Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Staff Security Engineer, IAM

$168k - $238k
Full-time

GitLab

GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50 million registered users and more than 50% of the Fortune 100* trust GitLab to ship better, more secure software faster.

The same principles built into our products are reflected in how our team works: we embrace AI as a core productivity multiplier, with all team members expected to incorporate AI into their daily workflows to drive efficiency, innovation, and impact. GitLab is where careers accelerate, innovation flourishes, and every voice is valued. Our high-performance culture is driven by our values and continuous knowledge exchange, enabling our team members to reach their full potential while collaborating with industry leaders to solve complex problems. Co-create the future with us as we build technology that transforms how the world develops software.

* Fortune 500® is a registered trademark of Fortune Media IP Limited, used under license. Claim based on GitLab data. Fortune 100 refers to the top 20% ranked companies in the 2025 Fortune 500 list, published in June 2025. Fortune and Fortune Media IP Limited are not affiliated with, and do not endorse products or services of GitLab.

An overview of this role

The Corporate Security Identity Team is on a mission to transform how our workforce ecosystem securely accesses the tools they need to do their best work, advancing from foundational controls to sophisticated, automated governance across our identity platforms and our emerging AI tooling.

As a Staff Security Engineer, you'll be a senior technical leader and strategic anchor on the team. You're passionate about designing elegant solutions to complex identity challenges, whether that's architecting enterprise-scale conditional access policies, codifying our configuration of our identity platforms, or building governance frameworks for AI agents and non-human identities. You'll be responsible for critical systems, write technical proposals that influence our roadmap, raise the bar through design and code review, and lead cross-functional initiatives that span Security, IT, Engineering, Compliance and People teams.

We're deliberately moving off click-ops and low-code platforms. Configuration is becoming peer-reviewed code; automation is becoming tested code running on GCP Cloud Run. Join us to lean in!

What you’ll do

  • Design comprehensive identity and AI access solutions that scale with our business growth, from AI agent governance frameworks to privileged access workflows that eliminate standing access through just-in-time provisioning
  • Replace low-code automation with engineered services, migrating our existingiPaaS automation to Python services on GCP Cloud Run with source control, tests, CI and observability
  • Codify our identity platforms in Terraform/OpenTofu/Pulumi , leading the migration of Okta, Lumos, and our NHI platform from click-ops to peer-reviewed infrastructure-as-code, with a focus on global critical policies
  • Help re-architect identity and access across our GCP and AWS organizations, partnering on resource hierarchy design, secure-by-default guardrails (org policies, SCPs, permission boundaries), workload identity federation, and a credible path to least privilege for both human and workload access
  • Lead identity and access engineering for our enterprise AI platforms including administration, SSO and SCIM integration, audit logging, data controls, and policy enforcement for Claude (web, Claude Code, Cowork) and adjacent tools
  • Pioneer non-human identity governance by designing monitoring and management solutions for service accounts, API keys, certificates, AI agents, and MCP integrations, and leading deployment, integration, and operationalization of our NHI platform across the SaaS estate
  • Drive cross-functional initiatives with Security, IT, Engineering, Enterprise AI, and the Office of the CIO to extract requirements from ambiguous business needs and translate them into actionable technical specifications
  • Mentor senior and intermediate engineers on technical implementation and strategic thinking, helping them develop expertise in modern identity and AI security practices

What you’ll bring

  • Extensive IAM experience designing and implementing enterprise-scale solutions, with demonstrated time at a Staff or senior IC level
  • Expert-level Okta expertise including Identity Engine, advanced authentication policies, lifecycle workflows, and API automation
  • Strong infrastructure-as-code practice with Terraform/OpenTofu/Pulumi , including provider experience for SaaS identity platforms and a track record of migrating click-ops to code
  • Proficiency writing and shipping Python as a software engineer designed asmodular, tested, code-reviewed, deployed as services (GCP Cloud Run or equivalent serverless runtime) and instrumented for failure
  • Cloud identity depth in GCP and/or AWS , including resource hierarchy and organization design, IAM policy models, workload identity federation, and preventive controls such as org policies, SCPs, and permission boundaries
  • Hands-on experience administering or governing enterprise AI platforms (Anthropic Claude preferred; OpenAI ChatGPT Enterprise, Google Gemini Enterprise, or similar acceptable), and awareness of AI-specific risks including prompt injection, MCP attack surface, agent identity, and data leakage
  • A working practice of building with AI tooling you use agentic tools (Claude Code, Cursor, or similar) in your daily engineering work, iterate on your own workflows as capabilities shift, and can bring the rest of the team along. The tooling landscape changes monthly and identity is at the center of it; we want someone whose instincts stay current because they're a practitioner
  • Experience with IGA platforms like Lumos, ConductorOne, or similar, with a preference for managing them declaratively
  • Experience in regulated environments with knowledge of compliance frameworks (FedRAMP, SOC2, SOX), including change management, evidence collection, and audit support

