Principal Security Researcher securing GitLab’s AI-powered DevSecOps platform. Leading vulnerability research, AI attack analysis, penetration testing, and remediation across GitLab’s codebase.
Responsibilities
Conduct and lead security research projects across multiple functional areas
Identify novel, systemic, and chained vulnerabilities in GitLab
Validate security vulnerabilities through hands-on testing and develop proof-of-concept exploits
Assess emerging industry vulnerability classes against the GitLab codebase and drive class-level remediation
Lead security research into GitLab's AI and agentic surfaces and define security requirements
Build and direct tooling and automation for security research, including agent-assisted vulnerability discovery
Research the security posture of open source tools and dependencies integrated with GitLab
Report findings to maintainers and track mitigation under responsible disclosure guidelines
Solve technical problems of the highest scope, complexity, and ambiguity
Help shape the team and sub-department roadmap
Lead integration of security research results into engineering and business functions
Teach, mentor, and advise domain experts and individual contributors
Share knowledge and novel vulnerability types with the security community
Report to the Senior Manager of Application Security
Requirements
10+ years of experience in security research, penetration testing, or offensive security roles
Strong ability in discovering and exploiting vulnerabilities in large codebase and complex systems
Proficiency in two or more of Ruby, Go, Python, TypeScript, or Rust
Ability to read and analyze code across multiple languages and codebases
Strong knowledge of AI frameworks
Strong understanding of AI attack vectors including prompt injection, agent manipulation, and workflow exploitation
At ease in establishing and driving complex remediation initiatives involving cross-functional teams
Excellent written communication skills with an ability to articulate complex topics in a clear and concise manner
Ability to translate complex technical findings into clear risk assessments and remediation recommendations
Strong analytical and problem-solving skills with creative thinking about attack scenarios
Nice to Have: Published security research or conference presentations; background in software engineering with distributed systems expertise; experience with GitLab or similar DevSecOps platforms
Benefits
Benefits to support your health, finances, and well-being
Flexible Paid Time Off
Team Member Resource Groups
Equity Compensation & Employee Stock Purchase Plan
Senior Security Specialist securing RBC’s cloud banking environments across AWS, Azure, and Google Cloud. Executing red/purple team exercises and refining offensive security tooling.
Senior Security Specialist operating BloodHound Enterprise for RBC, a Canadian bank. Mapping identity attack paths and prioritizing remediation across cloud, AD, DevOps, and PAM environments.
Staff Security Researcher conducting vulnerability research and penetration testing for GitLab’s AI - powered DevSecOps platform. Developing attack methodologies, tooling, and security improvements.
Senior security advisor strengthening Desjardins's security posture across governance, data protection, and fraud prevention. Leading complex strategic initiatives for the Desjardins financial services organization.
Senior Infrastructure Security Specialist protecting Kepler’s corporate, cloud, and operational infrastructure. Securing satellite - connectivity operations and Government of Canada environments through vulnerability management, SIEM, endpoint security, and incident response.
Principal Cloud Security Engineer securing LastPass’s browser - based access platform. Defining cloud security architecture and reducing risk across AWS and Kubernetes workloads.
Junior Cyber Security Developer building secure software and supporting cybersecurity requirements for BMO, a Canadian financial services company. Developing, testing, debugging, and maintaining technology applications.