GitLab - Staff Security Engineer, IAM (USA)
Upload My Resume
Drop here or click to browse · Tap to choose · PDF, DOCX, DOC, RTF, TXT
Requirements
• 8+ years of IAM experience designing and implementing enterprise-scale solutions, with demonstrated time at a Staff or senior IC level • Expert-level Okta expertise including Identity Engine, advanced authentication policies, lifecycle workflows, and API automation • Expert-level Okta expertise • Strong infrastructure-as-code practice with Terraform, including provider experience for SaaS identity platforms and a track record of migrating click-ops to code • Strong infrastructure-as-code practice with Terraform • Hands-on experience administering or governing enterprise AI platforms (Anthropic Claude preferred; OpenAI ChatGPT Enterprise, Google Gemini Enterprise, or similar acceptable), and awareness of AI-specific risks including prompt injection, MCP attack surface, agent identity, and data leakage • Hands-on experience administering or governing enterprise AI platforms • Strong automation experience using Python and iPaaS tools (Tines, Okta Workflows) • Experience with IGA platforms like Lumos, ConductorOne, or similar • Working knowledge of non-human identity tooling (Token Security, Oasis, Astrix, or similar), or equivalent experience governing service accounts, OAuth grants, and workload identities • Working knowledge of non-human identity tooling • Experience in regulated environments with knowledge of compliance frameworks (FedRAMP, SOC2, SOX), including change management, evidence collection, and audit support • Collaborative mindset and strategic communication skills for writing technical proposals, leading cross-functional initiatives, and mentoring teammates • Collaborative mindset and strategic communication skills • Nice to have Qualifications: Passion for emerging identity challenges including AI agent governance, non-human identity management, zero-trust architecture, and behavioral analytics; Active user of Claude Code, Cursor, or similar agentic development tools, with intuition for how engineers integrate them into daily workflows • Due to government requirements, you must be a United States Citizen (defined as any individual who is a citizen of the United States by law, birth, or naturalization) to fill this position. • The base salary range for this role’s listed level is currently for residents of the United States only. This range is intended to reflect the role's base salary rate in locations throughout the US. Grade level and salary ranges are determined through interviews and a review of education, experience, knowledge, skills, abilities of the applicant, equity with other team members, alignment with market data, and geographic location. The base salary range does not include any bonuses, equity, or benefits. See more information on our benefits and equity. Sales roles are also eligible for incentive pay targeted at up to 100% of the offered base salary.
Responsibilities
• Design comprehensive identity and AI access solutions that scale with our business growth, from AI agent governance frameworks to privileged access workflows that eliminate standing access through just-in-time provisioning • Design comprehensive identity and AI access solutions • Lead identity and access engineering for our enterprise AI platforms including administration, SSO and SCIM integration, audit logging, data controls, and policy enforcement for Claude (web, Claude Code, Cowork) and adjacent tools • Lead identity and access engineering for our enterprise AI platforms • Codify our identity platforms in Terraform, leading the migration of Okta, Lumos, and our NHI platform from click-ops to peer-reviewed infrastructure-as-code, with a focus on global critical policies • Codify our identity platforms in Terraform • Refactor our authentication framework to implement advanced conditional access controls such as device trust, location-based policies, risk-based step-up authentication, and behavioral analytics across our entire SaaS ecosystem • Refactor our authentication framework • Pioneer non-human identity governance by designing monitoring and management solutions for service accounts, API keys, certificates, AI agents, and MCP integrations, and leading deployment, integration, and operationalization of our NHI platform across the SaaS estate • Pioneer non-human identity governance • Drive cross-functional initiatives with Security, IT, Engineering, Enterprise AI, and the Office of the CIO to extract requirements from ambiguous business needs and translate them into actionable technical specifications • Drive cross-functional initiatives • Mentor senior and intermediate engineers on technical implementation and strategic thinking, helping them develop expertise in modern identity and AI security practices • Mentor senior and intermediate engineers
Benefits
• $168,000—$238,000 USD • How GitLab Supports Full-Time Employees • Benefits to support your health, finances, and well-being • Flexible Paid Time Off • Team Member Resource Groups • Equity Compensation & Employee Stock Purchase Plan • Growth and Development Fund • Please note that we welcome interest from candidates with varying levels of experience; many successful candidates do not meet every single requirement. Additionally, studies have shown that people from underrepresented groups are less likely to apply to a job unless they meet every single qualification. If you're excited about this role, please apply and allow our recruiters to assess your application. • Country Hiring Guidelines: GitLab hires new team members in countries around the world. All of our roles are remote, however some roles may carry specific location-based eligibility requirements. Our Talent Acquisition team can help answer any questions about location after starting the recruiting process. • Country Hiring Guidelines:
No credit card. Takes 10 seconds.