Staff Infrastructure Security Engineer
Job description
About the role
This position focuses on ensuring the security and resilience of GitLab's public cloud infrastructure. You will guide the technical direction for infrastructure security, impacting both SaaS offerings like GitLab Dedicated and Cells, as well as self-managed products. Your work will involve hands-on implementation and influencing engineering teams to build secure platforms for global software development. You will establish architectural blueprints, sample implementations, and core security automation to guide infrastructure security practices. You will lead infrastructure security projects from initial concept to completion, breaking down complex, multi-quarter efforts into manageable tasks with clear success metrics. You will perform and guide in-depth security assessments and threat modeling for intricate infrastructure elements, identifying widespread risks and overseeing their resolution. You will define the team's strategy for using AI in security engineering, pinpointing areas where it can significantly enhance efficiency and creating adoption patterns. You will act as a primary technical authority on infrastructure security for stakeholders, translating technical trade-offs into actionable decisions for engineering teams and leadership.
Key facts
What you'll do
- Establish architectural blueprints, sample implementations, and core security automation to guide infrastructure security practices.
- Lead infrastructure security projects from initial concept to completion, breaking down complex, multi-quarter efforts into manageable tasks with clear success metrics.
- Perform and guide in-depth security assessments and threat modeling for intricate infrastructure elements, identifying widespread risks and overseeing their resolution.
- Define the team's strategy for using AI in security engineering, pinpointing areas where it can significantly enhance efficiency and creating adoption patterns.
- Act as a primary technical authority on infrastructure security for stakeholders, translating technical trade-offs into actionable decisions for engineering teams and leadership.
- Contribute to technical planning, setting priorities, and developing roadmaps that align technical work with business goals.
- Mentor and develop fellow engineers, elevating technical standards and promoting collaborative, inclusive work environments.
- Secure GitLab's infrastructure by utilizing our own product, a practice known as "dogfooding."
- Drive the design and implementation of security controls for cloud native platforms, ensuring they are scalable, observable, and resilient by default.
- Partner with product and platform teams to embed security into the entire lifecycle of infrastructure changes, from design through deployment and operations.
- Analyze complex security incidents, determine root causes, and translate findings into preventative controls and process improvements.
- Champion secure coding practices and infrastructure hardening standards across engineering organizations through training and hands-on support.
- Evaluate emerging security technologies and open source tools, conducting PoCs to determine their viability for large scale adoption.
- Collaborate with global teams to ensure security solutions are practical, efficient, and aligned with diverse operational requirements.
Requirements
- Deep understanding of cloud infrastructure security (AWS, GCP, Azure), Kubernetes, and related infrastructure and data security principles.
- Proficiency in multiple programming languages such as Go, Python, and Ruby, with a history of developing production-ready security tools.
- Extensive experience with securing Infrastructure-as-Code (Terraform, Ansible, CloudFormation), policy-as-code, and automated compliance processes.
- Practical experience applying AI to security workflows, with a clear perspective on its value.
- Proven ability to lead technical initiatives involving multiple teams, starting from vague problems and achieving measurable results, while setting technical standards that other teams adopt.
- Strong communication skills, both written and verbal, with the ability to explain security considerations to both technical and non-technical audiences, including senior management.
- Familiarity with security certifications, frameworks, and standards like FedRAMP, ISO 27001, SOC 2, and PCI-DSS.
- Alignment with GitLab's company values.
Nice to have
- Experience with security certifications, frameworks, and standards (FedRAMP, ISO 27001, SOC 2, PCI-DSS).
Practical notes
GitLab hires globally and offers remote positions. Specific location-based eligibility may apply to certain roles. Benefits include support for health, finances, and well-being, flexible paid time off, parental leave, equity compensation, and a growth and development fund. GitLab is an equal opportunity employer committed to diversity and inclusion. Accommodations for disabilities or special needs can be requested during the recruiting process.