Staff Security Researcher

Posted 4 days ago

Apply Now

Resume Score

Check how well your resume matches this job before you apply.

Sign in to check score

About the role

  • Staff Security Researcher conducting vulnerability research and penetration testing for GitLab’s AI-powered DevSecOps platform. Developing attack methodologies, tooling, and security improvements.

Responsibilities

  • Conduct security research in two or more specialty areas
  • Identify novel, systemic, and chained vulnerabilities in GitLab
  • Validate vulnerabilities through hands-on testing and proof-of-concept exploits
  • Assess emerging vulnerability classes against the GitLab codebase and drive remediation
  • Research GitLab's AI and agentic surfaces and help define security requirements
  • Build tooling and automation for scalable security research, including agent-assisted vulnerability discovery
  • Research the security posture of open source tools and dependencies, report findings to maintainers, and track mitigation
  • Solve technical problems of high scope, complexity, and ambiguity
  • Define and implement security technical and process improvements
  • Contribute to the team roadmap
  • Provide actionable feedback to engineering teams
  • Mentor and advise individual contributors
  • Share knowledge and novel vulnerability types with the security community
  • Report to the Senior Manager of Application Security

Requirements

  • 7+ years of experience in security research, penetration testing, or offensive security roles
  • Hands-on experience discovering and exploiting vulnerabilities
  • Subject matter expertise in at least two technical areas impacting product security
  • Proficiency in one or more of Ruby, Go, Python, TypeScript, or Rust
  • Ability to read and analyze code across multiple languages and codebases
  • Understanding of AI attack vectors including prompt injection, agent manipulation, and workflow exploitation
  • Experience leading technical objectives in cross-functional teams
  • Excellent written communication skills with ability to articulate complex topics clearly and concisely
  • Ability to translate complex technical findings into clear risk assessments and remediation recommendations
  • Strong analytical and problem-solving skills with creative thinking about attack scenarios
  • Published security research or conference presentations (nice to have)
  • Background in software engineering with distributed systems expertise (nice to have)
  • Security certifications such as OSCP, OSCE, GPEN, or similar (nice to have)
  • Experience with GitLab or similar DevSecOps platforms (nice to have)

Benefits

  • Benefits to support your health, finances, and well-being
  • Flexible Paid Time Off
  • Team Member Resource Groups
  • Equity Compensation & Employee Stock Purchase Plan
  • Growth and Development Fund
  • Parental Leave

Job type

Full Time

Experience level

Lead

Salary

$168,000 - $238,000 per year

Degree requirement

No Education Requirement

Tech skills

Distributed SystemsOpen SourcePythonRubyRustTypeScriptGo

Location requirements

RemoteUnited States

Report this job

Found something wrong with the page? Please let us know by submitting a report below.