Grafana LabsGL

Staff Security Engineer, Security Assurance

Query, visualize, alert on, and understand your data no matter where it’s stored.

Grafana Labs

Employee count: 501-1000

Salary: 243k-243k USD

United States only

About the team

We are looking for a Staff Engineer to be the technical lead of our GRC engineering team. You will be responsible for developing and implementing strategies to ensure we get and maintain industry certifications, and liaising with other teams delivering parts of our overall security posture. The ideal candidate will have a proven track record of building, implementing and improving the maturity of security programs in Cloud-based SaaS organizations and possess excellent leadership and communication skills.

We are building a security system that’s automated at scale, rigorously data-driven, and built from the ground up with defense-in-depth and self-healing in mind. This system supports a highly autonomous, remote-first, cloud-native organization. We are a technical team that can build any tool we need. We also want to open-source as much of our work as possible for security practitioners.

To support our growth and ambitious vision, we embrace agile principles and values, share openly, apply context-driven security mechanisms, default to action, and have an OSS-first mindset. We are a 100% remote company. We believe in high-velocity but reasonable expectations and timeframes, giving people the room to do great work in a setting that prioritizes health, happiness, and work-life balance.

Role

The Staff Security Assurance Engineer will collaborate across Grafana to articulate security policies, implement continuous monitoring, automate workflows, and write and deploy policies across all of our SDLC, applications, and infrastructure. The ideal candidate will have a proven track record of building, implementing and improving the maturity of security programs in Cloud-based SaaS organizations and possess leadership and communication skills.

This role involved hands-on keyboard development, so programming chops and a deep knowledge of securing cloud-native, container-based architectures are critical. Knowledge of security standards and frameworks (ISO, FedRAMP, PCI-DSS, etc) is useful, but the disposition to quickly learn new things is more important than rote knowledge here. Experience negotiating with peers, stakeholders, customers, and auditors is highly valuable. You will work alongside other security engineers, full-stack developers, and customer-facing teams.

Responsibilities:

  • Be a technical lead for our assurance team covering a range of areas, including certifications, application security, cloud security, and internal tooling development
  • Develop, implement, and maintain highly automated security assurance programs to ensure compliance with organizational and regulatory requirements (e.g., ISO 27001, SOC 2, GDPR, NIST, PCI-DSS)
  • Develop systems, automations, and methods of security observability to push the GRC engineering organization beyond just meeting certification requirements
  • Deploy security and compliance checks in an employee-enabling way (guardrails and paved roads) in their daily workflows and build pipelines
  • Define, optimize, and implement the engineering strategy in concert with the security leadership team, ICs and stakeholders across the business
  • Design cutting-edge security metrics to show the security value of what we do
  • Coach and mentor to ensure your team members are motivated, happy and engaged. Provide continuous feedback to ensure that they can add value while maintaining high standards
  • Collaborate with cross-functional teams to integrate security controls into the software development lifecycle and operational processes.
  • Respond to customer security issues, security alerts, and potential incidents

Requirements:

  • Solid experience with at least one programming language. We primarily use Go, TypeScript, and Python but most languages translate well. You will take a code screen.
  • Deep knowledge of using and securing containerized, cloud-native applications, ideally with Kubernetes. Experience with multiple cloud providers is a strong plus.
  • Proven expertise in automating security compliance processes using tools, scripts, and frameworks while enabling developer and employee workflows.
  • Deep understanding of industry-recognized security frameworks, standards, and certifications, such as ISO 27001, SOC 2, PCI DSS, NIST, or GDPR.
  • Strong interpersonal skills. Experience collaborating (and negotiating) with peers, stakeholders, auditors, and customers.
  • Strong capability to manage multiple complex projects and deadlines simultaneously, ensuring timely delivery of security and compliance objectives.
  • A degree in Computer Science, Information Security, or related field (or equivalent experience).

Bonus Points:

  • Working knowledge of Grafana Labs OSS projects and products. Experience in using observability tooling to solve security problems.
  • Experience working with OSS communities
  • Experience securing large-scale distributed systems running in public clouds

In the United States, the Base compensation range for this role is USD 202,000 - USD 243,000. Actual compensation may vary based on level, experience, and skillset as assessed in the interview process. Benefits include equity, bonus (if applicable) and other benefits listed here.

*Compensation ranges are country-specific. If you are applying for this role from a different location than listed above, your recruiter will discuss your specific market’s defined pay range & benefits at the beginning of the process.

About Grafana Labs: There are more than 20M users of Grafana, the open source visualization tool, around the globe, monitoring everything from beehives to climate change in the Alps. The instantly recognizable dashboards have been spotted everywhere from a NASA launch and Minecraft HQ to Wimbledon and the Tour de France. Grafana Labs also helps more than 3,000 companies -- including Bloomberg, JPMorgan Chase, and eBay -- manage their observability strategies with the Grafana LGTM Stack, which can be run fully managed with Grafana Cloud or self-managed with the Grafana Enterprise Stack, both featuring scalable metrics (Grafana Mimir), logs (Grafana Loki), and traces (Grafana Tempo). Benefits: For more information about the perks and benefits of working at Grafana, please check out our careers page. Equal Opportunity Employer: At Grafana Labs we’re building a company where a diverse mix of talented people want to come, stay, and do their best work. We know that our company runs on the hard work and the dedication of our passionate and creative employees. If you're excited about this role but your experience doesn’t align perfectly with every qualification in the job description, we encourage you to apply anyways. We will recruit, train, compensate and promote regardless of race, religion, color, national origin, gender, disability, age, veteran status, and all the other fascinating characteristics that make us different and unique. We believe that equality and diversity builds a strong organization and we’re working hard to make sure that’s the foundation of our organization as we grow. For information about how your personal data is used once you’ve applied to a job, check out our privacy policy.

