Senior Security Risk Engineer

GitLab
•$139,200 - $189,000•Remote

About The Position

GitLab's Security Risk function is responsible for reducing risk across the security division, including third-party risk management (TPRM), annual security risk assessments, quarterly risk reporting, and remediation of security findings. As a Senior Security Risk Engineer, you will take ownership of risk identification, quantification, and remediation tracking across the business. You will be a driving force behind automating and modernizing how the team performs this work using AI and scripting. Reporting to the Security Risk Manager, you will bring expertise on risk methodology, risk-based thinking, and AI-enablement. In this role, you will partner closely with Security, Legal, IT, Product, and Engineering to translate technical findings and vendor risk into business-relevant risk statements and risk treatments. You will help surface emerging risks and report top risks to leadership.

Requirements

  • 5+ years of experience in security risk management, working with security-centric risk management or compliance frameworks (e.g., NIST RMF, NIST 800-39, ISO 31000).
  • Experience designing and executing qualitative and quantitative risk analyses that translate technical risks into measurable business impact.
  • A track record of driving risk assessments, risk registers, and remediation efforts to closure across IT, Procurement, Internal Audit, Legal, Product, and Engineering, in a heavily regulated or multi-entity environment.
  • Experience interpreting technical control requirements and translating them for both technical and non-technical stakeholders.
  • Demonstrated bias toward automation: you've personally built scripts, workflows, or AI-enabled tooling that reduced manual risk or GRC work, not just evaluated tools conceptually.
  • Comfort operating with ambiguity, managing multiple concurrent assessments, and reprioritizing under tight deadlines.
  • Exceptional written and verbal communication skills with demonstrated ability to translate security risks into business risks.
  • Strong understanding of cloud security, SaaS security models, and DevSecOps practices.

Nice To Haves

  • Familiarity with AI governance frameworks (e.g., ISO 42001, NIST AI RMF) is a plus.
  • Relevant certifications (e.g., CISSP, CISM, CISA, CRISC) are preferred but not required.

Responsibilities

  • Own risk identification, analysis, and prioritization across third-party risk (TPRM), security risk assessments, and security findings, using an established risk framework (e.g., NIST RMF, ISO 31000, or NIST 800-39).
  • Translate technical vulnerabilities, control gaps, and risk findings into clear, quantified risk statements that non-security stakeholders and leadership can act on.
  • Drive remediation of findings and risk exceptions to closure, partnering with Engineering, IT, Product, and Legal, and escalating stalled or high-severity items.
  • Mature and maintain a risk register and quarterly reporting cadence that gives leadership clear visibility into open risk, remediation progress, and trends.
  • Own and mature AI risk management, including AI impact assessments, AI risk assessments, and risk treatments, to support ISO 42001 certification.
  • Design, develop, and implement key risk indicators and supporting metrics for top risks in the risk register.
  • Identify manual, repetitive steps in risk and TPRM workflows and personally build the automation, scripting, or AI-enabled tooling to remove them.
  • Contribute to the roadmap for the risk program, incorporating new frameworks, regulatory changes, and lessons learned from past assessments.
  • Monitor the internal and external risk landscape (new frameworks, threat trends, business changes) to identify and escalate emerging risks before they become findings.

Benefits

  • Flexible Paid Time Off
  • Team Member Resource Groups
  • Equity Compensation & Employee Stock Purchase Plan
  • Growth and Development Fund
  • Parental Leave
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service