InterviewHack.ai
Start free
Jobs / Gitlab

Senior Security Risk Engineer

Gitlab·Remote, Canada; Remote, United StatesRemotesenior

In short

  • →Ingeniero de riesgo de seguridad senior que automatiza y moderniza la gestión de riesgos con IA.
  • →Traduce vulnerabilidades técnicas en declaraciones de riesgo cuantificadas para líderes y equipos no técnicos.
  • →Destacado: lidera la gestión de riesgos de IA y prepara a GitLab para la certificación ISO 42001.

Proficiency in English required for collaboration across global teams.

Apply on company site ↗Share on WhatsApp

In ~1 minute you get: who interviews you, the likely questions answered from your CV, and your CV tailored to this job. Free, no card.

The questions they'll ask you

1. ¿Cómo has traducido un hallazgo técnico complejo en una declaración de riesgo accionable para ejecutivos?

2. ¿Qué herramientas o scripts has usado para automatizar la gestión de riesgos en un entorno GRC?

3. ¿Qué pasos tomarías para iniciar un proceso de evaluación de riesgos de IA en un nuevo producto?

🔒 +7 more questions

No card. Upload your resume and the full dossier is ready in ~1 minute.

🎧Land the interview? Bring the copilot. Our free extension listens to the live interview and flashes 3-4-word anchors from your resume and prep — glance, connect, talk. Get the extension →

💵 USD · Remote · No visa

Not finding what you want? Try Micro1

Micro1 places engineers directly at US companies paying in USD. One vetting, multiple offers — no cold applying.

Get matched by Micro1 →
📬Jobs picked for YOUR resume, every morning on WhatsApp. Free: text “vacantes” and the bot sends your daily matches. Subscribe →

What they ask for

  • ✓Experiencia comprobada en gestión de riesgos de seguridad (TPRM, evaluaciones de riesgo, remediación).
  • ✓Conocimiento profundo de marcos de riesgo (NIST RMF, ISO 31000, NIST 800-39).
  • ✓Capacidad para traducir hallazgos técnicos en riesgos de negocio claros y cuantificables.
  • ✓Experiencia en automatización de flujos de trabajo de GRC con scripting o herramientas de IA.
  • ✓Experiencia en gestión de riesgos de IA y preparación para certificación ISO 42001.
  • ✓Habilidades de colaboración con equipos de ingeniería, legal, producto e IT.

Don't tick every box? That's normal — your free dossier shows your gaps and how to cover them in the interview.

NIST RMFISO 31000NIST 800-39AIScriptingRisk RegisterGRC workflowsKey Risk IndicatorsISO 42001Remediation tracking

Who should you write to at Gitlab?

Your free dossier identifies the people who'd interview you — their background, what they value, and how to reach out so you stand out before applying.

GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50 million registered users and more than 50% of the Fortune 100* trust GitLab to ship better, more secure software faster. The same principles built into our products are reflected in how our team works: we embrace AI as a core productivity multiplier, with all team members expected to incorporate AI into their daily workflows to drive efficiency, innovation, and impact. GitLab is where careers accelerate, innovation flourishes, and every voice is valued. Our high-performance culture is driven by our values and continuous knowledge exchange, enabling our team members to reach their full potential while collaborating with industry leaders to solve complex problems. Co-create the future with us as we build technology that transforms how the world develops software. * Fortune 500® is a registered trademark of Fortune Media IP Limited, used under license. Claim based on GitLab data. Fortune 100 refers to the top 20% ranked companies in the 2025 Fortune 500 list, published in June 2025. Fortune and Fortune Media IP Limited are not affiliated with, and do not endorse products or services of GitLab. An overview of this role GitLab's Security Risk function is responsible for reducing risk across the security division: third-party risk (TPRM), annual security risk assessments, quarterly risk reporting, and remediation of security findings. As a Senior Security Risk Engineer, you'll take ownership of risk identification, quantification, and remediation tracking across the business, and you'll be a driving force behind automating and modernizing how the team does this work using AI and scripting. Reporting to the Security Risk Manager, you will bring expertise on risk methodology, risk-based thinking, and AI-enablement. In this role, you'll partner closely with Security, Legal, IT, Product, and Engineering to translate technical findings and vendor risk into business-relevant risk statements and risk treatments. You’ll help surface emerging risks, and report top risks to leadership. Some examples of our projects: • Building and maintaining a risk register that translates technical vulnerabilities, control gaps, and third-party risk findings into quantified, business-relevant risk statements. • Driving cross-functional remediation of security findings and risk issues to closure, tracked against SLAs. • Driving automation and AI-enabled improvements for risk and GRC workflows so the team can spend less time on manual work and more time on high-value risk analysis and program maturity. What you'll do • Own risk identification, analysis, and prioritization across third-party risk (TPRM), security risk assessments, and security findings, using an established risk framework (e.g., NIST RMF, ISO 31000, or NIST 800-39). • Translate technical vulnerabilities, control gaps, and risk findings into clear, quantified risk statements that non-security stakeholders and leadership can act on. • Drive remediation of findings and risk exceptions to closure, partnering with Engineering, IT, Product, and Legal, and escalating stalled or high-severity items. • Mature and maintain a risk register and quarterly reporting cadence that gives leadership clear visibility into open risk, remediation progress, and trends. • Own and mature AI risk management, including AI impact assessments, AI risk assessments, and risk treatments, to support ISO 42001 certification. • Design, develop, and implement key risk indicators and supp

Looking for something similar?

Leave your email and we'll alert you when matching jobs appear.

Don't apply unprepared

We research who's interviewing you, tailor your CV and rehearse you live — first one free.

InterviewHack.ai

Prepare for the exact interview: who's interviewing you, a tailored CV, and a real coach.

Product

JobsCompanies hiringFree ATS checkerInterview-English checkSalary checkFree STAR answerResume verdict (Jev)LATAM salary reportFree coursesBlogTailored CVSpoken practiceIt's free

Remote jobs

ReactPythonFull-StackLATAMArgentinaMexicoSee all →

Prepare

Spoken practiceFrontendBackendAI EngineerBy companySell with your CV

Company

For employersAboutContactPrivacyTerms

© 2026 InterviewHack.ai · Your CV is yours. Never used to train anything. · A product of IA-PTY

Similar open roles

Manager, Renewals

Gitlab · Remote, Canada; Remote, United States

→

Associate Renewals Manager

Gitlab · Remote, Canada; Remote, United States

→

Senior Solutions Architect- Sydney

Gitlab · Remote

→

Senior Manager of Success Architects

Gitlab · Remote, Singapore

→