Skip to content
CISO Spotlights

Career profile

Josh Lemos

Chief Information Security Officer, GitLab Inc.

Status
Current role, per sources checked 11 October 2026
Appointed
13 June 2023
Published

Compiled 11 October 2026 from public records. Each statement below is drawn from the sources listed at the end.

Josh Lemos is the Chief Information Security Officer of GitLab Inc., appointed in June 2023.

Career path

Lemos began his security career as a Manager for Application Security at EY. He went on to serve as a Vice President at Accuvant. He later served as Federal CISO for ServiceNow. He then became Vice President of Research and Intelligence at BlackBerry Cylance, a role in which he had over 15 years of experience managing global research, security and software development teams and served as executive sponsor of projects across regulated, globally distributed cloud architectures. Lemos served as CISO at Block, formerly known as Square, before joining GitLab. GitLab announced his appointment as Chief Information Security Officer on June 13, 2023. He holds a B.S. in Computer and Information Systems Security from the University of San Francisco.

Remit at GitLab

As CISO, Lemos is responsible for leading GitLab's global security strategy and compliance initiatives, fortifying the GitLab DevSecOps platform, and ensuring security for customers. He is responsible for establishing and maintaining the enterprise vision, strategy, and program to ensure information assets and technologies are adequately protected. GitLab made the Secure by Design Pledge with the Cybersecurity and Infrastructure Security Agency, and Lemos said, "The Secure by Design concepts are well-aligned with GitLab's core values."

Public commentary and published work

Lemos has written articles published on GitLab's site, including AI agents are reshaping software: What CISOs need to know, Beyond shift left: Engineering supply chain safety at scale, Key security trends for CISOs in 2025, and Addressing the root cause of common security frustrations. In an interview with Help Net Security published in January 2025, Lemos discussed the shift from DevOps to DevSecOps, describing the complexity organizations face in integrating security tooling into fragmented build systems and developer ecosystems. He noted that while developers may deploy code many times a day, security scanners such as static application security testing tools often run on a scheduled basis, creating delays in feedback loops. He also discussed using metrics to track DevSecOps success and maintain development speed while fostering collaboration between security and engineering teams. Lemos also serves as a mentor to aspiring information security professionals and supports organizations that promote diversity and inclusion in the technology industry.

Sources

  1. 1.
    GlobeNewswire News Roomglobenewswire.com · published 13 June 2023 · checked 11 October 2026 · tier A
  2. 2.
    RSAC Conferencersaconference.com · undated page · checked 11 October 2026 · tier A
  3. 3.
    Cybersecurity and Infrastructure Security Agency CISAcisa.gov · undated page · checked 11 October 2026 · tier A
  4. 4.
    Help Net Securityhelpnetsecurity.com · published 9 January 2025 · checked 11 October 2026 · tier B
  5. 5.
    GitLababout.gitlab.com · undated page · checked 11 October 2026 · tier A

Tier A: the organization itself, a regulator or a government page. Tier B: established trade or business press.