- Experience
- 8+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 3 days ago
- Work mode
- In office
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
Role Purpose
The AI Engineer will develop an AI and agentic layer to enhance SAST/SCA capabilities by designing custom automation using large language model (LLM) APIs like OpenAI. This role excludes working on GitLab's native Duo/agentic features and focuses on reducing triage workload, minimizing false positives, and accelerating remediation processes.
Key Responsibilities
- Create integrations that extract SAST/SCA scan results from GitLab using API or webhooks and channel them into an AI-powered external pipeline.
- Develop LLM-based triage tools that assess false-positive probabilities, provide plain-language vulnerability explanations, and generate context-aware remediation recommendations based on code diffs and repository context.
- Design multi-step agentic workflows for functions such as verifying dependency CVEs against actual code usage, checking safe upgrade paths, and generating remediation merge requests for human review.
- Manage prompt engineering efforts, agent evaluation, and implementation of guardrails including hallucination detection, human-in-the-loop approval prior to automated fixes merging, and audit logging for every AI-supported decision.
- Choose and integrate LLM providers or stacks (e.g., OpenAI API or alternatives) while considering data privacy and residency constraints relevant to telco source code and vulnerability data, requiring compliant governance approvals.
- Develop feedback mechanisms that compare AI-generated outputs to analyst and developer decisions to continuously improve agent accuracy.
- Collaborate with subject matter experts to ensure the AI layer augments (not duplicates) GitLab scanning capabilities and with business analysts to translate objectives like reduced mean time to remediate (MTTR) and fewer false positives into concrete automation goals.
- Document system architecture, data flow, and model usage to support security and compliance assessments critical in regulated telecommunications environments, including formal risk analyses for any AI components handling sensitive source code or vulnerability information.
Experience Level
Seeking senior-level professionals with at least eight years in software or AI engineering, including a minimum of one to two years of hands-on experience developing production-grade LLM-based or agentic systems. Prior application security domain expertise is highly preferred.
Required Skills and Knowledge
- Practical experience utilizing LLM APIs (OpenAI, Anthropic, or similar) including function calling, tool integration, structured output generation, and managing context at production scale.
- Strong background in architecting agentic systems that enable multi-step reasoning with tool orchestration and enforce human approval checkpoints over fully autonomous actions.
- Robust software engineering capabilities to build and support integration pipelines utilizing GitLab API/webhooks and CI/CD hooks, beyond prototyping levels.
- Solid grasp of prompt engineering best practices and methods for evaluating AI decision quality beyond superficial plausibility.
- Knowledge of application security concepts such as SAST/SCA findings, CVE/CWE identifiers, and vulnerability risk ratings sufficient to automate related workflows.
- Understanding of data privacy and governance concerns around transmitting source code and vulnerability data to third-party LLM services, and experience implementing controls like data redaction, on-premises/private deployments, and retention policies.
- Familiarity with GitLab's API and webhook mechanisms for creating external integrations.
Preferred Qualifications
- Experience with self-hosted or open-weight LLMs tailored for scenarios requiring strict data residency.
- Previous work on AI tooling focused on security or DevSecOps areas, such as vulnerability triage and automated code reviews.
- Exposure to evaluation frameworks and observability tools for LLMs in production environments, including tracing, guardrails testing, and detecting model drift.
Industry
Software Development