
Gitlab · Remote
GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency,...
GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity,
improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50 million
registered users and more than 50% of the Fortune 100* trust GitLab to ship better, more secure software faster.
The same principles built into our products are reflected in how our team works: we embrace AI as a core productivity multiplier,
with all team members expected to incorporate AI into their daily workflows to drive efficiency, innovation, and impact. GitLab is
where careers accelerate, innovation flourishes, and every voice is valued. Our high-performance culture is driven by our
values and continuous knowledge exchange, enabling our team members to reach their full potential while collaborating with
industry leaders to solve complex problems. Co-create the future with us as we build technology that transforms how the world
develops software.
refers to the top 20% ranked companies in the 2025 Fortune 500 list, published in June 2025. Fortune and Fortune Media IP Limited
are not affiliated with, and do not endorse products or services of GitLab.
The Senior Manager, Customer Trust & Security Governance helps GitLab turn security into a clear business enabler. In this role,
you will oversee the programs that help our customers and prospects assess our security posture, reduce friction in our sales
cycle, strengthen our security policy and standards, and make security outcomes visible across the business. Reporting to the VP
of Security Assurance, you will own a broad scope across customer trust, governance, metrics, and security awareness, with a focus
on building durable processes, improving documentation, and using automation and AI to help our team spend more time on high-value
work.
In your first year, you will shape how GitLab addresses customer security needs at scale, mature the security governance program,
and improve how security is measured and communicated internally. You will work across Security, Sales, Legal, Product,
Procurement, and other business partners, and you will help strengthen confidence in GitLab's AI-powered DevSecOps platform
through practical guidance, clear standards, and thoughtful execution.
and vendor security inquiries.
cycle.
agreements.
solutions.
consistent negotiations.
security standards.
effectiveness.
environment.
business needs.
written communication.
security, governance, or trust roles.
DUE TO GOVERNMENT REQUIREMENTS, YOU MUST BE A UNITED STATES CITIZEN (DEFINED AS ANY INDIVIDUAL WHO IS A CITIZEN OF THE UNITED
STATES BY LAW, BIRTH, OR NATURALIZATION) TO FILL THIS POSITION.
The team is responsible for helping GitLab demonstrate and operationalize trust through customer-facing security support, internal
governance, measurable security outcomes, and security awareness. It works across regions in an asynchronous way and partners
closely with Security, Sales, Legal, Product, Procurement, and Engineering to make security clear, practical, and scalable. This
team supports both business velocity and sound governance by improving how GitLab responds to customer requirements, maintains
security standards, and communicates progress.
The base salary range for this role’s listed level is currently for residents of the United States only. This range is intended to
reflect the role's base salary rate in locations throughout the US. Grade level and salary ranges are determined through
interviews and a review of education, experience, knowledge, skills, abilities of the applicant, equity with other team members,
alignment with market data, and geographic location. The base salary range does not include any bonuses, equity, or benefits. See
more information on our benefits and equity. Sales roles are also eligible for incentive pay targeted at up to 100% of the offered
base salary.
United States Salary Range
Please note that we welcome interest from candidates with varying levels of experience; many successful candidates do not meet
every single requirement. Additionally, studies have shown that people from underrepresented groups are less likely to apply to a
job unless they meet every single qualification. If you're excited about this role, please apply and allow our recruiters to
assess your application.
Country Hiring Guidelines: GitLab hires new team members in countries around the world. All of our roles are remote, however some
roles may carry specific location-based eligibility requirements. Our Talent Acquisition team can help answer any questions about
location after starting the recruiting process.
Privacy Policy: Please review our Recruitment Privacy Policy. Your privacy is important to us.
GitLab is proud to be an equal opportunity workplace and is an affirmative action employer. GitLab’s policies and practices
relating to recruitment, employment, career development and advancement, promotion, and retirement are based solely on merit,
regardless of race, color, religion, ancestry, sex (including pregnancy, lactation, sexual orientation, gender identity, or gender
expression), national origin, age, citizenship, marital status, mental or physical disability, genetic information (including
family medical history), discharge status from the military, protected veteran status (which includes disabled veterans, recently
separated veterans, active duty wartime or campaign badge veterans, and Armed Forces service medal veterans), or any other basis
protected by law. GitLab will not tolerate discrimination or harassment based on any of these characteristics. See also GitLab’s
EEO Policy and EEO is the Law. If you have a disability or special need that requires accommodation, please let us know during
the recruiting process.
GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50 million registered users and more than 50% of the Fortune 100* trust GitLab to ship better, more secure software faster. The same principles built into our products are reflected in how our team works: we embrace AI as a core productivity multiplier, with all team members expected to incorporate AI into their daily workflows to drive efficiency, innovation, and impact. GitLab is where careers accelerate, innovation flourishes, and every voice is valued. Our high-performance culture is driven by our values and continuous knowledge exchange, enabling our team members to reach their full potential while collaborating with industry leaders to solve complex problems. Co-create the future with us as we build technology that transforms how the world develops software. *Fortune 500® is a registered trademark of Fortune Media IP Limited, used under license. Claim based on GitLab data. Fortune 100 refers to the top 20% ranked companies in the 2025 Fortune 500 list, published in June 2025. Fortune and Fortune Media IP Limited are not affiliated with, and do not endorse products or services of GitLab. AN OVERVIEW OF THIS ROLE As a Senior Manager, Security Compliance at GitLab, you'll lead and mature our security compliance function while helping the company meet the needs of customers, auditors, and regulators across a growing set of security and compliance requirements. Reporting to the VP of Security Assurance, you'll bring deep expertise in security frameworks, risk-based thinking, and team leadership to guide our certification strategy and strengthen how we manage compliance across the business. In this role, you'll work across Security, Legal, IT, Product, and Engineering to evolve a compliance program that supports both strong security outcomes and business growth. You'll help shape a roadmap that keeps pace with emerging regulations and frameworks, while also improving how the team works through automation, artificial intelligence, and scalable processes. This role is a strong fit for someone who can balance strategic leadership with operational excellence and who sees compliance as an important customer trust and sales enabler. Some examples of our projects: * Leading and expanding GitLab's security certification portfolio across commercial, public sector, and industry-specific frameworks while improving the way control testing and assurance activities are performed * Driving automation and AI-enabled improvements for risk and compliance workflows so the team can spend less time on manual work and more time on high-value risk analysis and program maturity WHAT YOU'LL DO * Lead and mentor a team focused on security compliance, providing direction, support, and clear priorities while building a high-performing function. * Oversee and expand GitLab's certification portfolio across frameworks such as ISO 27001/17/18, ISO 42001, Service Organization Control 2 (SOC 2), Payment Card Industry (PCI), TiSAX, Cyber Essentials, and Federal Risk and Authorization Management Program (FedRAMP). * Partner with cross-functional stakeholders in IT, Security, Legal, Product, and Engineering to integrate governance, risk, and compliance requirements into business processes and technical systems. * Drive automation within the function by using scripting, coding, and AI-enabled approaches to improve governance, risk, and compliance workflows, including compliance-as-code and policy-as-code practices. * Monitor regulatory changes, emerging frameworks, and industry trends, and use those insights to help shape the team's roadmap and prepare the business for new requirements. * Manage relationships with third-party auditors, assessors, and consultants during activities such as external audits, certification reviews, and penetration tests. * Strengthen the team's security metrics and reporting practices, including preparing and facilitating regular business reviews and giving leadership clear visibility into progress and risk. * Serve as a subject matter expert and thought partner by delivering guidance, training, and security-focused content for internal teams, customers, and senior stakeholders, while helping strengthen GitLab's voice in the broader security market. WHAT YOU'LL BRING * Extensive experience in security compliance, audit, or related governance, risk, and compliance work, including experience supporting external audits. * Deep knowledge of security and compliance frameworks such as SOC 2, ISO 27001, FedRAMP, and National Institute of Standards and Technology (NIST), with public sector or FedRAMP experience