Depth in application security architecture, including authentication and authorization models, privilege escalation, multi-tenant isolation, and trust boundary analysis
Experience securing distributed systems, including service-to-service authentication, secrets handling, and the failure modes of security decisions made across process boundaries
Working knowledge of software supply chain security: build and release integrity, artifact provenance, and dependency risk
A track record of proactive architecture work — identifying risk before it becomes an incident, and designing something that prevents a class of problem rather than an instance of one
Demonstrated ability to build trusted relationships with engineering leadership and influence technical direction through expertise rather than gatekeeping
Experience defining security standards or patterns that teams adopted without being compelled to
The ability to operate strategically while remaining hands-on, including reading unfamiliar code, building prototypes, and contributing changes
Clear written communication, and the ability to make a security argument to an engineering audience that does not already agree with it
A view on how security guidance should be authored and delivered for AI coding tools, not only for humans
What you'll be doing
Partner with engineering and product leadership across GitLab, developing enough context in their domains to anticipate security problems rather than react to them
Lead security architecture and design work for strategic initiatives, and provide direction to the cross-functional teams delivering them
Identify, assess, and prioritise systemic security risks, and act as Security Owner for high-priority items in the Product Security Risk Register, co-executing remediation with the teams who own the code
Codify recurring security decisions into reusable artifacts — guardrails, standards, design patterns,skills, and reference threat models — delivered into developer and AI coding tool workflows
Build proofs of concept and prototypes to unblock engineering teams and shorten the distance between a security requirement and a working implementation
Conduct security architecture reviews for large or strategic projects, and coordinate with Application Security so that review coverage is comprehensive and correctly prioritised
Threat model new and existing systems, and establish the patterns that let teams threat model their own work
Work with Security Research on proactive exploration of unknown risks in GitLab's architecture
Anticipate emerging security challenges and propose architectural responses before they reach implementation
Mentor security engineers across the division, and represent security architecture to engineering audiences
Perks and Benefits
Benefits to support your health, finances, and well-being
Flexible Paid Time Off
Team Member Resource Groups
Equity Compensation & Employee Stock Purchase Plan