Skip to content

Staff Security Engineer, IAM (USA)

GitLab

USremote country$168k-$238k/yrPosted May 28, 2026

At a glance

Highlights

  • Remote (U.S. only)
  • $168k‑$238k base salary
  • AI governance focus
  • Large‑scale identity platform

Heads up

  • U.S. citizenship required

Why this role might suit you

The role offers a senior technical leader position shaping enterprise identity and AI security at a fast‑growing, globally recognized platform, with a competitive U.S. salary range and the chance to influence cross‑functional initiatives.

Skills

oktaterraformpythontinesokta-workflowsscimssofedrampsoc2soxconditional-accessdevice-trustrisk-based-authenticationbehavioral-analyticsanthropic-claudeopenai-chatgptgoogle-geminitoken-securityoasisastrixlumosconductorone

About the role

GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50 million registered users and more than 50% of the Fortune 100 trust GitLab to ship better, more secure software faster.

The same principles built into our products are reflected in how our team works: we embrace AI as a core productivity multiplier, with all team members expected to incorporate AI into their daily workflows to drive efficiency, innovation, and impact. GitLab is where careers accelerate, innovation flourishes, and every voice is valued. Our high-performance culture is driven by our values and continuous knowledge exchange, enabling our team members to reach their full potential while collaborating with industry leaders to solve complex problems. Co-create the future with us as we build technology that transforms how the world develops software.

Fortune 500® is a registered trademark of Fortune Media IP Limited, used under license. Claim based on GitLab data. Fortune 100 refers to the top 20% ranked companies in the 2025 Fortune 500 list, published in June 2025. Fortune and Fortune Media IP Limited are not affiliated with, and do not endorse products or services of GitLab.

An overview of this role

The Corporate Security Identity Team is on a mission to transform how our workforce ecosystem securely accesses the tools they need to do their best work, advancing from foundational controls to sophisticated, automated governance across our identity platforms and our emerging AI tooling.

As a Staff Security Engineer, you'll be a senior technical leader and strategic anchor on the team. You're passionate about designing elegant solutions to complex identity challenges, whether that's architecting enterprise-scale conditional access policies, codifying our identity platforms in Terraform, or building governance frameworks for AI agents and non-human identities. You'll be responsible for critical systems, write technical proposals that influence our roadmap, raise the bar through design and code review, and lead cross-functional initiatives that span Security, IT, Engineering, Compliance and People teams.

This isn't about maintaining the status quo- it's about architecting the future of identity security for a rapidly scaling company operating in regulated environments. *Because this role may need to support our FedRamp tech stack, hiring may be restricted to US citizens physically located in the US.

What you’ll do

Design comprehensive identity and AI access solutions that scale with our business growth, from AI agent governance frameworks to privileged access workflows that eliminate standing access through just-in-time provisioning

Lead identity and access engineering for our enterprise AI platforms including administration, SSO and SCIM integration, audit logging, data controls, and policy enforcement for Claude (web, Claude Code, Cowork) and adjacent tools

Codify our identity platforms in Terraform, leading the migration of Okta, Lumos, and our NHI platform from click-ops to peer-reviewed infrastructure-as-code, with a focus on global critical policies

Refactor our authentication framework to implement advanced conditional access controls such as device trust, location-based policies, risk-based step-up authentication, and behavioral analytics across our entire SaaS ecosystem

Pioneer non-human identity governance by designing monitoring and management solutions for service accounts, API keys, certificates, AI agents, and MCP integrations, and leading deployment, integration, and operationalization of our NHI platform across the SaaS estate

Drive cross-functional initiatives with Security, IT, Engineering, Enterprise AI, and the Office of the CIO to extract requirements from ambiguous business needs and translate them into actionable technical specifications

Mentor senior and intermediate engineers on technical implementation and strategic thinking, helping them develop expertise in modern identity and AI security practices

