Senior Security Risk Engineer
Core
Own risk identification, quantification, and remediation tracking across the business, translating technical findings into business-relevant risk statements and driving automation/AI improvements for GRC workflows.
Role type
Senior Security Risk Engineer (GRC & Risk Management)
Builds
Risk register, quantified risk statements, AI-enabled risk management tooling, and key risk indicators.
Domain
Cybersecurity, GRC, Third-Party Risk Management (TPRM), AI Governance
Deliverable
dashboards & analysis
Required skills
Risk methodology (NIST RMF, ISO 31000, NIST 800-39), AI governance frameworks (ISO 42001, NIST AI RMF), quantitative/qualitative risk analysis, cross-functional remediation leadership, automation/scripting, cloud security, SaaS security models, DevSecOps
Preferred skills
CISSP, CISM, CISA, CRISC certifications
Technologies
NIST RMF, ISO 31000, NIST 800-39, ISO 42001, NIST AI RMF
Responsibilities
Own risk identification, analysis, and prioritization across TPRM and security assessments; Translate technical vulnerabilities into clear, quantified risk statements; Drive remediation of findings and risk exceptions to closure; Mature and maintain a risk register and quarterly reporting cadence; Own and mature AI risk management including AI impact assessments; Design and implement key risk indicators; Build automation, scripting, or AI-enabled tooling to remove manual steps; Monitor the internal and external risk landscape to identify emerging risks. (via careerplan.io/jobs/8846304002-senior-security-risk-engineer-at-gitlab-inc)
Seniority
Senior, hands-on IC