Overview
As Senior Manager of the Security Posture Management team, you lead the security of GitLab’s own software factory, guiding governed rollouts of security capabilities across all projects. You set secure defaults, drive proactive software supply chain security, and capture adoption signals to inform Product and Engineering. You collaborate with Compliance to prepare audit-ready evidence and shape the security roadmap. You will grow and coach the team, aligning work with GitLab’s mission to secure software at scale.
Pay / Benefits
- Flexible Paid Time Off
- Team Member Resource Groups
- Equity Compensation & Employee Stock Purchase Plan
- Growth and Development Fund
- Parental Leave
Responsibilities
- Lead governed rollouts of GitLab’s security capabilities across the estate to align with the Project Security Configuration Standard.
- Establish secure defaults and paved paths to accelerate engineering while maintaining security.
- Serve as Customer Zero to identify adoption friction and feed insights to product and engineering roadmap.
- Make software supply chain security a first-class capability, including third-party governance and SBOM requirements.
- Reduce systemic risk across groups, including token governance and lateral movement controls.
- Own the Product Security Risk Register, metrics, and dashboards for a data-driven posture.
- Collaborate with Compliance to generate audit-ready evidence and support maturity assessments.
- Represent security initiatives publicly to strengthen go-to-market narrative and customer trust and lead, coach, and grow the team.
Key requirements
- Experience managing a security or engineering team, including hiring and career development.
- Technical fluency in security posture management, software supply chain security, and secure configuration of a large SaaS estate.
- Track record of driven, governed rollouts of security across an organization you do not own.
- Ability to translate security requirements into actionable controls for engineering teams.
- Experience producing evidence for audits or maturity assessments and partnering with Compliance/GRC.
- Ability to deliver impact under ambiguity and drive iterative, ship-ready wins.
- Strong written communication for an all-remote, async environment.
- leadership and people management
- stakeholder management
- clear written communication
- security posture management
- software supply chain security
- secure configuration of a large SaaS estate
…
