Enable job alerts via email!

Staff Security Engineer, Product Security Risk & Metrics

GitLab

Canada

Remote

CAD 80,000 - 120,000

Full time

Today
Be an early applicant

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

Ein innovatives Unternehmen sucht einen Staff Security Engineer, der sich auf Produkt-Sicherheitsrisiken und Metriken konzentriert. In dieser spannenden Rolle werden Sie Key Risk Indicators (KRIs) entwickeln und Datenanalysen durchführen, um Trends zu identifizieren und informierte Entscheidungen zu treffen. Sie werden auch für die Pflege des Product Security Risk Register verantwortlich sein und sicherstellen, dass Risiken effektiv gemanagt werden. Diese Position bietet die Möglichkeit, in einem dynamischen, remote-freundlichen Umfeld zu arbeiten und einen bedeutenden Beitrag zur Sicherheit des Produkts zu leisten.

Qualifications

  • 5+ Jahre Erfahrung in Produkt-Sicherheit oder DevSecOps.
  • Kenntnisse in der Entwicklung von Sicherheitsmetriken und KRIs.

Responsibilities

  • Erstellen und Pflegen von KRIs zur Überwachung von Produktsicherheitsrisiken.
  • Entwickeln von Visualisierungen zur Verfolgung von Risiken und Fortschritten.

Skills

Produkt-Sicherheit
DevSecOps
Risikomanagement
Datenanalyse
Visualisierungstools (z.B. Tableau, Power BI)
Analytische Fähigkeiten
Stakeholder-Management

Education

5+ Jahre Erfahrung in relevanten Bereichen
Sicherheitszertifikate (CISSP, CISM, CRISC)

Tools

GitLab
Jira
Asana
Tableau
Power BI

Job description

Staff Security Engineer, Product Security Risk & Metrics

Join to apply for the Staff Security Engineer, Product Security Risk & Metrics role at GitLab.

GitLab is an open core software company developing the most comprehensive AI-powered DevSecOps Platform, used by over 100,000 organizations. Our mission is to enable everyone to contribute to and co-create the software that powers our world, fostering a culture of contribution and innovation.

This role focuses on developing Key Risk Indicators (KRIs), designing data collection systems, and creating visualizations to demonstrate our product security posture, measure team effectiveness, and drive data-informed decisions. You will operationalize our Product Security Risk Register and facilitate cross-functional alignment to ensure risk reduction initiatives are effectively managed.

Responsibilities
  • Create and maintain KRIs to monitor product security risks
  • Engineer tracking systems and visualizations for risk and remediation progress
  • Apply data analysis to identify trends and inform risk management
  • Design metrics collection systems for strategic and operational effectiveness
  • Maintain the Product Security Risk Register and related workflows
  • Manage operational cadences like risk reviews and action tracking
  • Coordinate across teams to align risk reduction efforts
  • Ensure risk tracking aligns with broader risk management programs
  • Serve as the central coordinator for risk register operations and stakeholder reporting
Qualifications
  • 5+ years in product security, DevSecOps, risk management, or data analytics
  • Understanding of secure development and product security risks
  • Experience developing security metrics, KRIs, and dashboards
  • Ability to translate security data into visual insights
  • Proficiency with visualization tools (e.g., Tableau, Power BI)
  • Experience with workflows in ticketing systems like GitLab, Jira, Asana
  • Strong analytical skills and experience with automation and scripting
  • Stakeholder management and communication skills
Preferred Qualifications
  • Experience with security initiatives in product and engineering teams
  • Familiarity with GitLab and DevSecOps
  • Experience with risk registers, vulnerability management, threat modeling, security reviews, pentesting
  • Security certifications (CISSP, CISM, CRISC, etc.) and project management certifications (PMP)
  • Knowledge of risk assessment frameworks (NIST RMF, FAIR, ISO 31000) and compliance standards (FedRAMP, SOC 2, ISO 27001, PCI-DSS)
  • Experience in a rapidly scaling tech environment

We are committed to diversity and equal opportunity. All roles are remote, with location-based eligibility where applicable. Review our Privacy Policy.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Director of Operations

BeMo Academic Consulting

Remote

CAD 110.000 - 150.000

8 days ago

Product Support Engineer, Level 2

Jacobs Engineering Group Inc.

Burnaby

Remote

CAD 79.000 - 84.000

7 days ago
Be an early applicant

Staff Security Engineer, Product Security Risk & Metrics

GitLab

Remote

CAD 90.000 - 150.000

30+ days ago

Staff Product Engineer, Growth (100% remote)

vidIQ

Remote

CAD 70.000 - 110.000

4 days ago
Be an early applicant

Cyber Security Specialist

Affinity

Regina

On-site

CAD 80.000 - 110.000

Today
Be an early applicant

Senior Information Security Analyst

TD

On-site

CAD 76.000 - 116.000

Yesterday
Be an early applicant

Senior Information Security Analyst

TD Bank

Toronto

Hybrid

CAD 76.000 - 116.000

4 days ago
Be an early applicant

Business Intelligence Specialist

TD Bank

Toronto

Hybrid

CAD 91.000 - 137.000

11 days ago

Added - 8 minutes ago Senior Cybersecurity Specialist Security Analyst Regina , Saskatchewan

InSync Systems

Regina

On-site

CAD 80.000 - 120.000

Yesterday
Be an early applicant