New The Skills of Tomorrow: how AI-exposed is every skill in 2026? See the data →
GitLab

Software Security Engineer

GitLab
remote mid full-time $103,600-$166,500 USD Remote, Canada; Remote, US
Apply →

First indexed 24 Apr 2026

Description

You will engineer security improvements to the GitLab product as well as building and maintaining the tools we use to detect and prevent abuse on our SaaS platforms. A strong software engineering background with experience in large Ruby/Rails codebases is required.

As an engineer on the Trust and Safety team, you will predictively identify abuse patterns and trends and build prevention systems to mitigate abusive users. The Trust and Safety team both maintains core abuse prevention platforms as well as cross functionally builds customer safety mechanisms on GitLab, such as the introduction of Compromised Password Detection for GitLab.com.

This role is an ideal fit for candidates with software engineering backgrounds interested in moving into security engineering. Formal security engineering experience is not a requirement for this role.

Key Responsibilities:

Maintain core abuse prevention systems and build new abuse detection rules to identify and prevent evolving abuse patterns such as platform abuse, cryptomining, platform spam and abuse of terms of service

Maintain and build new capabilities in our in-house abuse platform

Improve and expand agentic AI capabilities in our abuse mitigation tools

Collaborate with peers to deliver safety improvements for the GitLab product

Resolve automation gaps and create efficient, automated processes

Create and maintain documentation such as runbooks and procedures

Key Requirements:

Strong software development skills with experience in Ruby/Rails

Experience working on distributed applications with large codebases and deployed in cloud environments strongly preferred

Passion/desire to proactively develop security engineering skills

Comfortable working in an all remote environment where results and impact matter above hours worked

Interest in “thinking like a hacker” and defending against attacks with an “automation first” mindset

Interest in cloud native development (Google Cloud Platform (GCP) and/or AWS)

Interest in handling trust and safety security incidents (platform abuse, cryptomining, platform spam)

This listing is enriched and indexed by YubHub. To apply, use the employer's original posting: https://job-boards.greenhouse.io/gitlab/jobs/8516916002