GitLab
Staff Corporate Security Engineer
Remote work allowed only within certain countries or regions.
Employer listed it 9 days ago · Added 5 days ago
First listed 9 days ago and still open.
Salary
$168,000 to $238,000
Location
Work style
Async
Contract
Full-time
Experience
Lead
Category
Software
Stated by the employer in the job description
Remote flexibility
Region Restricted
Remote work is allowed, but only for candidates based in Canada, United States.
What the employer says
- Source listing states candidate location: "Remote, Canada; Remote, United States"
- Job description states: "residents of the United States only. This range"
What Nomaders makes of it
- Timezone overlap with the listed area is often expected
The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.
About the role
GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50 million registered users and more than 50% of the Fortune 100* trust GitLab to ship better, more secure software faster.
The same principles built into our products are reflected in how our team works: we embrace AI as a core productivity multiplier, with all team members expected to incorporate AI into their daily workflows to drive efficiency, innovation, and impact. GitLab is where careers accelerate, innovation flourishes, and every voice is valued. Our high-performance culture is driven by our values and continuous knowledge exchange, enabling our team members to reach their full potential while collaborating with industry leaders to solve complex problems. Co-create the future with us as we build technology that transforms how the world develops software.
* Fortune 500® is a registered trademark of Fortune Media IP Limited, used under license. Claim based on GitLab data. Fortune 100 refers to the top 20% ranked companies in the 2025 Fortune 500 list, published in June 2025. Fortune and Fortune Media IP Limited are not affiliated with, and do not endorse products or services of GitLab.
An overview of this role
As a Senior Corporate Security Engineer, you'll help secure the systems GitLab team members rely on every day across a fully remote environment. This role sits within Corporate Security Engineering and focuses on building secure-by-default controls for endpoints and the SaaS platforms that support them, with a strong emphasis on macOS. You'll own meaningful technical decisions around endpoint hardening, automation, and detection, and you'll help turn security requirements into scalable engineering systems that are measurable, auditable, and designed to reduce friction for end users.
This is a strong fit if you're motivated by solving security problems with code. You will work across endpoint management, identity, and security operations to improve how GitLab manages macOS, iOS, Windows, and Linux devices through Infrastructure-as-Code, Terraform, and GitOps workflows. In your first year, you'll be expected to strengthen endpoint security architecture, expand automation, and improve the reliability and auditability of how controls are deployed and maintained.
What you’ll do
Lead the security architecture of GitLab's endpoint fleet and related infrastructure, with a primary focus on macOS.
Design and support automation for secure endpoint deployment, configuration, and lifecycle management using code-based workflows.
Manage endpoint and SaaS security configuration through Terraform, version control, merge requests, continuous integration pipelines, and automated rollouts.
Define and enforce security baselines across macOS, iOS, Windows, and Linux endpoints.
Develop patching and software distribution approaches that align with security, compliance, and operational requirements.
Partner with Information Technology, Security Operations, and Detection and Response teams to improve endpoint telemetry, detections, and response models.
Drive process improvements that reduce manual work and lower risk by favoring automation, policy-driven controls, and auditable change management.
Mentor engineers across Corporate Security and Information Technology, and serve as a senior escalation point for complex endpoint security issues.
What you’ll bring
Experience designing and delivering endpoint, systems, or corporate security solutions in environments that require scalable, durable controls.
Deep knowledge of endpoint management platforms such as Jamf Pro or FleetDM, especially for architecting and securing macOS environments.
Strong hands-on ability with Terraform and Infrastructure-as-Code practices, including module design, state management, and pipeline-based deployment.
Experience working with GitOps workflows where changes are managed through Git repositories, merge requests, code review, and automated pipelines.
Strong proficiency in scripting or programming for automation and security tooling, such as bash, Python, PowerShell, or Go.
Familiarity with cloud identity providers and directories, including platforms such as Okta, Google Workspace, LDAP.
Ability to communicate clearly, collaborate across distributed teams, and work independently in an all-remote environment.
Openness to bringing transferable experience from adjacent security, systems, or platform engineering backgrounds, along with a practical and security-focused approach to problem solving.
Requirements
- ·Experience designing and delivering endpoint, systems, or corporate security solutions in environments that require scalable, durable controls.
- ·Deep knowledge of endpoint management platforms such as Jamf Pro or FleetDM, especially for architecting and securing macOS environments.
- ·Strong hands-on ability with Terraform and Infrastructure-as-Code practices, including module design, state management, and pipeline-based deployment.
- ·Experience working with GitOps workflows where changes are managed through Git repositories, merge requests, code review, and automated pipelines.
- ·Strong proficiency in scripting or programming for automation and security tooling, such as bash, Python, PowerShell, or Go.
Benefits
- ·Flexible Paid Time Off
- ·Team Member Resource Groups
- ·Equity Compensation & Employee Stock Purchase Plan
- ·Growth and Development Fund
How to apply
- 1Check the flexibility label above, region restricted, matches where you plan to live and work.
- 2Tailor your CV to the role at GitLab, mentioning your remote working experience and working hours (Async).
- 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.
Found 5d ago. Last checked 23 Sept. Always confirm the details on the original posting, salary and location can change after publication.
Listing sourced from Company boards.
Similar roles
Other open software roles with comparable remote rules.
Free to apply, no account needed.
$168,000 to $238,000 · You'll be taken to the employer's careers page.