About the job

Apply before

Posted on

Job type

Full Time

Experience level

Senior

Salary

Salary: 243k-243k USD

Location requirements

Hiring timezones

United States +/- 0 hours

About Grafana Labs

Learn more about Grafana Labs and their company culture.

View company profile

Query, visualize, alert on, and understand your data no matter where it’s stored. With Grafana you can create, explore, and share all of your data through beautiful, flexible dashboards.

We work in a big tent where everyone is welcome. Come on in.

OK, it’s not an actual big tent, but it is one of our core philosophies.

We know that data has incredible power to solve complex problems, transform business, drive innovation, and ultimately make the world a better place. The unfortunate reality is that the data we need often lives all over the place in disparate systems across geos, platforms, servers, and more. It’s our mission as Grafanistas to unite data, no matter where it lives, and empower our users to analyze, take action, and make smart decisions.

Building a powerful product takes a village — from engineering to customer success to people operations and beyond. What’s your calling?

What we value

Shared values are foundational to culture. They empower us, as both individuals and teams, to have an impact and achieve our mission, because we’re aligned on what’s really important to us. We’ve established these guiding principles to drive independent thinking, thoughtful decision-making, and result-oriented action that stays true to our mission.

Share openly and default to transparency

We share anything and everything we can — some might even call us over-sharers, and we’re OK with that. We want to ensure that Grafanistas have all the context they need to make smart, informed decisions in their daily work.

Respectfully empowered

We encourage our team members to be autonomous — this is essential for a distributed team. Freedom and empowerment are built on respect for one’s commitments and colleagues. We default to action. We value team members who take the initiative to get things done, ask when they need help, and dive into the job with both feet.

OSS is in our DNA

We have a big tent philosophy. We work with competitors and value interoperability. Decisions at Grafana are made with the long-term health of the company in mind. We aren’t distracted by short-term gains. We understand that our commercial success as a company is linked to our users’ success with our software.

We keep our commitments

We care about the say/do ratio, and for all our math friends out there, we like to see a good 1:1 ratio here. We do what we promise for each other, customers, and users, and we are personally accountable for delivering on our commitments. We dislike indecision: An imperfect or controversial decision is better than no decision. Debates are won with data and reason, not job titles.

Seek diverse perspectives

Each and every one of us prioritizes an open and inclusive culture at Grafana Labs, and we strive to bring diverse perspectives to the table to come up with the best ideas. We’re building a company where a diverse mix of talented people want to come, to stay, and to do their best work. We believe this will create the best results: Diversity drives innovation, and that innovation drives our success.

Don’t let perfect get in the way of great

We should all aim to do our best, but if perfection is the goal, we’ll probably never produce anything. Instead, we determine requirements to make something great and work hard to hit them. What can be squeaked out as an MVP at 60%? What actually needs to be done closer to 90%? From there, we iterate. This requires more than talent to succeed; it requires grit and determination. We want to get a great product out to our customers now and continue to iterate on it with fresh ideas and innovation. We’re a startup; we’re far from perfect. Get super comfortable with things not being perfect, while continuing to hold high standards for yourself and the team.

Help each other thrive

Supporting each other, our users, and our customers is a priority and core part of what we do. We pitch in where needed and do what it takes to get things done, even if it isn’t necessarily our job to do so. We win together, as one global team.

Employee benefits

Learn about the employee benefits and perks provided at Grafana Labs.

View benefits

Grafana Shutdown Days

Grafana Labs offers additional shutdown days throughout the year for an extra breather, enhancing work-life balance.

Wellbeing Resource Group

Grafana Labs organizes sessions with fellow team members and external trainers to promote mindfulness and well-being.

Parental & Sick Leave

Grafana Labs provides parental leave and sick leave, supporting team members during important life events and personal health needs.

Tech Choice

Grafana Labs empowers employees to choose their own laptop and accessories required for the job, with a tech refresh every two years.

View Grafana Labs's employee benefits
Claim this profileGrafana Labs logoGL

Grafana Labs

View company profile

Similar remote jobs

Here are other jobs you might want to apply for.

View all remote jobs

152 remote jobs at Grafana Labs

Explore the variety of open remote roles at Grafana Labs, offering flexible work options across multiple disciplines and skill levels.

View all jobs at Grafana Labs

Remote companies like Grafana Labs

Find your next opportunity by exploring profiles of companies that are similar to Grafana Labs. Compare culture, benefits, and job openings on Himalayas.

View all companies

Find your dream job

Sign up now and join over 85,000 remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan
Grafana Labs hiring Staff Security Engineer, Security Assurance • Remote (Work from Home) | Himalayas