- Experience
- 7+ yrs
- Salary
- USD 168,000 – USD 238,000 / year
- Openings
- 1
- Posted
- 1 week ago
- Work mode
- Work from home
- Resume
- Required to apply
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About GitLab
GitLab is a leading orchestration platform designed for DevSecOps, trusted by over 50 million users and more than half of the Fortune 100 companies. The platform helps organizations boost developer productivity, streamline operational efficiencies, decrease security and compliance risks, and accelerate digital transformation.
Our team embraces AI as a fundamental tool to enhance productivity, expecting members to integrate AI into their everyday activities to foster efficiency, innovation, and influence. GitLab nurtures a culture where careers advance rapidly, ingenuity thrives, and every voice matters. Our dynamic environment is propelled by core values and continuous learning, enabling team members to reach their full potential while collaborating with industry leaders to tackle complex challenges.
Role Overview
We are looking for a Staff Security Research Engineer to join our Application Security Team. This role involves advanced security research on GitLab's AI-driven DevSecOps features. As GitLab reshapes software development through collaboration between developers and AI agents, the role seeks proactive identification and validation of vulnerabilities to safeguard the platform and its users.
The successful candidate will work at the cutting edge of security research, focusing on GitLab’s DevSecOps platform, Duo Agent Platform, GitLab Duo Chat, and AI workflows facilitating human/AI co-development. Responsibilities include creating innovative testing approaches (especially for AI agent security), performing hands-on penetration tests, and transforming emerging security threats into concrete enhancements. The research performed here will significantly contribute to securing the next generation of AI-powered DevSecOps tools, ensuring GitLab remains a leader in secure software development.
This position offers a rare chance to influence security and AI security methodologies within one of the world’s foremost DevSecOps platforms, collaborating with teams pushing AI-assisted software development boundaries. You will have access to state-of-the-art AI systems, freedom for exploratory attack simulations, and a direct impact on the security of millions of developers globally.
Key Responsibilities
- Perform security research across two or more specialized domains.
- Discover novel, systemic, and compound vulnerabilities where combined weaknesses produce significant impact.
- Validate vulnerabilities using hands-on testing and develop proof-of-concept exploits illustrating realistic attack methods.
- Evaluate emerging vulnerability classes against GitLab’s codebase, driving remediation at the class level rather than isolated instances.
- Investigate GitLab’s AI and agent surfaces to define security requirements for engineering teams.
- Create tools and automation solutions to scale security research, including agent-assisted vulnerability discovery.
- Research security postures of open-source tools and dependencies integrated with GitLab, reporting findings responsibly and tracking mitigations.
- Address complex technical problems involving high complexity and ambiguity.
- Propose and implement technical and process improvements in security.
- Contribute to the security team’s roadmap.
- Provide clear, actionable feedback to engineering teams based on research insights.
- Mentor and support other team members and occasionally colleagues outside the immediate team.
- Share insights and novel vulnerability discoveries with the broader security community.
Candidate Profile
- At least seven years of professional experience in security research, penetration testing, or offensive security roles.
- Proven expertise in discovering and exploiting security vulnerabilities.
- Recognized subject matter expert in a minimum of two technical areas related to product security.
- Proficiency in one or more programming languages such as Ruby, Go, Python, TypeScript, or Rust, with AI framework experience considered a plus.
- Ability to comprehend and analyze code written in multiple languages and across different codebases.
- Understanding of AI-specific attack methods, including prompt injection, agent manipulation, and exploitation of AI workflows.
- Experience leading technical initiatives within cross-functional teams.
- Strong written communication skills with the ability to explain complex subjects clearly and concisely.
- Aptitude for translating intricate technical findings into clear risk evaluations and remediation strategies.
- Analytical and creative thinking skills to envision diverse attack scenarios.
- Preferred qualifications include published security research or presentations at conferences; software engineering background with expertise in distributed systems; recognized security certifications such as OSCP, OSCE, GPEN; and experience with GitLab or comparable DevSecOps platforms.
About the Security Team
The Security Researchers operate within the Application Security team, focusing on addressing complex security challenges faced by GitLab and its users. They work to minimize systemic product security risks while maintaining the development tempo of the Engineering organization.
Compensation and Benefits
The salary range offered for US residents is between $168,000 and $238,000 USD annually. Note that this reflects base salary and does not include bonuses, equity, or benefits. Compensation and grade levels are based on candidate qualifications, market data, equity among team members, and geographic location. Sales roles may also receive incentive pay up to 100% of base salary.
GitLab provides comprehensive benefits supporting health, financial stability, and well-being, including flexible paid time off, employee resource groups, equity compensation with stock purchase plans, funds for growth and development, and parental leave.
Diversity and Inclusion
GitLab is committed to equal opportunity employment and affirmative action. Hiring and career advancement practices are merit-based, free from discrimination on any legally protected basis including race, gender, disability, veteran status, and more. The company fosters an inclusive environment encouraging applications from candidates of all backgrounds and offers accommodations for disabilities during recruitment.
Industry
Software Development