gitlab logo

Senior Security Risk Engineer

gitlab • Remote, Canada; Remote, United States


No Relocation

Posted: September 29, 2026

Job Description

An overview of this role

GitLab's Security Risk function is responsible for reducing risk across the security division: third-party risk (TPRM), annual security risk assessments, quarterly risk reporting, and remediation of security findings. As a Senior Security Risk Engineer, you'll take ownership of risk identification, quantification, and remediation tracking across the business, and you'll be a driving force behind automating and modernizing how the team does this work using AI and scripting. Reporting to the Security Risk Manager, you will bring expertise on risk methodology, risk-based thinking, and AI-enablement. 

In this role, you'll partner closely with Security, Legal, IT, Product, and Engineering to translate technical findings and vendor risk into business-relevant risk statements and risk treatments. You’ll help surface emerging risks, and report top risks to leadership. 

Some examples of our projects:

  • Building and maintaining a risk register that translates technical vulnerabilities, control gaps, and third-party risk findings into quantified, business-relevant risk statements.
  • Driving cross-functional remediation of security findings and risk issues to closure, tracked against SLAs.
  • Driving automation and AI-enabled improvements for risk and GRC workflows so the team can spend less time on manual work and more time on high-value risk analysis and program maturity.

What you'll do

  • Own risk identification, analysis, and prioritization across third-party risk (TPRM), security risk assessments, and security findings, using an established risk framework (e.g., NIST RMF, ISO 31000, or NIST 800-39). 
  • Translate technical vulnerabilities, control gaps, and risk findings into clear, quantified risk statements that non-security stakeholders and leadership can act on. 
  • Drive remediation of findings and risk exceptions to closure, partnering with Engineering, IT, Product, and Legal, and escalating stalled or high-severity items. 
  • Mature and maintain a risk register and quarterly reporting cadence that gives leadership clear visibility into open risk, remediation progress, and trends.
  • Own and mature AI risk management, including AI impact assessments, AI risk assessments, and risk treatments, to support ISO 42001 certification.
  • Design, develop, and implement key risk indicators and supporting metrics for top risks in the risk register.
  • Identify manual, repetitive steps in risk and TPRM workflows and personally build the automation, scripting, or AI-enabled tooling to remove them. 
  • Contribute to the roadmap for the risk program, incorporating new frameworks, regulatory changes, and lessons learned from past assessments.
  • Monitor the internal and external risk landscape (new frameworks, threat trends, business changes) to identify and escalate emerging risks before they become findings.

What you'll bring

  • 5+ years of experience in security risk management, working with security-centric risk management or compliance frameworks (e.g., NIST RMF, NIST 800-39, ISO 31000). Familiarity with AI governance frameworks (e.g., ISO 42001, NIST AI RMF) is a plus.
  • Experience designing and executing qualitative and quantitative risk analyses that translate technical risks into measurable business impact. 
  • A track record of driving risk assessments, risk registers, and remediation efforts to closure across IT, Procurement, Internal Audit, Legal, Product, and Engineering, in a heavily regulated or multi-entity environment.
  • Experience interpreting technical control requirements and translating them for both technical and non-technical stakeholders.
  • Demonstrated bias toward automation: you've personally built scripts, workflows, or AI-enabled tooling that reduced manual risk or GRC work, not just evaluated tools conceptually. 
  • Comfort operating with ambiguity, managing multiple concurrent assessments, and reprioritizing under tight deadlines. 
  • Exceptional written and verbal communication skills with demonstrated ability to translate security risks into business risks.
  • Strong understanding of cloud security, SaaS security models, and DevSecOps practices.
  • Relevant certifications (e.g., CISSP, CISM, CISA, CRISC) are preferred but not required. 

About the team

The Security Assurance organization helps GitLab build and maintain trust by strengthening how we approach security, compliance, and risk across the company. The Security Risk team sits within that group and owns third-party risk (TPRM), security risk assessments, and remediation of security findings. The Security Risk Team performs thorough, collaborative, and efficient risk assessments as well as drive risk reduction so that GitLab can achieve its goals while maintaining a high level of security. Security Risk counterparts are Security Compliance, Security Governance and Security Enablement functions.