# Staff Security Researcher

**Company**: GitLab
**Location**: Remote, Canada; Remote, Israel; Remote, United Kingdom; Remote, United States
**Work arrangement**: remote
**Experience**: staff
**Job type**: full-time
**Salary**: $168,000-$238,000 USD
**Category**: Engineering
**Industry**: Technology

**Apply**: https://job-boards.greenhouse.io/gitlab/jobs/8782153002?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply
**Canonical**: https://yubhub.co/jobs/job_dc784a43-134

## Description

GitLab is seeking a Staff Security Research Engineer to join its Application Security Team. The successful candidate will conduct cutting-edge security research on GitLab's AI-powered DevSecOps capabilities.

Responsibilities:

- Conduct security research in two or more specialty areas

- Identify novel, systemic, and chained vulnerabilities in GitLab

- Validate security vulnerabilities through hands-on testing and develop proof-of-concept exploits

- Assess emerging industry vulnerability classes against the GitLab codebase

- Conduct security research into GitLab's AI and agentic surfaces

- Build tooling and automation that scales security research

- Research the security posture of open source tools and dependencies integrated with GitLab

- Solve technical problems of high scope, complexity, and ambiguity

- Define and implement security technical and process improvements

- Contribute to the team roadmap

- Provide actionable and constructive feedback to engineering teams

- Mentor and advise other individual contributors

- Share knowledge and novel vulnerability types with the security community

Requirements:

- 7+ years of experience in security research, penetration testing, or offensive security roles

- Hands-on experience discovering and exploiting vulnerabilities

- Subject matter expert (SME) of at least two technical areas impacting the security of the product

- Proficiency in one or more of Ruby, Go, Python, TypeScript, or Rust

- Ability to read and analyze code across multiple languages and codebases

- Understanding of AI attack vectors

- Experience leading technical objectives in cross-functional teams

- Excellent written communication skills

- Ability to translate complex technical findings into clear risk assessments and remediation recommendations

Nice to have:

- Published security research or conference presentations

- Background in software engineering with distributed systems expertise

- Security certifications such as OSCP, OSCE, GPEN, or similar

- Experience with GitLab or similar DevSecOps platforms

## Skills

### Required
- security research
- penetration testing
- offensive security
- Ruby
- Go
- Python
- TypeScript
- Rust
- AI attack vectors

### Nice to have
- published security research
- software engineering
- distributed systems
- OSCP
- OSCE
- GPEN

---

Source: [Apply at job-boards.greenhouse.io](https://job-boards.greenhouse.io/gitlab/jobs/8782153002?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply)
