A live role

Staff Security Governance Engineer, Policies & Standards

from GitLab · read the original and apply on their site

Remote, United States

Our take: The real work here is owning the full lifecycle of security policy at a global DevSecOps company, turning emerging regulation into clear requirements engineers will follow and using automation to keep governance continuous.

If you love turning dense regulation into policy that engineers will actually follow, this is your room to own the whole lifecycle from draft to retirement. You will work in the open, remote-first and async, using automation and AI to keep governance light instead of a once-a-year scramble. It suits someone who finds quiet satisfaction in getting the details right, influencing across Security, Legal, Product and Engineering without needing a title to do it.

Needs

  • owning policy lifecycle
  • writing clear policy
  • translating regulation
  • automating governance
  • risk-based judgement
  • influencing without authority

Rewards

  • setting the roadmap
  • mentoring the team
  • visible broad-scope impact
  • owning real outcomes

Demands

  • spotting new regulations
  • diplomatic translation
  • coordinating audit evidence
  • deep domain rigour

Grows

  • writing in the open
  • synthesising frameworks
  • designing better process

Values

  • building customer trust
  • working in the open
  • pragmatic risk balance
  • remote-first async

Drains

  • framework mapping upkeep
  • attestation chasing
  • customer questionnaires
  • exception expiry tracking

Would you love this work?

See how what you love doing lines up with this role - it takes about ten minutes to find out.

Find what I'd love to do next