GitLab

Staff Security Engineer, IAM

GitLab · Remote, Canada; Remote, United States

Posted 16 days ago

or apply directly on GitLab's site. We never take the application ourselves.

Is this posting real?

This role has been open
16 days
GitLab's roles stay open a median of 41 days
Reposted
No
Salary listed
No
0% of GitLab's roles list one
Ghost-job risk at GitLab
low
0 stale, 9 reposted of 238 open
Hiring momentum
338 roles opened in the last 90 days
↑ up vs. the prior 90 days
Last confirmed on the employer's board
2026-09-17

Measured from postings appearing on and disappearing from GitLab's own greenhouse board since 2026-08-03. Full hiring picture for GitLab.

About this role

As a Staff Security Engineer focused on Identity and Access Management (IAM) at GitLab, you will lead the design and implementation of advanced identity solutions, including governance frameworks for AI agents and automated access controls. Your role involves migrating existing automation to engineered services, codifying identity platforms, and collaborating across teams to enhance security practices. You will also mentor other engineers and drive cross-functional initiatives to address complex identity challenges.

Our read on this posting3.4out of 5
benefits
3/5
freshness
4/5
career value
5/5
role clarity
5/5
pay transparency
0/5

Scored from the posting itself — how clearly the role is described, how much it says about pay and benefits, and how recently it was listed. Not a judgement of GitLab as an employer.

What you need

  • Extensive IAM experience designing and implementing enterprise-scale solutions, with demonstrated time at a Staff or senior IC level
  • Expert-level Okta expertise including Identity Engine, advanced authentication policies, lifecycle workflows, and API automation
  • Strong infrastructure-as-code practice with Terraform/OpenTofu/Pulumi, including provider experience for SaaS identity platforms and a track record of migrating click-ops to code
  • Proficiency writing and shipping Python as a software engineer designed as modular, tested, code-reviewed, deployed as services (GCP Cloud Run or equivalent serverless runtime) and instrumented for failure
  • Cloud identity depth in GCP and/or AWS, including resource hierarchy and organization design, IAM policy models, workload identity federation, and preventive controls such as org policies, SCPs, and permission boundaries
  • Hands-on experience administering or governing enterprise AI platforms (Anthropic Claude preferred; OpenAI ChatGPT Enterprise, Google Gemini Enterprise, or similar acceptable), and awareness of AI-specific risks including prompt injection, MCP attack surface, agent identity, and data leakage

Nice to have

  • Passion for emerging identity challenges including AI agent governance, non-human identity management, zero-trust architecture, and behavioral analytics
  • Experience carrying a cloud org restructuring through to completion, including the migration and stakeholder work, not just the target-state design

What you get

  • Flexible Paid Time Off
  • Team Member Resource Groups
  • Equity Compensation & Employee Stock Purchase Plan
  • Growth and Development Fund
  • Parental Leave

Worth weighing

  • No specific salary listed for Canada; US salary range provided is $168,000 — $238,000 USD
  • Role involves significant migration and engineering work, moving away from low-code solutions
  • Focus on mentoring and cross-functional collaboration may require strong interpersonal skills

Summarised from GitLab's posting. Read the full original.

Listed by GitLab on their greenhouse job board, last confirmed open on 2026-09-17. PitchMeAI is not the employer.

More roles at GitLab

All 238 open roles at GitLab

Apply to a Staff Security Engineer, IAM position at GitLab - Jobs near me at Remote, Canada; Remote, United States