FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Senior Security Risk Engineer
GitLab. Own risk identification, analysis, and prioritization across third-party risk, security risk assessments, and security findings using an established risk framework .
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in security risk management, including risk identification, analysis, and remediation across third-party and security risks. Proficient in translating technical vulnerabilities into business-relevant risk statements and implementing AI risk management practices.
Highest-signal resume keywords
Security Risk ManagementNIST RMFISO 42001Risk AssessmentCloud Security
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Risk IdentificationRisk AnalysisRisk PrioritizationRisk Register ManagementQuantitative Risk AnalysisQualitative Risk AnalysisTechnical Control InterpretationAutomation ScriptingAI Risk ManagementDevSecOps Practices
Soft Skills
Exceptional Communication SkillsAbility to Operate with AmbiguityTime Management
Tools & Technologies
AI-Enabled ToolingGRC WorkflowsRisk Frameworks
Certifications & Qualifications
CISSPCISMCISACRISC
Industry Keywords
Third-Party Risk ManagementCompliance FrameworksSecurity FindingsRegulatory ChangesInternal Audit
Tech Stack
Tools & technologiesCloud
About the role
Key responsibilities & impact- Own risk identification, analysis, and prioritization across third-party risk, security risk assessments, and security findings using an established risk framework
- Translate technical vulnerabilities, control gaps, and risk findings into clear, quantified risk statements for stakeholders and leadership
- Drive remediation of findings and risk exceptions to closure with Engineering, IT, Product, and Legal; escalate stalled or high-severity items
- Mature and maintain a risk register and quarterly reporting cadence covering open risk, remediation progress, and trends
- Own and mature AI risk management, including AI impact assessments, AI risk assessments, and risk treatments supporting ISO 42001 certification
- Design, develop, and implement key risk indicators and supporting metrics for top risks
- Build automation, scripting, or AI-enabled tooling to eliminate manual risk and TPRM workflow steps
- Contribute to the risk program roadmap, incorporating frameworks, regulatory changes, and assessment lessons learned
- Monitor internal and external risk landscapes and identify and escalate emerging risks
- Partner with Security, Legal, IT, Product, and Engineering to translate technical findings and vendor risk into business-relevant risk statements and treatments
- Report top risks to leadership
Requirements
What you’ll need- 5+ years of experience in security risk management
- Experience working with security-centric risk management or compliance frameworks such as NIST RMF, NIST 800-39, or ISO 31000
- Familiarity with AI governance frameworks such as ISO 42001 or NIST AI RMF is a plus
- Experience designing and executing qualitative and quantitative risk analyses that translate technical risks into measurable business impact
- Track record of driving risk assessments, risk registers, and remediation efforts to closure across IT, Procurement, Internal Audit, Legal, Product, and Engineering in a heavily regulated or multi-entity environment
- Experience interpreting technical control requirements and translating them for technical and non-technical stakeholders
- Demonstrated experience personally building scripts, workflows, or AI-enabled tooling to reduce manual risk or GRC work
- Comfort operating with ambiguity, managing multiple concurrent assessments, and reprioritizing under tight deadlines
- Exceptional written and verbal communication skills with demonstrated ability to translate security risks into business risks
- Strong understanding of cloud security, SaaS security models, and DevSecOps practices
- Relevant certifications such as CISSP, CISM, CISA, or CRISC are preferred but not required
Benefits
Comp & perks- Benefits to support your health, finances, and well-being
- Flexible Paid Time Off
- Team Member Resource Groups
- Equity Compensation & Employee Stock Purchase Plan
- Growth and Development Fund
- Parental Leave