Senior Security Risk Engineer

G
GitLabCybersecurity software
Remote, Canada; Remote, United StatesFull-TimeSenior
Salary139,200 - 189,000 USD per year
Apply NowOpens the employer's application page

Job Details

Experience
5+ years of experience in security risk management
Required Skills
Risk Management

Requirements

  • 5+ years of experience in security risk management.
  • Experience with security-centric risk management or compliance frameworks such as NIST RMF, NIST 800-39, or ISO 31000.
  • Experience designing and executing qualitative and quantitative risk analyses that translate technical risks into measurable business impact.
  • Experience driving risk assessments, risk registers, and remediation to closure across cross-functional teams.
  • Experience interpreting technical control requirements for technical and non-technical stakeholders.
  • Demonstrated experience personally building scripts, workflows, or AI-enabled tooling to reduce manual risk or GRC work.
  • Strong understanding of cloud security, SaaS security models, and DevSecOps practices.
  • Ability to manage concurrent assessments and reprioritize under tight deadlines.
  • Relevant certifications such as CISSP, CISM, CISA, or CRISC are preferred but not required.
  • Familiarity with AI governance frameworks such as ISO 42001 or NIST AI RMF is a plus.

Responsibilities

  • Own risk identification, analysis, and prioritization across third-party risk, security risk assessments, and security findings.
  • Translate technical vulnerabilities, control gaps, and risk findings into quantified risk statements for stakeholders and leadership.
  • Drive remediation of findings and risk exceptions to closure, escalating stalled or high-severity items.
  • Maintain the risk register and quarterly reporting cadence, including remediation progress and trends.
  • Manage AI impact assessments, AI risk assessments, and risk treatments to support ISO 42001 certification.
  • Design and implement key risk indicators and supporting metrics for top risks.
  • Build automation, scripts, or AI-enabled tooling to reduce manual work in risk and TPRM workflows.
  • Contribute to the risk program roadmap and monitor emerging frameworks, threats, and business changes.
View Full Description & ApplyYou'll be redirected to the employer's site
139,200 - 189,000 USD per year
Apply Now