Security Governance Stage

The Security Governance stage builds policy, compliance, and AI governance capabilities so customers can define security rules once and enforce them across the platform.

The Security Governance engineering stage owns how security and compliance rules are expressed, stored, evaluated, and audited across GitLab, including the governance surface for AI workloads.

This stage was formed in the FY27 Sec reorg from the former Security Risk Management stage plus the Compliance group.

Leadership

Role Person
Stage lead Mohamed Waseem (@mwaseem5)
Senior Staff Engineer Mehmet Emin Inaç (@minac)

Teams

Group Engineering Manager Tech Lead Label
Policy Engine Alan Paruszewski (@alan) Martin Cavoj (@mcavoj) group::policy engine
Policy Management Alan Paruszewski (@alan) Alexander Turinske (@aturinske) group::policy management
Security Controls Alan Paruszewski (@alan) Gal Katz (@gkatz1) group::security controls
Compliance Nathan Rosandich (@nrosandich) Huzaifa Iftikhar (@huzaifaiftikhar1) group::compliance
AI Governance Nathan Rosandich (@nrosandich) Jean van der Walt (@jeanvdw) group::ai governance
AI Control Plane Abhimanyu Singh (@asingh73) To be hired group::ai control plane

Group membership is sourced from Workday and published on the product categories page.

Renamed groups still link to their previous handbook location. Those pages move under this stage in a follow-up merge request, tracked in the Sec reorg project.

Labels

Work in this stage carries the devops::security governance stage label plus the owning group’s group:: label. Both are scoped labels and exist in the gitlab-org and gitlab-com top-level groups.

Slack

  • #sec-security-governance - stage channel.

Per-group channels are listed on each group page. Several channel renames are still in progress, tracked in Sec reorg issue 2.


AI Control Plane Group
The AI Control Plane group builds the control plane for the Duo Agent Platform and the Software Factory.
AI Governance Group
The AI Governance group builds platform-wide Flow ID and auditing for the Duo Agent Platform and Software Factory.
Compliance Group
The Compliance group gives organizations visibility into their compliance posture in GitLab and tools to identify non-compliant activity and enforce compliance requirements.
Policy Engine Group
The Policy Engine group owns the evaluation core: how a policy's rules run against an input and return a decision.
Policy Management Group
The Policy Management team at GitLab is responsible for creating solutions that enforce scans, and require security approvals once vulnerabilities are detected.
Security Controls Group
The Security Controls group owns enablement and product-led growth for GitLab security features.
Security Governance Planning
How we do planning Our milestone planning is handled asynchronously as much as possible. Planning …