A live role
Staff Security Governance Engineer, Policies & Standards
from GitLab · read the original and apply on their site
Remote, United States
Our take: The real work here is owning the full lifecycle of security policy at a global DevSecOps company, turning emerging regulation into clear requirements engineers will follow and using automation to keep governance continuous.
If you love turning dense regulation into policy that engineers will actually follow, this is your room to own the whole lifecycle from draft to retirement. You will work in the open, remote-first and async, using automation and AI to keep governance light instead of a once-a-year scramble. It suits someone who finds quiet satisfaction in getting the details right, influencing across Security, Legal, Product and Engineering without needing a title to do it.
Needs
- owning policy lifecycle
- writing clear policy
- translating regulation
- automating governance
- risk-based judgement
- influencing without authority
Rewards
- setting the roadmap
- mentoring the team
- visible broad-scope impact
- owning real outcomes
Demands
- spotting new regulations
- diplomatic translation
- coordinating audit evidence
- deep domain rigour
Grows
- writing in the open
- synthesising frameworks
- designing better process
Values
- building customer trust
- working in the open
- pragmatic risk balance
- remote-first async
Drains
- framework mapping upkeep
- attestation chasing
- customer questionnaires
- exception expiry tracking
Would you love this work?
See how what you love doing lines up with this role - it takes about ten minutes to find out.
Find what I'd love to do next