GitLab is the intelligent orchestration platform for DevSecOps, enabling organizations to increase developer productivity and improve operational efficiency. The Intermediate Infrastructure Security Engineer will support the Public Sector SRE team, identify and mitigate security issues, and partner with senior engineers to ensure that project architectures meet rigorous security standards.
Responsibilities:
- Support the Public Sector SRE team as a stable counterpart
- Identify and help mitigate security issues, misconfigurations, and vulnerabilities related to GitLab’s cloud, container and Kubernetes infrastructure
- Build tooling to increase our visibility into environments to expedite vulnerability detection
- Own efforts securing GitLab's FedRAMP environment
- Support other security teams as an Infrastructure SME
- Document best practices and remediations to help engineers learn from common vulnerability types
- Partner with senior engineers to review new architectures and projects and provide feedback cross-functionally
- Fulfill the Product Security Division Mission of securing GitLab Infrastructure with our own product (“dogfooding”)
Requirements:
- Proof of U.S. citizenship and residency
- Hands-on experience with public cloud providers (ex. AWS, GCP, Azure)
- Development experience with Ruby, Python, Go
- Experience with Infrastructure-as-Code (IaC) tools (ex. Terraform, Ansible, Chef)
- Knowledge of the Linux operating system
- Familiarity with containers (Docker) and orchestration platforms (Kubernetes)
- An interest in Information Security
- Demonstrated experience working collaboratively with cross-functional teams
- Proficiency to communicate over a text-based medium (Slack, GitLab Issues, Email) and can succinctly document technical details
- Share our values, and work in accordance with those values