Senior Security Risk Engineer

🔥 34 minutes ago

🌐 United States, Canada – Remote

infoinfo

💵 $139.2k - $189k / year

⏰ Full Time

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

👻 Ghost score 0%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of GitLab

GitLab

1001 - 5000 employees

Founded 2014

💼 Consulting

📣 Marketing

🤖 Artificial Intelligence

💰 Secondary Market on 2020-11

Consulting • Marketing • Artificial Intelligence

GitLab is the most comprehensive AI-powered DevSecOps platform, offering tools for automated software delivery, security, and compliance throughout the software development lifecycle. It provides solutions across areas such as AI-assisted development, continuous integration/continuous deployment (CI/CD), source code management, and vulnerability management. GitLab aims to simplify and accelerate software delivery by uniting development, security, and operations on a unified platform. It is particularly recognized for its AI code assistants and has been named a leader in the Gartner Magic Quadrant™ for DevOps Platforms, making it a preferred choice for many enterprises.

📋 Description

• Own risk identification, analysis, and prioritization across third-party risk, security risk assessments, and security findings using an established risk framework • Translate technical vulnerabilities, control gaps, and risk findings into clear, quantified risk statements for stakeholders and leadership • Drive remediation of findings and risk exceptions to closure with Engineering, IT, Product, and Legal; escalate stalled or high-severity items • Mature and maintain a risk register and quarterly reporting cadence covering open risk, remediation progress, and trends • Own and mature AI risk management, including AI impact assessments, AI risk assessments, and risk treatments supporting ISO 42001 certification • Design, develop, and implement key risk indicators and supporting metrics for top risks • Build automation, scripting, or AI-enabled tooling to eliminate manual risk and TPRM workflow steps • Contribute to the risk program roadmap, incorporating frameworks, regulatory changes, and assessment lessons learned • Monitor internal and external risk landscapes and identify and escalate emerging risks • Partner with Security, Legal, IT, Product, and Engineering to translate technical findings and vendor risk into business-relevant risk statements and treatments • Report top risks to leadership

🎯 Requirements

• 5+ years of experience in security risk management • Experience working with security-centric risk management or compliance frameworks such as NIST RMF, NIST 800-39, or ISO 31000 • Familiarity with AI governance frameworks such as ISO 42001 or NIST AI RMF is a plus • Experience designing and executing qualitative and quantitative risk analyses that translate technical risks into measurable business impact • Track record of driving risk assessments, risk registers, and remediation efforts to closure across IT, Procurement, Internal Audit, Legal, Product, and Engineering in a heavily regulated or multi-entity environment • Experience interpreting technical control requirements and translating them for technical and non-technical stakeholders • Demonstrated experience personally building scripts, workflows, or AI-enabled tooling to reduce manual risk or GRC work • Comfort operating with ambiguity, managing multiple concurrent assessments, and reprioritizing under tight deadlines • Exceptional written and verbal communication skills with demonstrated ability to translate security risks into business risks • Strong understanding of cloud security, SaaS security models, and DevSecOps practices • Relevant certifications such as CISSP, CISM, CISA, or CRISC are preferred but not required

🏖️ Benefits

• Benefits to support your health, finances, and well-being • Flexible Paid Time Off • Team Member Resource Groups • Equity Compensation & Employee Stock Purchase Plan • Growth and Development Fund • Parental Leave

Apply Now

Similar Jobs

🔥 1 hour ago

Sage Bionetworks

51 - 200

🏥 Healthcare

💼 Consulting

📦 Logistics

Associate Director leading cybersecurity and IT operations for Sage Bionetworks’ nonprofit biomedical research and open-science platforms. Strengthening controls, incident response, infrastructure, and employee technology.

🔥 1 hour ago

TEECOM

51 - 200

💼 Consulting

🏥 Healthcare

🏗️ Construction

Security systems designer developing physical security solutions for complex facilities at TEECOM, a global consulting firm. Producing construction documents and coordinating integrated security systems across US, UK, and India teams.

🔥 2 hours ago

BizFirst LLC

11 - 50

💼 Consulting

📦 Logistics

📣 Marketing

Senior Cloud Security Engineer securing CBP AWS environments and delivery pipelines. Supporting federal cloud modernization, zero trust architecture, vulnerability management, and ATO compliance.

🔥 2 hours ago

Valiant Solutions

201 - 500

💼 Consulting

🎖️ Defense

🔒 Cybersecurity

Senior Enterprise Security Architect designing Azure, cloud, and on-premise security architectures for federal agencies. Leading Zero Trust, NIST compliance, risk analysis, and enterprise security guidance.

🔥 4 hours ago

NVIDIA

10,000+ employees

🏥 Healthcare

🏭 Manufacturing

🤖 Artificial Intelligence

Security Engineer securing NVIDIA GPU kernel and firmware components. Leading vulnerability triage, security pipelines, product hardening, and advanced analysis for AI and accelerated computing.