Nice to have Qualifications:

  • Passion for emerging identity challenges including AI agent governance, non-human identity management, zero-trust architecture, and behavioral analytics
  • Experience carrying a cloud org restructuring through to completion , including the migration and stakeholder work, not just the target-state design

The base salary range for this role’s listed level is currently for residents of the United States only. This range is intended to reflect the role's base salary rate in locations throughout the US. Grade level and salary ranges are determined through interviews and a review of education, experience, knowledge, skills, abilities of the applicant, equity with other team members, alignment with market data, and geographic location. The base salary range does not include any bonuses, equity, or benefits. See more information on our benefits and equity. Sales roles are also eligible for incentive pay targeted at up to 100% of the offered base salary.

United States Salary Range

$168,000—$238,000 USD

How GitLab Supports Full-Time Employees

  • Benefits to support your health, finances, and well-being
  • Flexible Paid Time Off
  • Team Member Resource Groups
  • Equity Compensation & Employee Stock Purchase Plan
  • Growth and Development Fund
  • Parental Leave

Please note that we welcome interest from candidates with varying levels of experience; many successful candidates do not meet every single requirement. Additionally, studies have shown that people from underrepresented groups are less likely to apply to a job unless they meet every single qualification. If you're excited about this role, please apply and allow our recruiters to assess your application.

Country Hiring Guidelines: GitLab hires new team members in countries around the world. All of our roles are remote, however some roles may carry specific location-based eligibility requirements. Our Talent Acquisition team can help answer any questions about location after starting the recruiting process.

Privacy Policy: Please review our Recruitment Privacy Policy. Your privacy is important to us.

GitLab is proud to be an equal opportunity workplace and is an affirmative action employer. GitLab’s policies and practices relating to recruitment, employment, career development and advancement, promotion, and retirement are based solely on merit, regardless of race, color, religion, ancestry, sex (including pregnancy, lactation, sexual orientation, gender identity, or gender expression), national origin, age, citizenship, marital status, mental or physical disability, genetic information (including family medical history), discharge status from the military, protected veteran status (which includes disabled veterans, recently separated veterans, active duty wartime or campaign badge veterans, and Armed Forces service medal veterans), or any other basis protected by law. GitLab will not tolerate discrimination or harassment based on any of these characteristics. See also GitLab’s EEO Policy and EEO is the Law. If you have a disability or special need that requires accommodation, please let us know during the recruiting process.

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Staff Security Engineer, IAM in Remote vacancy
  • Austin, TXTechnology - Security /RemoteThe Staff Security Engineer will be responsible for designing, implementing, and maintaining security identity services...  ...environmentsDomain Specific Minimum RequirementsCloud IAM Architecture: Deep knowledge of cloud security... 
    Suggested
    Temporary work
    Remote work
    Flexible hours

    Aledade

    Austin, TX
    5 days ago
  • $165k - $200k

     ...out of bed every morning. Greenlight is looking for a Staff Offensive Security Engineer for our Security team. This individual will be...  ...Deep understanding of AWS security architecture, including IAM bypass techniques, container escapes (Kubernetes), and serverless... 
    Suggested
    Full time
    Work at office
    Local area
    Remote work
    Work from home
    Flexible hours
    Day shift

    Greenlight Financial Technology

    Remote
    1 day ago
  • $156k - $255k

     ...Team LinkedIn’s Information Security organization protects our...  ...early, and partnering across engineering to reduce risk at scale. The...  ...precision. About the role As a Staff Security Engineer on the...  ...with IR/Threat Intel/Cloud/IAM to turn hypotheses and TTPs... 
    Suggested
    Full time
    For contractors
    Work experience placement
    Work at office
    Remote work
    Work from home
    Flexible hours

    LinkedIn

    Mountain View, CA
    4 days ago
  • $130k - $195k

     ...Posting Type Remote Job Overview The Senior IAM Engineer is a technically authoritative leader who sets the direction for the enterprise...  ...) identity domains. Partnering with the Manager of Enterprise Security and leading cross-functional teams, the role reduces... 
    Suggested
    Full time
    Remote work
    Flexible hours

    Relativity

    Nebraska
    1 day ago
  • $104k - $156k

     ...Posting Type Remote Job Overview The Advanced IAM Engineer is a technically deep, hands-on practitioner who forms the operational...  ...) identity domains. Partnering with the Manager of Enterprise Security and cross-functional teams, the role reduces Relativity's identity... 
    Suggested
    Full time
    Remote work

