Staff Security Engineer, IAM

GitLab

United States

On-site

USD 180,000 - 240,000

Full time

11 days ago
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

GitLab is seeking a Staff Security Engineer to lead identity and AI security initiatives across the enterprise. You’ll design scalable access controls, governance frameworks, and automation that reduces risk while enabling teams to move fast.

You will codify identity platforms, migrate from click-ops to code, and mentor engineers, partnering with Security, IT, Engineering, and Enterprise AI to translate complex business needs into robust technical solutions.

Qualifications

  • Extensive IAM experience designing enterprise-scale solutions.
  • Expert-level Okta Identity Engine and API automation.
  • Strong IaC experience with Terraform/OpenTofu/Pulumi and migrating from click-ops to code.
  • Proficiency writing Python for modular, tested services deployed on serverless runtimes.

Responsibilities

  • Design scalable identity and AI access solutions that grow with the business.
  • Replace low-code automation with engineered services on GCP Cloud Run with source control and tests.
  • Codify identity platforms in Terraform/OpenTofu/Pulumi, migrating from click-ops to code.
  • Architect identity across GCP and AWS with guardrails, least privilege, and federation.
  • Lead identity and access engineering for enterprise AI platforms including SSO and SCIM.
  • Pioneer non-human identity governance for service accounts and API keys.
  • Collaborate with Security, IT, Engineering, Enterprise AI to translate needs into specs.
  • Mentor senior engineers on modern identity and AI security practices.

Skills

IAM design
Enterprise security
Okta expertise
Infrastructure as code
Python programming
Cloud platforms
Leadership
Mentoring

Tools

Terraform
OpenTofu
Pulumi
Okta
GCP Cloud Run
CI/CD

Job description

GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50 million registered users and more than 50% of the Fortune 100* trust GitLab to ship better, more secure software faster.

The same principles built into our products are reflected in how our team works: we embrace AI as a core productivity multiplier, with all team members expected to incorporate AI into their daily workflows to drive efficiency, innovation, and impact. GitLab is where careers accelerate, innovation flourishes, and every voice is valued. Our high-performance culture is driven by our values and continuous knowledge exchange, enabling our team members to reach their full potential while collaborating with industry leaders to solve complex problems. Co-create the future with us as we build technology that transforms how the world develops software.

* Fortune 500® is a registered trademark of Fortune Media IP Limited, used under license. Claim based on GitLab data. Fortune 100 refers to the top 20% ranked companies in the 2025 Fortune 500 list, published in June 2025. Fortune and Fortune Media IP Limited are not affiliated with, and do not endorse products or services of GitLab.

An overview of this role

The Corporate Security Identity Team is on a mission to transform how our workforce ecosystem securely accesses the tools they need to do their best work, advancing from foundational controls to sophisticated, automated governance across our identity platforms and our emerging AI tooling.

As a Staff Security Engineer, you'll be a senior technical leader and strategic anchor on the team. You're passionate about designing elegant solutions to complex identity challenges, whether that's architecting enterprise-scale conditional access policies, codifying our configuration of our identity platforms, or building governance frameworks for AI agents and non-human identities. You'll be responsible for critical systems, write technical proposals that influence our roadmap, raise the bar through design and code review, and lead cross-functional initiatives that span Security, IT, Engineering, Compliance and People teams.

We're deliberately moving off click-ops and low-code platforms. Configuration is becoming peer-reviewed code; automation is becoming tested code running on GCP Cloud Run. Join us to lean in!

What you'll do
  • Design comprehensive identity and AI access solutions that scale with our business growth, from AI agent governance frameworks to privileged access workflows that eliminate standing access through just-in-time provisioning
  • Replace low-code automation with engineered services, migrating our existingiPaaS automation to Python services on GCP Cloud Run with source control, tests, CI and observability
  • Codify our identity platforms in Terraform/OpenTofu/Pulumi , leading the migration of Okta, Lumos, and our NHI platform from click-ops to peer-reviewed infrastructure-as-code, with a focus on global critical policies
  • Help re-architect identity and access across our GCP and AWS organizations, partnering on resource hierarchy design, secure-by-default guardrails (org policies, SCPs, permission boundaries), workload identity federation, and a credible path to least privilege for both human and workload access
  • Lead identity and access engineering for our enterprise AI platforms including administration, SSO and SCIM integration, audit logging, data controls, and policy enforcement for Claude (web, Claude Code, Cowork) and adjacent tools
  • Pioneer non-human identity governance by designing monitoring and management solutions for service accounts, API keys, certificates, AI agents, and MCP integrations, and leading deployment, integration, and operationalization of our NHI platform across the SaaS estate
  • Drive cross-functional initiatives with Security, IT, Engineering, Enterprise AI, and the Office of the CIO to extract requirements from ambiguous business needs and translate them into actionable technical specifications
  • Mentor senior and intermediate engineers on technical implementation and strategic thinking, helping them develop expertise in modern identity and AI security practices
What you'll bring
  • Extensive IAM experience designing and implementing enterprise-scale solutions, with demonstrated time at a Staff or senior IC level
  • Expert-level Okta expertise including Identity Engine, advanced authentication policies, lifecycle workflows, and API automation
  • Strong infrastructure-as-code practice with Terraform/OpenTofu/Pulumi , including provider experience for SaaS identity platforms and a track record of migrating click-ops to code
  • Proficiency writing and shipping Python as a software engineer designed as modular, tested, code-reviewed, deployed as services (GCP Cloud Run or equivalent serverless runtime) and instrumented for fail
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff IAM & AI Security Engineer
Staff IAM & AI Security Engineer

GitLab • United States

On-site
USD 180,000 - 240,000
Cybersecurity IAM Architect - Staff Engineer
Cybersecurity IAM Architect - Staff Engineer

OneMain Financial • Maryland

On-site
USD 140,000 - 190,000
Principal Software Engineer (Identity Services)
Principal Software Engineer (Identity Services)

INSPYR Solutions • Beverly Hills (CA)

Hybrid
USD 180,000 - 240,000
Senior Security Engineer
Senior Security Engineer

twentysix • El Segundo (CA)

On-site
USD 120,000 - 180,000
Staff Identity Engineer
Staff Identity Engineer

United States Digital Space LLC • Washington

On-site
USD 161,000 - 221,000
Equity
Health insurance
Dental & Vision insurance
+1
Sr IAM Cloud Engineer
Sr IAM Cloud Engineer

HealthEquity • United States

On-site
USD 130,000 - 180,000
Staff Identity Governance and Access Engineer
Staff Identity Governance and Access Engineer

United States Digital Space LLC • Washington

On-site
USD 180,000 - 230,000
Lead Engineer, IAM Platform Engineering
Lead Engineer, IAM Platform Engineering

Jobtailor • Pennsylvania

On-site
USD 150,000 - 190,000
Senior AI Platform Security Engineer - Contract to Hire San Francisco, CA
Senior AI Platform Security Engineer - Contract to Hire San Francisco, CA

FrontApp Inc. • San Francisco (CA), Northern (KY)

Hybrid
USD 180,000 - 260,000
Senior Engineering Manager (Identity & Access Management)
Senior Engineering Manager (Identity & Access Management)

Tulip Interfaces • Somerville (MA)

On-site
USD 180,000 - 240,000
Health insurance
Dental
Vision
+4