Staff Software Engineer, Security Factory – Static Analysis

Posted 13 hours ago

Apply Now

Resume Score

Check how well your resume matches this job before you apply.

Sign in to check score

About the role

  • Staff software engineer directing GitLab's AI-assisted static analysis engine and SAST capabilities. Defining program-analysis architecture, trustworthy agent tooling, and security detection quality.

Responsibilities

  • Act as the directly responsible individual for the team's highest-scope initiatives from design through delivery
  • Ship large features with minimal guidance and shape the team's long-range goals
  • Bring systems built by one engineer to team ownership through documentation, tests, and shared review
  • Set technical direction for AI-assisted tooling that implements, reviews, and validates engine changes and findings
  • Design checks for agent-written changes and generated results, and measure detection quality against benchmark applications with known vulnerabilities
  • Own the architecture of the program model, including parsing, symbol resolution, intermediate representations, call graphs, taint analysis, and data-flow analysis
  • Own the pipeline that turns source code into findings and define its extension to new languages and frameworks
  • Solve high-scope technical problems and advocate for quality, security, and performance improvements
  • Collaborate with Product Management, UX, Code Security, Composition Analysis, and other partner teams
  • Mentor engineers through code review and pairing, remove blockers, and improve internal standards
  • Participate in on-call rotations for product operations, security operations, and urgent engineering issues
  • Define architecture and specification documents and drive implementation by AI agents and engineers
  • Build and maintain harnesses, agent instructions, agentic skills, coding and reviewing agents, independent review panels, and performance, API, and dependency gates
  • Stay current with program analysis and security research, run AI-assisted research and spikes, and turn findings into prototypes, proposals, and upstream contributions
  • Develop GitLab's SAST capabilities for customer software repositories

Requirements

  • Experience building your own LLM tooling, such as a harness, an agent pipeline, or evaluations, with the judgment to know when output is trustworthy
  • Extensive professional experience writing, testing, and reviewing production code in Rust, Go, or a comparable systems language, with depth in at least one
  • Willingness to work across Rust, Go, and Ruby
  • Experience with performance optimization and containerized workflows and CI/CD, including Docker
  • Deep program analysis and static analysis background, including parsing and ASTs, intermediate representations, SSA, control-flow and call graphs, taint and data-flow analysis, type inference, incremental and fixpoint computation, or detection rules
  • Ability to read, evaluate, and apply research literature
  • Deep application security experience, including vulnerability research, secure code review, or writing detection rules
  • Fluency with OWASP Top 10 and CWE vulnerability classes
  • Ability to communicate clearly and concisely about complex technical, architectural, and organizational problems
  • Ability to write architecture and design specifications that bring a team to a decision
  • Track record of owning ambiguous, team-wide problems and shipping from concept to production with minimal guidance
  • Experience defining overarching architecture, delegating component specifications to engineers and AI agents, and getting them implemented reliably
  • Track record of mentoring engineers, raising technical standards, and influencing technical direction by achieving consensus
  • Familiarity with popular web or mobile application frameworks (helpful)
  • Experience designing guardrails for agent-written code, such as mutation testing, fuzzing, and CI gates (helpful)
  • Research community engagement through publications, tool papers, or upstream open source contributions (helpful)

Benefits

  • Benefits to support your health, finances, and well-being
  • Flexible Paid Time Off
  • Team Member Resource Groups
  • Equity Compensation & Employee Stock Purchase Plan
  • Growth and Development Fund
  • Parental Leave

Job type

Full Time

Experience level

Lead

Salary

$152,800 - $259,200 per year

Degree requirement

No Education Requirement

Tech skills

DockerOpen SourceRubyRustGo

Location requirements

RemoteUnited States

Report this job

Found something wrong with the page? Please let us know by submitting a report below.