Overview
GitLab is an open-core software company that develops the AI-powered DevSecOps Platform used by more than 100,000 organizations. Our mission is to enable everyone to contribute to and co-create software. We value AI as a core productivity multiplier and expect team members to incorporate AI into daily workflows to drive efficiency, innovation, and impact. Co-create the future with us as we build technology that transforms how the world develops software.
About the Role
GitLab is seeking an experienced Principal Field Security Engineer to tackle complex customer security challenges at the intersection of technical architecture and business requirements. You will apply deep security expertise to answer technical questions, assess contract requirements, and enable GitLab’s Sales and field organizations to address security problems for enterprise customers. You will work directly with customers and internal teams to provide technical guidance, create security content, and help customers understand how GitLab's security controls meet their compliance and risk management needs.
What You’ll Do
- Customer Engagement & Assurance: Serve as the primary security point of contact for enterprise customer questions, requests, and concerns; join customer and prospect meetings to provide expert guidance on GitLab’s security practices and controls to address security, privacy, and compliance requirements; build and maintain templates, playbooks, fallback positions, and training that simplify and accelerate negotiations; facilitate customer assurance activities through our Customer Assurance Activities Service Desk; provide escalation support for complex security questionnaires, RFPs, and risk assessments.
- Contract & Legal Review: Perform comprehensive contract reviews for both customer agreements and vendor relationships; analyze security and compliance clauses in legal documents; provide risk-based recommendations and remediation guidance for contractual security requirements; partner with Legal, Sales, Product, and Procurement teams to negotiate security-related contract terms, manage escalations, and develop solutions to enable teams to close deals; document and track contract-related security obligations.
- Security Evangelism & Thought Leadership: Act as a trusted technical thought leader, developing internal and external security content such as blog posts, whitepapers, technical standards, and field sales enablement training materials; stay abreast of regulatory changes affecting our agreements; identify and facilitate solutions for security-related customer trends and improvement areas; build and strengthen GitLab's security brand within the industry.
- Strategic Initiatives: Maintain and enhance GitLab's Trust Center and self-service security resources; provide strategic recommendations based on customer security concerns to support revenue growth; participate in Quarterly Business Reviews to inform product and security roadmap decisions; mentor Security Assurance team members; drive continuous improvement of Field Security processes and documentation; design and implement solutions to enable Sales-facing teams to discuss security problems with customers.
What You’ll Bring
- 10+ years of experience in information security, with at least 5 years in customer-facing security roles
- Deep expertise in security frameworks and standards such as SOC 2, ISO 27001, FedRAMP, GDPR, NIST, etc.
- Proven track record of contract negotiation and security/privacy agreement reviews
- Excellent written and verbal communication skills with ability to translate complex technical concepts for diverse audiences
- Experience creating security content (blogs, whitepapers, presentations); experience speaking at conferences is a plus
- Strong understanding of cloud security, SaaS security models, and DevSecOps practices
- Experience working cross-functionally with Sales, Legal, Product, and Engineering teams
- Ability to balance security risk with business objectives
EEO & Accessibility
GitLab is proud to be an equal opportunity workplace and an affirmative action employer. We value merit-based recruitment and do not discriminate based on protected characteristics. If you have a disability or special need that requires accommodation, please let us know during the recruiting process.
Note on Applicants
Please apply if you’re excited about this role. While we welcome diverse experiences, some requirements may be open to variation.