What you’ll bring

8+ years of IAM experience designing and implementing enterprise-scale solutions, with demonstrated time at a Staff or senior IC level

Expert-level Okta expertise including Identity Engine, advanced authentication policies, lifecycle workflows, and API automation

Strong infrastructure-as-code practice with Terraform, including provider experience for SaaS identity platforms and a track record of migrating click-ops to code

Hands-on experience administering or governing enterprise AI platforms (Anthropic Claude preferred; OpenAI ChatGPT Enterprise, Google Gemini Enterprise, or similar acceptable), and awareness of AI-specific risks including prompt injection, MCP attack surface, agent identity, and data leakage

Strong automation experience using Python and iPaaS tools (Tines, Okta Workflows)

Experience with IGA platforms like Lumos, ConductorOne, or similar

Working knowledge of non-human identity tooling (Token Security, Oasis, Astrix, or similar), or equivalent experience governing service accounts, OAuth grants, and workload identities

Experience in regulated environments with knowledge of compliance frameworks (FedRAMP, SOC2, SOX), including change management, evidence collection, and audit support

Collaborative mindset and strategic communication skills for writing technical proposals, leading cross-functional initiatives, and mentoring teammates

Nice to have Qualifications: Passion for emerging identity challenges including AI agent governance, non-human identity management, zero-trust architecture, and behavioral analytics; Active user of Claude Code, Cursor, or similar agentic development tools, with intuition for how engineers integrate them into daily workflows

Due to government requirements, you must be a United States Citizen (defined as any individual who is a citizen of the United States by law, birth, or naturalization) to fill this position.

The base salary range for this role’s listed level is currently for residents of the United States only. This range is intended to reflect the role's base salary rate in locations throughout the US. Grade level and salary ranges are determined through interviews and a review of education, experience, knowledge, skills, abilities of the applicant, equity with other team members, alignment with market data, and geographic location. The base salary range does not include any bonuses, equity, or benefits. information on our benefits and equity. Sales roles are also eligible for incentive pay targeted at up to 100% of the offered base salary.

United States Salary Range

$168,000—$238,000 USD

How GitLab Supports Full-Time Employees

Benefits to support your health, finances, and well-being

Flexible Paid Time Off

Team Member Resource Groups

Equity Compensation & Employee Stock Purchase Plan

Growth and Development Fund

Parental Leave

Please note that we welcome interest from candidates with varying levels of experience; many successful candidates do not meet every single requirement. Additionally, studies have shown that people from underrepresented groups are less likely to apply to a job unless they meet every single qualification. If you're excited about this role, please apply and allow our recruiters to assess your application.

Country Hiring Guidelines: GitLab hires new team members in countries around the world. All of our roles are remote, however some roles may carry specific location-based eligibility requirements. Our Talent Acquisition team can help answer any questions about location after starting the recruiting process.

Compensation

This Security Engineer role pays $168k-$238k/yr. Within typical range for security engineer roles in United States.

Questions about this role

  • How do I apply to this Staff Security Engineer, IAM (USA) role at GitLab?

    Click "Apply with AI Applyd" above. We auto-fill the application from your resume and answer screening questions in seconds. No copy and paste, no juggling tabs.

  • What's the typical salary for Security Engineer in United States?

    Compensation for Security Engineer roles in United States varies widely by seniority, employer size, and remote vs onsite arrangement. Check the salary range on this listing when published, or browse our Security Engineer hub for United States medians across recent openings.

  • How fast does AI Applyd auto-apply?

    Most applications complete in under 90 seconds. You can track the status in your dashboard and watch the screenshot proof land the moment the application submits.

  • What ATS does GitLab use?

    AI Applyd supports Greenhouse, Lever, Ashby, Workday, iCIMS, SmartRecruiters, LinkedIn Easy Apply, and most other ATS platforms. If we can submit through the platform, we do.

Want AI Applyd to auto-apply to roles like this?

We tailor your resume per posting, fill the forms, and track replies for you.