You will use scripting, coding, AI-enabled methods, compliance-as-code, and policy-as-code to improve workflows. You will monitor regulatory developments, manage auditor and assessor relationships, strengthen metrics and reporting, and provide guidance and training to internal teams, customers, and senior stakeholders.

Requirements

  • Extensive experience in security compliance, audit, or governance, risk, and compliance work, including external audit support.
  • Deep knowledge of SOC 2, ISO 27001, FedRAMP, and NIST frameworks.
  • Experience leading teams and developing people.
  • Understanding of cloud security, SaaS security models, and DevSecOps practices.
  • Ability to apply risk-based control design, testing, and continuous improvement.
  • Experience with automation, scripting, or AI-enabled approaches for compliance programs.
  • Excellent written and verbal communication skills.
  • United States citizenship.
  • CISSP, CISM, CISA, or similar certifications are highly desirable.

Responsibilities

  • Lead and mentor the security compliance team.
  • Oversee and expand the certification portfolio across security and compliance frameworks.
  • Partner with IT, Security, Legal, Product, and Engineering to integrate governance, risk, and compliance requirements.
  • Drive automation, scripting, coding, and AI-enabled improvements to compliance workflows.
  • Monitor regulatory changes, emerging frameworks, and industry trends to shape the roadmap.
  • Manage relationships with third-party auditors, assessors, and consultants.
  • Strengthen security metrics and reporting and facilitate regular business reviews.
  • Deliver security guidance, training, and content for internal teams, customers, and senior stakeholders.

Benefits

  • Health, financial, and well-being benefits.
  • Flexible Paid Time Off.
  • Team Member Resource Groups.
  • Equity compensation and Employee Stock Purchase Plan.
  • Growth and Development Fund.
  • Parental Leave.
Senior Manager, Security Compliance at GitLab Inc. | JobStash