Enable job alerts via email!

Staff Security Engineer, Product Security Risk & Metrics

GitLab

United States

Remote

USD 90,000 - 150,000

Full time

7 days ago
Be an early applicant

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

An established industry player is seeking a Staff Security Engineer to enhance product security through innovative metrics and data analysis. This role involves creating Key Risk Indicators and developing robust data collection systems to monitor security posture and drive informed decisions. The ideal candidate will possess a strong background in product security, data analytics, and stakeholder management, making a significant impact on the organization's security initiatives. Join a forward-thinking team that embraces AI and fosters collaboration to ensure the highest security standards across all products.

Benefits

Flexible working hours
Remote work options
Health insurance
Professional development opportunities
Paid time off
Retirement savings plan
Wellness programs
Employee assistance programs

Qualifications

  • 5+ years of experience in product security and data analytics.
  • Proven ability to develop security metrics and KRIs.
  • Strong analytical skills with complex data sets.

Responsibilities

  • Create and maintain Key Risk Indicators for product security risk.
  • Engineer data collection systems and visualizations for security metrics.
  • Drive cross-functional alignment to ensure risk reduction initiatives.

Skills

Product Security
Data Analysis
Stakeholder Management
Secure Development Practices
Automation and Scripting
Analytical Skills
Communication Skills

Education

Bachelor's Degree in Computer Science or related field

Tools

Tableau
Power BI
GitLab
Jira
Asana

Job description

GitLab is an open core software company that develops the most comprehensiveAI-powered DevSecOps Platform, used by more than 100,000 organizations. Ourmissionis to enable everyone to contribute to and co-create the software that powers our world. When everyone can contribute, consumers become contributors, significantly accelerating the rate of human progress. This mission is integral to our culture, influencing how we hire, build products, and lead our industry. We make this possible at GitLab by running ouroperationson our product and staying aligned with ourvalues. Learn more aboutLife at GitLab.

Thanks to products likeDuo Enterprise, andDuo Workflow, customers get the benefit of AI at every stage of the SDLC. The same principles built into our products are reflected in how our team works: we embrace AI as a core productivity multiplier. All team members are encouraged and expected to incorporate AI into their daily workflows to drive efficiency, innovation, and impact across our global organisation.

An overview of this role:

We are seeking a Staff Security Engineer to join our Security Architecture team with a specialized focus on product security risk and metrics engineering. This position will develop specialized Key Risk Indicators (KRIs), design data collection systems, and create data visualizations that demonstrate our product security posture improvements, measure Product Security teams’ strategic and operational effectiveness, and drive data-informed security decisions. This engineer will also operationalize our Product Security Risk Register and drive cross-functional alignment across Security, Engineering, and Product stakeholders to ensure buy-in and commitment to risk reduction initiatives.

The ideal candidate combines product security expertise, data analysis expertise, and strong stakeholder management skills to build frameworks that enhance visibility, prioritization, and progress tracking of our product security initiatives.