preferred. * Experience leading teams and developing people, with the ability to set direction, manage priorities, and build strong partnerships across a distributed organization. * Strong understanding of cloud security, software as a service (SaaS) security models, and DevSecOps practices, with the ability to apply that knowledge in a fast-moving technology environment. * A risk-based mindset that goes beyond checklist compliance and focuses on meaningful control design, testing, and continuous improvement. * Comfort using automation, scripting, or AI-enabled approaches to reduce manual work and improve the scale and efficiency of compliance programs. * Excellent written and verbal communication skills, including the ability to explain complex technical and regulatory topics clearly to auditors, customers, executives, and cross-functional partners. * Relevant certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), or similar credentials are highly desirable. Due to government requirements, you must be a United States Citizen (defined as any individual who is a citizen of the United States by law, birth, or naturalization) to fill this position. ABOUT THE TEAM The Security Assurance organization helps GitLab build and maintain trust by strengthening how we approach security, compliance, and assurance across the company. Within that group, the security compliance function works at the intersection of customer trust, regulatory readiness, operational rigor, and business growth. The team partners broadly across GitLab to help ensure our controls, certifications, and assurance activities support both secure operations and the needs of a global business. The base salary range for this role’s listed level is currently for residents of the United States only. This range is intended to reflect the role's base salary rate in locations throughout the US. Grade level and salary ranges are determined through interviews and a review of education, experience, knowledge, skills, abilities of the applicant, equity with other team members, alignment with market data, and geographic location. The base salary range does not include any bonuses, equity, or benefits. See more information on our benefits and equity. Sales roles are also eligible for incentive pay targeted at up to 100% of the offered base salary. United States Salary Range $168,000—$245,000 USD HOW GITLAB SUPPORTS FULL-TIME EMPLOYEES * Benefits to support your health, finances, and well-being * Flexible Paid Time Off * Team Member Resource Groups * Equity Compensation & Employee Stock Purchase Plan * Growth and Development Fund * Parental Leave Please note that we welcome interest from candidates with varying levels of experience; many successful candidates do not meet every single requirement. Additionally, studies have shown that people from underrepresented groups are less likely to apply to a job unless they meet every single qualification. If you're excited about this role, please apply and allow our recruiters to assess your application. ---------------------------------------------------------------------------------------------------------------------------------- Country Hiring Guidelines: GitLab hires new team members in countries around the world. All of our roles are remote, however some roles may carry specific location-based eligibility requirements. Our Talent Acquisition team can help answer any questions about location after starting the recruiting process. Privacy Policy: Please review our Recruitment Privacy Policy. Your privacy is important to us. GitLab is proud to be an equal opportunity workplace and is an affirmative action employer. GitLab’s policies and practices relating to recruitment, employment, career development and advancement, promotion, and retirement are based solely on merit, regardless of race, color, religion, ancestry, sex (including pregnancy, lactation, sexual orientation, gender identity, or gender expression), national origin, age, citizenship, marital status, mental or physical disability, genetic information (including family medical history), discharge status from the military, protected veteran status (which includes disabled veterans, recently separated veterans, active duty wartime or campaign badge veterans, and Armed Forces service medal veterans), or any other basis protected by law. GitLab will not tolerate discrimination or harassment based on any of these characteristics. See also GitLab’s EEO Policy and EEO is the Law. If you have a disability or special need that requires accommodation, please let us know during the recruiting process.
