VP, Corporate Security
About the role
An overview of this role
Corporate Security at GitLab leads Identity Engineering, Corporate Security Engineering, and End User Services, bringing together the engineering and service functions that secure workforce identity, internal systems, endpoints, and core business applications. This organization enables GitLab team members to work productively and securely through a 24x5 support model and engineering ownership across identity, device trust, SaaS, platform, and internal security controls.
As VP, Corporate Security, you will lead this organization through its next stage of maturity. You will own strategy, execution, and operational excellence across Corporate Security engineering and services, shaping how GitLab scales secure workforce access, endpoint security, SaaS governance, and internal IT experience in an all-remote environment. You will inherit and develop a multi-disciplinary organization that already includes leadership across identity engineering and corporate security engineering, and you will partner closely with the CISO and peers across Security, IT, Engineering, People, Legal, and Finance.
This role is right for someone who can connect security posture, team member experience, and business enablement. You should be equally comfortable setting executive direction and drilling into operating questions such as how to modernize identity, reduce authentication friction, mature endpoint and SaaS controls, improve onboarding and offboarding, and build systems that are secure by default and auditable by design.
Some examples of the team's focus areas:
- Corporate Security (CorpSec)
- End User Services (EUS)
- Identity Engineering
What you’ll do
- Set the vision and operating model for Corporate Security across engineering, identity, endpoint and device security, and end-user services, aligning security outcomes with productivity and service quality.
- Lead a globally distributed, multi-disciplinary organization through clear roadmaps, strong managers, measurable priorities, and high operational standards.
- Own GitLab’s internal identity and access strategy across Okta, lifecycle automation, RBAC and ABAC, administrative access controls, cloud access governance, and the ongoing evolution of Identity v3.
- Drive secure-by-default endpoint and device strategy across GitLab’s fleet, with particular strength in macOS, endpoint hardening, configuration