Corporate Security (CorpSec)

👋 Welcome to Corporate Security, we’re glad you’re here! You may also know us as the former IT Operations team that moved from the Finance to Security division in early 2024.

Need Help?

Please try exploring the following pages to see if your question has been answered in the handbook pages. Please contact us via the Compass app in Slack (type “Compass” in the top search bar to find it) or it-help@gitlab.com if you have any further questions.

What We Do

Mission

Security Division Mission

As a remote company, we do not have office buildings, physical datacenters, or other traditional IT environments. All of our team members are issued a laptop that they use to work from home or on the road. Although our engineering and product teams are building software that is deployed on AWS and GCP, almost all of our corporate software is vendor-managed software-as-a-service (SaaS). Although this results in a simpler physical threat landscape, the cybersecurity threat landscape is vast and still requires a lot of attention to do it right.

Our mission is to empower our employees to be productive with the technology provided by the business, enable the business to be successful, protect our customers and their data, and provide internal security for GitLab (the company) and our team member’s use of GitLab (the product).

GitLab is both a company and a product. The Corporate Security department focuses on protecting the technology that the company uses to conduct business internally, and provides the hardware, software, and tools that our team members need to get their job done. We have a 24x5 technical support helpdesk for team members and have engineers that configure and maintain many of our company-wide tech stack applications. We also invest heavily in device trust and identity management to provide the highest level of security assurance for the administrators of our product and ensure all appropriate controls are in place when handling customer data.

Prime Directive

  • Safeguard our organization’s digital assets, ensuring the integrity, confidentiality, and availability of all data.
  • Implement robust security measures, fostering a culture of awareness and compliance among employees, and continuously monitoring and enhancing our information technology systems to protect against evolving threats.
  • Leverage the GitLab platform (dogfooding) to assist us in the securing of GitLab.
  • Provide reliable, secure and efficient IT and Security engineering, innovation, and services with Zero Trust principals to support cross-functional organizational goals

Scope

  • Architecting next-generation automation and integration between security-related systems that provides data consistency, reliability, strong security, and auditability.
  • Building relationships with cross-department system owners and proposing solutions to ensure our tech stack applications conform to our latest security best practices
  • Consolidating and refactoring legacy tech debt
  • Designing processes and choosing software tools that improves back office automation or mitigates security risks
  • Escalation engineering and crisis response for leadership teams
  • Factor in cost, security, compatibility, maintainability and user experience when making decisions
  • Growing other team members’ skill sets through mentorship to improve operational efficiency and encourage professional development
  • Handbook documentation for processes and systems architecture
  • Identity and access management (IAM)
  • Joint collaboration with process and system owners across the company for improving automation efficiency, security posture, and vulnerability management
  • Keeping leaders and stakeholders informed of next-gen initiatives and contributing to creating automated analytics for day-to-day IT and Security operations
  • Leading innovation opportunities between several teams with a willingness to experiment and to boldly confront problems of large complexity and scope
  • Making technical decisions on behalf of the department and organization while providing presentation support to leaders during technical discussions
  • New tech stack (vendor) application onboarding and provisioning
  • Onboarding provisioning, offboarding deprovisioning
  • Policy and configuration management for organization-wide applications and systems that we manage
  • Role-based access control (RBAC)
  • Shipping laptops to new team members and refreshing older models
  • Tech support for team members and temporary service providers
  • User experience and productivity optimization for internal software and tools
  • Vulnerability and malware risk mitigation
  • Workflow automation for employee lifecycle
  • X-Men, we are. Always be saving the day with a smile on your face!
  • Yesterday’s problems are tomorrow’s opportunties for iteration
  • Zero trust implementation

Direction and Strategy

Services

Engineering

Who We Are

See the Team Directory.

Contact Us


Automation
Corporate Security (CorpSec) Support
Where to find help and support from the Corporate Security (CorpSec) team, including helpdesk services, systems, and common team member requests.
CorpSec Direction
Thank you for your interest in the direction of Corporate Security. See the internal handbook for …
CorpSec Engineering
The Engineering team members are organized functionally based on the category of tech stack …
CorpSec Services
Identity and access management services owned by Corporate Security Identity Engineering, covering provisioning architecture, automation, and security controls. Requests and enablement are handled by Corporate IT / End User Services.
CorpSec Systems and Tech Stack
The Corporate Security department provides configuration management engineering and tech support helpdesk services for team members and temporary service providers (aka contractors, vendors, etc.) for the company-wide systems that we manage. The systems directory provides a list of all of our systems with quick reference links to administration runbooks, end user documentation, issue templates, mentionable groups, and tags that are used in GitLab epics, issues, and merge requests.
CorpSec Team Directory
The Corporate Security department provides tech support helpdesk services for team members and …
How We Work (CorpSec)
We have four approaches to how we work: Support Helpdesk Services - We provide 24x5 technical …