WHO WE ARE The real world is the next frontier, and at Metropolis, we are creating the artificial intelligence to make it responsive. We are pioneering the Recognition Economy — a future where mundane repetition disappears and being known unlocks access, comfort and belonging everywhere you go. From transforming parking into a seamless drive-in, drive-out experience for millions of Members to expanding our intelligence layer across retail and hospitality, we are building a world that feels instinctive and magical. The future isn’t coming; it’s here, and we need builders, innovators and problem solvers to help us create it. WHO YOU ARE Metropolis is seeking a Governance, Risk, and Compliance (GRC) Analyst to join our expanding Security team. Reporting to the Senior Manager, GRC, you will mature information security policies, drive employee security awareness, and pioneer our AI governance framework. You will partner across Technology, Legal, Internal Audit, Procurement, and People Operations to safeguard customer trust and support operational excellence. WHAT YOU'LL DO * Author, update, and enforce corporate security policies to guarantee cross-departmental compliance * Deploy and manage required information security training campaigns as the platform owner * Transform static policies into interactive modules with comprehension quizzes for mandatory sign-offs * Establish and enforce an internal AI governance framework with Data, Legal, and Tech teams * Conduct structured risk assessments on emerging tools and internal AI models to maintain behavioral guardrails * Report training metrics, policy exceptions, and risk postures directly to senior management * Review vendor security profiles and software pipelines to mitigate security risk WHAT WE'RE LOOKING FOR * 3+ years of experience in information security GRC, cybersecurity training, or technology compliance * Proven track record of managing required security awareness programs and driving cross-functional accountability * Experience with modern training orchestration platforms and understanding of AI and machine learning data security * Working knowledge of standard industry frameworks, specifically SOC 2 and PCI-DSS * Communication skills with the ability to explain complex regulatory needs to non-technical employees * Bachelor’s degree in Cybersecurity, Information Systems, or an equivalent technical discipline WHILE NOT REQUIRED, THESE ARE A PLUS: * GRC certifications such as CISA or CRISC ---------------------------------------------------------------------------------------------------------------------------------- 4 Days in Office: Metropolis values in-person collaboration to drive innovation, strengthen culture, and enhance the Member experience. Our corporate team members hold to our office-first model, which requires employees to be on-site at least four days a week, fostering organic interactions that spark creativity and connection When you join Metropolis, you'll join a team of world-class product leaders and engineers, building an ecosystem of technologies at the intersection of parking, mobility, and real estate. Our goal is to build an inclusive culture where everyone has a voice and the best idea wins. You will play a key role in building and maintaining this culture as our organization grows. The anticipated base salary for this position is $100,000.00 USD to $135,000.00 USD annually. The actual base salary offered is determined by a number of variables, including, as appropriate, the applicant's qualifications for the position, years of relevant experience, distinctive skills, level of education attained, certifications or other professional licenses held, and the location of residence and/or place of employment. Base salary is one component of Metropolis’s total compensation package, which may also include access to or eligibility for healthcare benefits, a 401(k) plan, short-term and long-term disability coverage, basic life insurance, a lucrative stock option plan, bonus plans and more. #LI-CM1 #LI-Onsite Metropolis may utilize an automated employment decision tool (AEDT) to assess or evaluate your candidacy for employment or promotion. AEDTs are used to assist in assessing a candidate’s application relative to the required job qualifications and responsibilities listed in the job posting. As part of this process, Metropolis retains data relevant to your candidacy, including personal information, for a period that is reasonably necessary for the use of the tool. If you are hired for the position, your data may become part of your employee records. Metropolis Technologies is an equal opportunity employer. We make all hiring decisions based on merit, qualifications, and business needs, without regard to race, color, religion, sex (including gender identity, sexual orientation, or pregnancy), national origin, disability, veteran status, or any other protected characteristic under federal, state, or local law.
