> Markdown version of [/jobs/ext/2700513-principal-security-awareness-human-risk-engineer](https://www.wearedevelopers.com/jobs/ext/2700513-principal-security-awareness-human-risk-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Security Awareness & Human Risk Engineer - **Company:** GitLab - **Location:** Sheffield, UK - **Experience:** Expert - **Salary:** £203,200.0 - £275,000.0 - **Contract:** Permanent contract - **Skills:** Open Web Application Security, Phishing, Secure Coding, Simulation Software, Value Engineering, Gitlab - **Published:** September 4, 2026 - **Apply:** https://www.totaljobs.com/job/principal-security-engineer/gitlab-job107935520 ## About the Role * A minimum of 10 years' experience building or scaling global awareness and human-risk programs in a large, globally distributed enterprise, with measurable outcomes; regulated-industry experience preferred. * SANS Security Awareness Professional (SSAP) certification, or equivalent demonstrated expertise in building, maintaining, and measuring a mature awareness program. * Demonstrated experience running enterprise-scale phishing programs and organization-wide awareness campaigns. * Track record of evaluating, selecting, consolidating, or replacing security training vendors, including cost and value analysis. * Instructional design capability * Working knowledge of security policy development, audit support, and control evidence. * Ability to influence enterprise strategy across technical and non-technical teams without formal authority. * Ability to make complex security topics practical and engaging in an all-remote organization. * Track record of onboarding, managing, and negotiating with third party vendors. ## Description The Principal Security Awareness & Human Risk Engineer is a strategic individual contributor role within GitLab's Security Assurance team. The role owns GitLab's global security awareness and education program and drives measurable reduction in human-related security risk - moving the program beyond completion-rate compliance toward sustained behavior change and embedded security culture. What You'll Do * Own and evolve the global security awareness and education program, spanning annual, new-hire, role-based, targeted, executive, and microlearning content. * Lead the phishing simulation program end to end - design, deployment, analysis, and targeted follow-up. * Apply behavior change principles to reinforce secure habits and address priority risk behaviors. * Build and sustain security culture through learning campaigns, Security Awareness Month, and ongoing engagement. * Produce multimedia awareness and education content, including video. * Administer the training and phishing platforms, owning program data and reporting end to end. * Define and report performance indicators to Security Assurance leadership. * Own vendor relationships for phishing, secure coding (OWASP) training, and video production. * Lead market and competitor evaluations, renewal decisions, and cost negotiation, recommending in-house builds where commercial options underperform. * Collaborate on and maintain security policies, standards, and procedures. * Coordinate audit evidence and demonstrate control effectiveness. * Track remediation of identified gaps to closure. ## Related Videos - [WeAreDevelopers LIVE - Modern DevOps for IoT Devices and More](https://www.wearedevelopers.com/videos/1805-wearedevelopers-live-modern-devops-for-iot-devices-and-more) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) - [Security Blindspots and How to Learn About Them - Anna Oliveira](https://www.wearedevelopers.com/videos/1754-security-blindspots-and-how-to-learn-about-them-anna-oliveira) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Stop Googling Git Commands. Start Actually Learning Git.](https://www.wearedevelopers.com/magazine/730-stop-googling-git-commands-start-actually-learning-git) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)