    Relativity

    Kansas
    1 day ago
  •  ...Staff Security Engineer Assured is on a mission to modernize insurance. Claims processing (i.e. should we pay this claim?), while often overlooked...  ...cloud-native infrastructure, especially AWS, including IAM, networking, and containerized workloads. Experience building... 
    Temporary work
    Remote work
    Work from home
    Home office

    ASSURED

    United States
    2 days ago
  • $170k - $205k

     ...Staff Security Engineer Snyk is the leader in secure AI software development, helping millions of developers develop fast and stay secure as...  ...and reporting posture as a trend over time. Leading cloud IAM and least privilege. Designing and enforcing permission models... 
    Work at office
    Remote work
    Work from home
    Flexible hours

    Venturefizz Product Management Community

    United States
    5 days ago
  • $193.8k - $285k

     ...three-sided marketplace of consumers, merchants, and Dashers. Security Engineering is paramount to the success of our business, and DoorDash...  ...Our Proactive Security Engineering team is looking for a Staff Security Engineer, Proactive Security to execute on AI Security... 
    Hourly pay
    Full time
    Work experience placement
    Work at office
    Local area
    Remote work
    Flexible hours

    DoorDash USA

    Remote
    1 day ago
  •  ...Staff Security Engineer We are seeking a Staff Security Engineer who operates at the nexus of high-level strategy and multi-tenant operational...  ...AWS/Azure security; Zero Trust Architecture (ZTA); Advanced IAM/Entra ID. SecOps & Intelligence - Advanced SOAR/SIEM... 
    Remote work

    Red Cup IT

    United States
    1 day ago
  • $168.2k - $269.9k

     ...applications and next steps. Our partner is looking for a Staff Cloud Security Engineer based in United States. As a Staff Cloud Security Engineer...  ...operational efficiency. Establish and maintain IAM controls across cloud environments, enforcing least-privilege... 
    Full time
    Remote work
    Flexible hours

    Jobgether

    Remote
    4 days ago
  • $155.52k - $228.7k

     ...is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Staff Enterprise Security Engineer, AI Security based in United States. This is a senior technical leadership opportunity focused on securing enterprise... 
    Full time
    Remote work
    Flexible hours

    Jobgether

    Remote
    4 days ago
  •  ...connectivity provider, is looking for a skilled and experienced Staff Information Security Engineer to join their technology team. Information security plays...  ...operations.Platform EnvironmentIdentity & Access: IAM, SSO, RADIUS, TACACS+, AD/LDAP/Kerberos, Entra, PIM, Identity... 
    Full time
    Work at office
    Remote work
    Flexible hours
    2 days per week

    Motion Recruitment

    Charlotte, NC
    3 days ago
  • Role Description We are looking for a Staff Product Security Engineer to define and build the security architecture for Theo and the cloud platform...  ...systems. ~Strong knowledge of authentication, authorization, IAM, tenant isolation, secrets management, encryption, network... 
    Full time

    FirstPrinciples

    Remote
    5 days ago
  • $210k - $260k

     ...journey toward becoming the world's top retail-focused trading platform in the world. What you'll do:We're looking for aStaff Security Engineer, Application Security to help scale and mature our security program. You'll own key security domains and initiatives end-to-end... 
    Work at office
    Remote work
    Worldwide
    Monday to Friday
    Flexible hours

    NinjaTrader Group

    Chicago, IL
    8 hours ago
  •  ...and colleagues. Those stories are part of what makes this such a special place to work.Job OverviewMacy’s is seeking a Staff Information Security Engineer to join its Cloud Security team. This position plays a pivotal role in designing, implementing, and operating secure... 
    Work experience placement
    Flexible hours
    Shift work

    Macy's

    Georgia
    3 days ago
  • $198k - $273k

     ...CAInformation Technology and Applications - Enterprise Security /Full-time /HybridZoox's Network Security team...  ...of the company — from corporate offices to engineering labs and product/mission environments. As a Senior or Staff Network Security Engineer, you will design,... 
    Full time
    Temporary work
    Remote work
    Relocation package

    Zoox

    Foster, CA
    4 days ago
  • This is a hybrid role (3 days in office / 2 days remote).About your team:We seek a motivated Incident Responder to join our Security Operations team. You will assist in monitoring, detecting, analyzing, and responding to security events and incidents. This role is ideal... 
    Work at office
    Remote work

    Interactive Brokers

    Chicago, IL
    2 days ago
  •  ...every step of the way. Join us to invest in yourself, your career, and the financial world.The role: We’re seeking a Staff Security Detection Engineer to build and mature SoFi’s machine learning-driven detection and anomaly detection program. You will own the detection... 
    Remote work

