# Principal Security Researcher

**Company**: GitLab
**Location**: Remote, Canada; Remote, Israel; Remote, United Kingdom; Remote, United States
**Work arrangement**: remote
**Experience**: senior
**Job type**: full-time
**Salary**: $203,200-$275,000 USD
**Category**: Engineering
**Industry**: Technology

**Apply**: https://job-boards.greenhouse.io/gitlab/jobs/8731718002?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply
**Canonical**: https://yubhub.co/jobs/job_14f781e8-54e

## Description

GitLab is seeking a Principal Security Researcher to join its Application Security Team. The successful candidate will conduct cutting-edge security research on GitLab's AI-powered DevSecOps capabilities.

Responsibilities:

- Conduct and lead security research projects across multiple functional areas.

- Identify novel, systemic, and chained vulnerabilities in GitLab.

- Validate security vulnerabilities through hands-on testing and develop proof-of-concept exploits.

- Assess emerging industry vulnerability classes against the GitLab codebase.

- Lead security research into GitLab's AI and agentic surfaces.

- Build and direct the tooling and automation that scales security research.

- Research the security posture of open source tools and dependencies integrated with GitLab.

- Solve technical problems of the highest scope, complexity, and ambiguity.

- Help shape the team and sub-department roadmap.

- Lead the integration of security research results into engineering and business functions.

- Teach, mentor, and advise other domain experts and individual contributors.

- Share knowledge and novel vulnerability types with the security community.

Requirements:

- 10+ years of experience in security research, penetration testing, or offensive security roles.

- Strong ability in discovering and exploiting vulnerabilities in large codebases and complex systems.

- Proficiency in two or more of Ruby, Go, Python, TypeScript, or Rust.

- Ability to read and analyze code across multiple languages and codebases.

- Strong knowledge of AI frameworks.

- Strong understanding of AI attack vectors.

- Excellent written communication skills.

- Ability to translate complex technical findings into clear risk assessments and remediation recommendations.

- Strong analytical and problem-solving skills with creative thinking about attack scenarios.

Benefits:

- Benefits to support health, finances, and well-being.

- Flexible Paid Time Off.

- Team Member Resource Groups.

- Equity Compensation & Employee Stock Purchase Plan.

- Growth and Development Fund.

- Parental Leave.

Salary Range: $203,200-$275,000 USD

## Skills

### Required
- security research
- penetration testing
- offensive security
- Ruby
- Go
- Python
- TypeScript
- Rust
- AI frameworks

### Nice to have
- published security research
- conference presentations
- software engineering
- distributed systems expertise
- GitLab or similar DevSecOps platforms

---

Source: [Apply at job-boards.greenhouse.io](https://job-boards.greenhouse.io/gitlab/jobs/8731718002?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply)
