Senior Security Compliance Engineer, Public Sector
New
G
GitLabCybersecurity / DevSecOps
Location: Remote, United StatesFull-TimeSenior
Salary139,200 - 196,000 USD per year
Apply NowOpens the employer's application page
Job Details
- Experience
- Minimum of 5 years of experience in GRC, cybersecurity, or a related field
- Required Skills
- AWSCloud ComputingCybersecurityGCP
Requirements
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or equivalent experience.
- Minimum of 5 years of experience in GRC, cybersecurity, or a related field in highly regulated industries.
- Proven experience achieving and maintaining security certifications such as FedRAMP, CMMC, SOC 2, IRAP, or ISO 27001.
- Strong understanding of regulatory and compliance requirements for the public sector.
- Familiarity with implementing compliance-as-code or policy-as-code and automating control testing.
- Basic knowledge of FedRAMP requirements, processes, and documentation.
- Familiarity with cloud hyperscalers such as AWS and GCP.
- Excellent analytical, problem-solving, and project management skills.
- Strong communication and interpersonal skills.
- Relevant certifications such as CISSP, CISM, or CISA are highly desirable.
Responsibilities
- Develop, implement, and manage GRC strategies and processes to support compliance with various regulatory and industry standards, including FedRAMP, IRAP, and others.
- Work closely with highly regulated customers to understand their unique compliance requirements and provide tailored solutions.
- Lead and manage security assessments, audits, and certification processes.
- Support GitLab Dedicated for Government’s ongoing FedRAMP continuous monitoring commitments.
- Collaborate with cross-functional teams, including IT, Product, Engineering, Security, and Legal, to integrate GRC requirements.
- Develop and maintain comprehensive documentation, including policies, procedures, and controls.
- Utilize scripting/coding skills to automate GRC processes and implement compliance-as-code or policy-as-code solutions.
- Monitor and analyze regulatory changes and industry trends to ensure continuous improvement of the GRC program.
View Full Description & ApplyYou'll be redirected to the employer's site