Staff Infrastructure Security Engineer (apac, Emea)

GitLab GitLab · Enterprise · APAC +1 · Remote · Product Security

This role focuses on applying AI to enhance infrastructure security within a DevSecOps platform. The Staff Infrastructure Security Engineer will set architectural patterns, lead security initiatives, conduct threat modeling, and define the team's approach to AI-assisted security engineering. The role requires expertise in cloud security, container orchestration, Infrastructure-as-Code, and hands-on experience with AI in security workflows.

What you'd actually do

  1. Set architectural patterns, reference implementations, and foundational security automation that shape how infrastructure security is implemented across GitLab
  2. Lead infrastructure security initiatives from problem framing through delivery, scoping ambiguous multi-quarter work into executable streams with clear success criteria
  3. Conduct and lead comprehensive security reviews and threat modeling for complex infrastructure components, identifying systemic risks and driving remediation across affected systems
  4. Set the team's approach to AI-assisted security engineering, identifying where AI can meaningfully increase leverage and establishing patterns others can adopt
  5. Serve as an authoritative technical voice for Infrastructure Security across our stakeholders, translating architectural tradeoffs into clear decisions for engineering teams and senior leadership

Skills

Required

  • security for cloud infrastructure (AWS/GCP/Azure)
  • container orchestration (Kubernetes)
  • data security topics
  • Go
  • Python
  • Ruby
  • production-quality security tooling
  • Infrastructure-as-Code security (Terraform, Ansible, CloudFormation)
  • policy-as-code
  • automated compliance
  • AI to security workflows
  • leading multi-team technical initiatives
  • written and verbal communication skills
  • security certifications, frameworks, and standards (FedRAMP, ISO 27001, SOC 2, PCI-DSS)

Nice to have

  • AI can meaningfully increase leverage
  • AI-assisted security engineering
  • Hands-on experience applying AI to security workflows

What the JD emphasized

  • Expert knowledge of security for cloud infrastructure (AWS/GCP/Azure), container orchestration (Kubernetes) and related infrastructure and data security topics
  • Proficiency in multiple programming languages (Go, Python, Ruby) with a track record of delivering production-quality security tooling
  • Extensive experience with Infrastructure-as-Code security (Terraform, Ansible, CloudFormation), policy-as-code, and automated compliance
  • Hands-on experience applying AI to security workflows, with a point of view on where it creates meaningful leverage
  • Track record of leading multi-team technical initiatives from ambiguous problem statements to measurable outcomes, setting technical direction that peer teams adopt

Other signals

  • AI can meaningfully increase leverage
  • AI-assisted security engineering
  • Hands-on experience applying AI to security workflows