Act as the directly responsible individual for the team's highest-scope initiatives from design through delivery
Ship large features with minimal guidance and shape the team's long-range goals
Bring systems built by one engineer to team ownership through documentation, tests, and shared review
Set technical direction for AI-assisted tooling that implements, reviews, and validates engine changes and findings
Design checks for agent-written changes and generated results, and measure detection quality against benchmark applications with known vulnerabilities
Own the architecture of the program model, including parsing, symbol resolution, intermediate representations, call graphs, taint analysis, and data-flow analysis
Own the pipeline that turns source code into findings and define its extension to new languages and frameworks
Solve high-scope technical problems and advocate for quality, security, and performance improvements
Collaborate with Product Management, UX, Code Security, Composition Analysis, and other partner teams
Mentor engineers through code review and pairing, remove blockers, and improve internal standards
Participate in on-call rotations for product operations, security operations, and urgent engineering issues
Define architecture and specification documents and drive implementation by AI agents and engineers
Build and maintain harnesses, agent instructions, agentic skills, coding and reviewing agents, independent review panels, and performance, API, and dependency gates
Stay current with program analysis and security research, run AI-assisted research and spikes, and turn findings into prototypes, proposals, and upstream contributions
Develop GitLab's SAST capabilities for customer software repositories
Requirements
Experience building your own LLM tooling, such as a harness, an agent pipeline, or evaluations, with the judgment to know when output is trustworthy
Extensive professional experience writing, testing, and reviewing production code in Rust, Go, or a comparable systems language, with depth in at least one
Willingness to work across Rust, Go, and Ruby
Experience with performance optimization and containerized workflows and CI/CD, including Docker
Deep program analysis and static analysis background, including parsing and ASTs, intermediate representations, SSA, control-flow and call graphs, taint and data-flow analysis, type inference, incremental and fixpoint computation, or detection rules
Ability to read, evaluate, and apply research literature
Deep application security experience, including vulnerability research, secure code review, or writing detection rules
Fluency with OWASP Top 10 and CWE vulnerability classes
Ability to communicate clearly and concisely about complex technical, architectural, and organizational problems
Ability to write architecture and design specifications that bring a team to a decision
Track record of owning ambiguous, team-wide problems and shipping from concept to production with minimal guidance
Experience defining overarching architecture, delegating component specifications to engineers and AI agents, and getting them implemented reliably
Track record of mentoring engineers, raising technical standards, and influencing technical direction by achieving consensus
Familiarity with popular web or mobile application frameworks (helpful)
Experience designing guardrails for agent-written code, such as mutation testing, fuzzing, and CI gates (helpful)
Research community engagement through publications, tool papers, or upstream open source contributions (helpful)
Benefits
Benefits to support your health, finances, and well-being
Flexible Paid Time Off
Team Member Resource Groups
Equity Compensation & Employee Stock Purchase Plan
Information Security Specialist strengthening technology controls, security governance, and risk management at TD, a major North American bank. Advising partners, assessing controls, supporting audits, and responding to incidents.
Buildings, development and security Analyst supporting fire prevention, facility safety, and building management at Desjardins. Analyzing risks, developing safety plans, and implementing physical security systems.
BMO banking associate providing bilingual credit and lending sales and service remotely in Quebec. Handling customer contacts, credit decisions, compliance, and suspicious - activity reporting.
Principal Information Security Engineer defining scalable security strategy, architecture, automation, cloud, identity, and AI controls. Helping Arctic Wolf protect organizations worldwide and end cyber risk.
Consultant cybersécurité hybride à Montréal chez I - TRACING, pure - player indépendant en sécurité informatique. Conception, déploiement et support de solutions IAM, réseau, systèmes et applications.