The Security Product Management team is vital in safeguarding customer trust and making data security a market differentiator that enables MongoDB to succeed in enterprise and regulated industries. Our team's scope is broad and critical, covering a range of features, including Networking, IAM, Data Governance, Encryption, Compliance, and Auditing. This role can be based out of our Toronto office, or remotely in Canada. RESPONSIBILITIES * In this role, you will be a key member of security product management responsible for Account Protection and safeguarding customer trust at MongoDB * Develop a robust vision for best-in-class security and identity threat management, from identification to remediation * Build a vision for best-in class security features that identify, mitigate, and proactively prevent unauthorized attempts to access data * Partner with engineering to develop a prioritized product roadmap and backlog to execute against that vision * Deeply understand all aspects of the business - to ensure a business outcome aligned with our broader product, customer, and company goals * Deepen our understanding of evolving threats and corresponding technologies in data security. Use customer inputs to serve as an expert and propose new innovations or best practices from the industry * Partner with engineering, legal, research, product marketing, support, sales, and security teams to deepen customer trust as they use MongoDB for their most critical data workloads * Define and implement key performance indicators (KPIs) and success metrics for security initiatives, ensuring alignment with business objectives and product goals REQUIREMENTS * 5+ years of product management or equivalent experience in enterprise security or platforms * Experience working with security focused engineers in a diverse team * Domain expertise in threat detection, data security, or a related field * Experience driving business results through influential leadership across multiple partner teams including engineering, sales, marketing, solution architects and customer success. * Excellent written and verbal communication skills, including experience presenting to executive leadership * Proven ability to define and deliver successful product strategies and roadmaps * Demonstrated experience in defining technical product requirements into an actionable product roadmap * Understanding of various public cloud providers such as AWS, Azure, and GCP * Comfortable with stage presence and public speaking * B.Sc. in Computer Science, or equivalent experience NICE TO HAVE * Certifications or similar evidence of professional milestone completion and continuous training (such as: CISSP, CompTia Security+, SANS, etc.) * Community support and participation to advance data and cloud security such as conference or meetup panels and blog or paper authorship * MBA, M.Sc.+ or equivalent in relevant domain ABOUT MONGODB MongoDB is built for change, empowering our customers and our people to innovate at the speed of the market. We have redefined the data platform for the AI era, enabling builders to create, transform, and disrupt industries with software. MongoDB’s unified data platform, the most widely available, globally distributed data platform on the market, helps organizations modernize legacy workloads, embrace innovation, and unleash AI. Our cloud-native platform, MongoDB Atlas, is the only globally distributed, multi-cloud data platform and is available across AWS, Google Cloud, and Microsoft Azure. With offices worldwide and over 67,000 customers, including 75% of the Fortune 100 and AI-native startups, relying on MongoDB for their most important applications, we’re powering the next era of software. Our compass at MongoDB is our Leadership Commitment, guiding how and why we make decisions, show up for each other, and win. It’s what makes us MongoDB. To drive the personal growth and business impact of our employees, we’re committed to developing a supportive and enriching culture for everyone. From employee affinity groups, to fertility assistance and a generous parental leave policy, we value our employees’ wellbeing and want to support them along every step of their professional and personal journeys. Learn more about what it’s like to work at MongoDB, and help us make an impact on the world! MongoDB is committed to providing any necessary accommodations for individuals with disabilities within our application and interview process. To request an accommodation due to a disability, please inform your recruiter. MongoDB is an equal opportunities employer. Req ID: 4263333204 MongoDB’s base salary range for this role is posted below. Compensation at the time of offer is unique to each candidate and based on a variety of factors such as skill set, experience, qualifications, and work location. Salary is one part of MongoDB’s total compensation and benefits package. Other benefits for eligible employees may include: equity, participation in the employee stock purchase program, flexible paid time off, 20 weeks fully-paid gender-neutral parental leave, fertility and adoption assistance, Registered Retirement Savings Plan (RRSP) with employer match, mental health counseling, backup child and elder care, and health, dental, and vision benefits offerings. Please note, the base salary range listed below and the benefits in this paragraph are only applicable to candidates based in Canada. MongoDB’s base salary range for this role in Canada is: $130,000—$180,000 CAD AI is used to review applications based on job-related criteria and does not replace human decision-making. The hiring team decide who moves forward. MongoDB’s base salary range for this role is posted below. Compensation at the time of offer is unique to each candidate and based on a variety of factors such as skill set, experience, qualifications, and work location. Salary is one part of MongoDB’s total compensation and benefits package. Other benefits for eligible employees may include: equity, participation in the employee stock purchase program, flexible paid time off, 20 weeks fully-paid gender-neutral parental leave, fertility and adoption assistance, Registered Retirement Savings Plan (RRSP) with employer match, mental health counseling, backup child and elder care, and health, dental, and vision benefits offerings. Please note, the base salary range listed below and the benefits in this paragraph are only applicable to candidates based in Canada. MongoDB’s base salary range for this role in Canada is: $130,000—$180,000 CAD