    SoFi

    San Francisco, CA
    2 days ago
  • $145k - $155k

     ...for Applicants:At Bixal, we want to ensure a transparent and secure application process for all candidates. Official communication...  ...FedRAMP-authorized systems continuously compliant while enabling engineering velocity.This role offers you a unique opportunity to make a... 
    Temporary work
    Local area
    Remote work
    Flexible hours
    Weekend work

    Bixal

    Fairfax, VA
    4 days ago
  •  ...IAM Security Engineer The IAM Security Engineer role will be responsible for designing, developing, testing, implementing, and integrating...  ...technical concepts to a broad range of technical and non- technical staff. Must possess a high degree of integrity, be trustworthy,... 
    Remote work

    InterSources

    United States
    2 days ago
  • $73.84k - $128.44k

     ...invited to join our Enterprise Information Security team, focusing on corporate Identity &...  ...your technical expertise across various IAM products and systems to improve the security...  ...platforms such as Microsoft Entra ID Engineer and manage identity integrations with ServiceNow... 

    Esri

    Redlands, CA
    2 days ago
  • $65 - $72 per hour

     ...recruiter to learn more. Base pay range $65.00/hr - $72.00/hr Software Guidance & Assistance, Inc., (SGA), is searching for a IAM Security Engineer (GCP) for a Contract assignment with one of our premier Regulatory clients in Rockville, MD. Candidate must be in the DMV... 
    Full time
    Contract work
    Remote work
    2 days per week
    3 days per week

    Software Guidance & Assistance

    Rockville, MD
    4 days ago
  • $119k - $187k

     ...About this role: Wells Fargo is seeking an Information Security Engineering Manager to lead a Privileged Access Management (PAM) engineering...  ...standing access Partner closely with security architecture, IAM, cloud, infrastructure, and application teams to embed privileged... 
    Full time
    Work experience placement
    Remote work

    Wells Fargo

    Irving, TX
    1 day ago
  • $96.5k - $123k

     ...IAM Security Engineer Job Locations US-Remote Our Mission Our mission is to SAVE AND IMPROVE LIVES BY EMPOWERING HEALTHCARE CONSUMERS. Come be part of remarkable. Overview How you can make a difference Join our team as an IAM Engineer and... 
    Work experience placement
    Remote work

    HealthEquity

    Draper, UT
    3 days ago
  • $106k - $142k

     ...inclusive, adaptable, and forward-thinking organization, apply now. We are currently seeking a Identity & Access Management (IAM) Security Engineer - ONSITE in Addison, TX to join our team in Addison, Texas (US-TX), United States (US). Prior to Applying, please... 
    Temporary work
    Work at office
    Remote work
    Flexible hours

    NTT DATA, Inc.

    Addison, TX
    13 days ago
  • $139.8k - $223.7k

     ...challenged. Be heard. Be valued. Be you ... be here.Job SummaryThe Staff Cyber Security Engineer is a senior individual contributor who will provide...  ...experience working in cybersecurity, security operations, IAM, PAM, cyber defense, or related technical roles.Demonstrated... 
    Full time
    Temporary work
    Work at office
    Local area
    Immediate start
    Remote work
    Work visa
    Flexible hours

    Bread Financial

    Columbus, OH
    8 hours ago
  •  ...clients in Seattle, WA to drive high-impact Identity Security initiatives across our enterprise IAM landscape. This contingent role sits within the...  ...Identity Security organization and partners closely with engineering, architecture, compliance, and business teams to... 
    Temporary work
    Remote work

    Confiz

    Seattle, WA
    a month ago
  •  ...powering telehealth solutions at scale. We are hiring a Sr. Staff IAM Engineer (Architect) to be the design authority for identity across...  ...across Okta, Entra ID, AWS, and GCP. ~Build out Identity Security Posture Management, extending the posture warehouse and remediation... 
    Full time
    Flexible hours

    OpenLoop Health

    Remote
    22 days ago
  •  ...Staff Cloud Security Engineer Join us as a Staff Cloud Security Engineer and play a pivotal role in securing and scaling the cloud foundation that...  ...into CI/CD workflows and product lifecycles. Define IAM strategies, implement network segmentation, apply encryption... 
    Temporary work
    Remote work
    Work from home
    Home office

    ASSURED

    United States
    1 day ago
  • $20k

     ...Ready to be a Titan? We are seeking an experienced Staff Cloud Security Engineer to shape the security foundation of our modern cloud environments...  ...security processes. Identity and Access Management (IAM) Cloud Identity Controls: Build and maintain IAM security... 
    Minimum wage
    Local area
    Remote work
    Flexible hours

    ServiceTitan

    United States
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Staff Security Engineer, IAM. Be the first to apply!