Search Remote Jobs

Senior Security Assurance Engineer

🔥 18 hours ago

🇺🇸 United States – Remote

💵 $139.2k - $196k / year

⏰ Full Time

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

👻 Ghost score 0%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of GitLab

GitLab

1001 - 5000 employees

Founded 2014

💼 Consulting

📣 Marketing

🤖 Artificial Intelligence

💰 Secondary Market on 2020-11

Consulting • Marketing • Artificial Intelligence

GitLab is the most comprehensive AI-powered DevSecOps platform, offering tools for automated software delivery, security, and compliance throughout the software development lifecycle. It provides solutions across areas such as AI-assisted development, continuous integration/continuous deployment (CI/CD), source code management, and vulnerability management. GitLab aims to simplify and accelerate software delivery by uniting development, security, and operations on a unified platform. It is particularly recognized for its AI code assistants and has been named a leader in the Gartner Magic Quadrant™ for DevOps Platforms, making it a preferred choice for many enterprises.

📋 Description

• Design, document, maintain, and test IT General Controls and security controls across the in-scope estate • Map shared controls and test them against SOX, SOC 2, ISO 27001, ISO 42001, NIST CSF, PCI-DSS, privacy regulations, and customer contractual commitments • Serve as compliance point of contact and liaison for IT, Corporate Security, Engineering, and Finance teams • Set standards and control expectations for governed AI use across corporate and business systems • Partner with Security Governance on corporate security policies, standards, procedures, reviews, attestations, and Acceptable Use Policy adherence • Run recurring compliance monitoring for access reviews, privileged access, segregation of duties, change management, and configuration baselines • Assess system implementations, migrations, and significant changes for control readiness before go-live • Manage SOX ITGC testing and certification requests from internal and external auditors • Direct and automate evidence collection for external audits • Identify, track, and lead remediation of control deficiencies and risks • Recommend improvements to compliance processes, metrics, and reporting

🎯 Requirements

• 5+ years in IT compliance, security compliance, IT audit, information security, or information technology • BA/BS in a business or technology field or equivalent experience • Experience testing controls and documenting tests against COSO, COBIT, NIST CSF, ISO 27001, SOC 2, and SOX ITGC • Experience working directly with internal or external auditors • Experience assessing controls in SaaS and cloud-native application stacks • Working knowledge of identity and access management, including SSO, SCIM, RBAC, privileged access, and joiner/mover/leaver processes • Familiarity with AI governance concepts and control questions involving AI tools, agents, and integrations • Experience contributing to security policies and standards and supporting policy adherence or attestation processes • Ability to reason about data flows between product usage, billing, subscription, and financial reporting systems • Exceptional written and verbal communication • Ability to use GitLab, or willingness to learn • Big 4 or external audit experience is a plus • Relevant certifications such as CISA, CISSP, CRISC, or CISM are nice to haves • Experience with usage-based or consumption billing platforms, subscription management systems, or in-house metering and entitlement services is a nice to have • Experience with compliance automation and continuous control monitoring, or setting standards for AI use in an enterprise environment, is a nice to have • Prior experience in a Security Assurance or GRC function supporting both corporate IT and product engineering is a nice to have

🏖️ Benefits

• Benefits to support your health, finances, and well-being • Flexible Paid Time Off • Team Member Resource Groups • Equity Compensation & Employee Stock Purchase Plan • Growth and Development Fund • Parental Leave

Apply Now

Similar Jobs

🔥 19 hours ago

Oxfam America

201 - 500

🤲 Charity

🤝 Non-profit

🌍 Social Impact

Cybersecurity and Infrastructure Manager securing Oxfam’s technology systems. Leading infrastructure, incident response, helpdesk, and IT asset operations for a global anti-poverty organization.

🔥 20 hours ago

ComPsych

1001 - 5000

🏥 Healthcare

💼 Consulting

📦 Logistics

Senior Cloud Security Engineer securing ComPsych’s mental health and absence-management platforms across cloud, applications, data, and AI. Building automated controls, detection, response, and privacy protections.

🔥 20 hours ago

BNSF Railway

10,000+ employees

🚗 Transport

📦 Logistics

Cybersecurity Engineer securing BNSF’s freight rail infrastructure, applications, and digital assets. Building controls, automation, incident response, and compliance capabilities.

🔥 20 hours ago

OpenText

10,000+ employees

🏢 Enterprise

☁️ SaaS

🤝 B2B

Partner Account Manager driving cybersecurity channel revenue for OpenText, Carbonite, Webroot and Zix. Growing VAR, service provider, and strategic partner relationships across an assigned U.S. territory.

🔥 20 hours ago

EverCommerce

1001 - 5000

☁️ SaaS

🤝 B2B

📣 Marketing

Security Engineer strengthening EverCommerce’s SaaS security architecture, cloud controls, and compliance framework. Designing secure systems and guiding integrations across distributed service-commerce teams.