What you'll do:
  • Create and maintain Key Risk Indicators (KRIs) specifically designed to measure, monitor, and communicate product security risk levels
  • Engineer tracking systems and data visualizations that monitor remediation progress and provide visibility into risk reduction initiatives
  • Apply data analysis techniques to identify trends and patterns in product security risk data to inform proactive risk management
  • Design and implement robust metrics collection systems that accurately measure both strategic and operational effectiveness for all Product Security teams
  • Build and maintain the operational systems for the Product Security Risk Register, focusing on efficient workflows and data collection
  • Manage operational cadences including the monthly risk review process and action item tracking workflows
  • Facilitate cross-team collaboration to ensure risk reduction efforts are properly coordinated and tracked
  • Drive cross-functional alignment between Security, Engineering, Product, and other stakeholders to ensure buy-in and commitment to risk reduction initiatives
  • Work alongside the Security Risk Team to ensure product-specific risk tracking aligns with broader operational and enterprise risk management programs while maintaining distinct focus areas
  • Serve as the central coordinator for the Product Security Risk Register operations, related metrics collection, and stakeholder reporting within the Security Architecture team
What you'll bring:
  • 5+ years of experience in product security, DevSecOps, security risk management, data analytics, or related technical roles
  • Demonstrated understanding of secure development practices and product security risks
  • Proven experience developing and implementing security metrics, KRIs, and risk dashboards that drive organizational outcomes
  • Proven ability to translate complex security concepts into actionable data and visualizations
  • Proficiency with data visualization and analysis tools (e.g., Tableau, Power BI, or similar)
  • Proficiency in designing workflows and scalable labeling systems in development ticketing systems like GitLab, Jira, Asana, etc.
  • Strong analytical skills with ability to collect, organize, and derive insights from complex data sets
  • Experience with automation and scripting for data collection and reporting
  • Proven ability to manage cross-functional stakeholders, drive consensus, and navigate competing priorities
  • Excellent written and verbal communication skills with the ability to present complex data in accessible formats
Nice to have qualifications:
  • Experience working directly with product and engineering teams on security initiatives
  • Familiarity with GitLab and its DevSecOps capabilities
  • Prior experience specifically with security risk registers or vulnerability management programs
  • Prior experience with threat modeling, security reviews, or pentesting
  • Security certifications such as CISSP, CISM, CRISC, CRM, etc.
  • Project management certifications like PMP
  • Experience with risk assessment methodologies and frameworks such as NIST RMF, FAIR, ISO 31000, etc.
  • Knowledge of compliance frameworks such as FedRAMP, SOC 2, ISO 27001, PCI-DSS, TISAX, etc.
  • Experience working in a rapidly scaling technology company

Country Hiring Guidelines: GitLab hires new team members in countries around the world. All of our roles are remote, however some roles may carry specific location-based eligibility requirements. Our Talent Acquisition team can help answer any questions about location after starting the recruiting process.

Privacy Policy: Please review our Recruitment Privacy Policy. Your privacy is important to us.

GitLab is proud to be an equal opportunity workplace and is an affirmative action employer. GitLab’s policies and practices relating to recruitment, employment, career development and advancement, promotion, and retirement are based solely on merit, regardless of race, color, religion, ancestry, sex (including pregnancy, lactation, sexual orientation, gender identity, or gender expression), national origin, age, citizenship, marital status, mental or physical disability, genetic information (including family medical history), discharge status from the military, protected veteran status (which includes disabled veterans, recently separated veterans, active duty wartime or campaign badge veterans, and Armed Forces service medal veterans), or any other basis protected by law. GitLab will not tolerate discrimination or harassment based on any of these characteristics. See alsoGitLab’s EEO PolicyandEEO is the Law. If you have a disability or special need that requiresaccommodation, please let us know during therecruiting process.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Staff Product Engineer, Growth (100% remote)

vidIQ

California

Remote

USD 80,000 - 120,000

Yesterday
Be an early applicant

IT Systems Analyst (Remote)

Bright Horizons Children's Centers

Newton

Remote

USD 85,000 - 100,000

Yesterday
Be an early applicant

Lead Security Engineer - Digital Workspace

Enterprise Holdings

St. Louis

Remote

USD 90,000 - 130,000

Yesterday
Be an early applicant

Lead Security Engineer - Digital Workspace

Enterprise Holdings Inc.

Missouri

Remote

USD 80,000 - 120,000

Yesterday
Be an early applicant

Staff Product Security Engineer

DataDirect Networks

Remote

USD 100,000 - 150,000

5 days ago
Be an early applicant

Senior Security Engineer

Nebraska Angels

Fort Wayne

Remote

USD 130,000 - 170,000

7 days ago
Be an early applicant

SW Solutions Architect US Remote

Varian Medical Systems US

Denver

Remote

USD 116,000 - 175,000

Yesterday
Be an early applicant

Sr. Field Marketing Manager, Public Sector

Proofpoint Canada ULC

Pittsburgh

Remote

USD 98,000 - 156,000

2 days ago
Be an early applicant

Security Engineer

Disney Parks and Resorts

Burbank

Remote

USD 99,000 - 154,000

Yesterday
Be an early applicant